How NOT to Perform Covert Entry Assessments
Brent White, Tim Roberts
DEF CON 33 · Day 1 · Main Stage
Overview
In this highly engaging and refreshingly candid DEF CON talk, Brent White and Tim Roberts, seasoned physical security penetration testers with over 12 years of experience, dismantle common misconceptions about covert entry assessments. Titled "How NOT to Perform Covert Entry Assessments," the presentation serves as a critical guide for both aspiring and experienced practitioners, shifting the focus from merely showcasing exploits to understanding the ethical, practical, and often overlooked nuances of physical security testing. The speakers aim to save fellow professionals "headaches" by sharing lessons learned from years of real-world engagements, emphasizing professionalism, client empathy, and effective methodologies over the "Hollywood spy" theatrics often associated with the field.

Key moments
- 0:00 Introduction: How NOT to do physical security pentests
- 2:30 Help clients identify weaknesses, don't just beat them up
- 3:30 Be forgettable, not famous: avoid overhype
- 4:10 Hollywood myth vs. reality: You're not Jason Bourne
- 5:10 Real-world roof entry demonstration video
- 6:00 Simple hotel room access for roof entry explanation
How NOT to Perform Covert Entry Assessments
Speakers: Brent White, Tim Roberts
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=DNP_fHTMy84
Overview
In this highly engaging and refreshingly candid DEF CON talk, Brent White and Tim Roberts, seasoned physical security penetration testers with over 12 years of experience, dismantle common misconceptions about covert entry assessments. Titled "How NOT to Perform Covert Entry Assessments," the presentation serves as a critical guide for both aspiring and experienced practitioners, shifting the focus from merely showcasing exploits to understanding the ethical, practical, and often overlooked nuances of physical security testing. The speakers aim to save fellow professionals "headaches" by sharing lessons learned from years of real-world engagements, emphasizing professionalism, client empathy, and effective methodologies over the "Hollywood spy" theatrics often associated with the field.
The core message revolves around the idea that successful covert entry is less about collecting the latest "cool" tools and more about foundational understanding, meticulous planning, and adept social engineering. White and Roberts stress that the objective is not to "beat up on the client" or make them feel their security is "ugly," but rather to identify weaknesses in a constructive manner, helping organizations understand how an adversary might gain physical access. This talk is crucial for anyone involved in offensive security, red teaming, or physical security, offering a grounded perspective that prioritizes client value, legal compliance, and repeatable success over flashy, but often impractical, exploits.
Background
▶ Watch: Introduction: How NOT to do physical security pentests (0:00)
The landscape of physical security assessments is frequently distorted by popular media, creating a "Hollywood myth and reality" gap that the speakers are keen to address. Movies often depict elaborate, high-tech infiltrations involving parkour, parachute drops, and complex badge cloning, fostering unrealistic expectations among practitioners. This romanticized view leads many newcomers to focus on acquiring an arsenal of tools, akin to collecting "Pokemon," without a deep understanding of why and how these tools should be effectively deployed. The speakers highlight a pervasive issue where the same fundamental vulnerabilities are exploited repeatedly, suggesting a lack of foundational understanding in the industry.
White and Roberts argue that the "sexy side of offensive security" – social engineering and covert entry – often attracts individuals who believe being "good at lying" is sufficient. However, they contend that this narrow view overlooks the critical psychological, regional, and contextual factors that influence social engineering success. Furthermore, the talk underscores a significant problem: the tendency for assessors to make the client, or even security personnel, an "adversary." This adversarial mindset can lead to conflict, damage rapport, and ultimately hinder the client's willingness to implement necessary security improvements. The speakers advocate for a philosophy of being "forgettable, not famous," reminding practitioners that their role is to provide actionable intelligence, not to create dramatic footage for a report or personal notoriety. They emphasize that the most effective methods are often the simplest, leveraging human behavior and overlooked physical weaknesses rather than relying solely on advanced, often unreliable, technology.
Key Findings
▶ Watch: Be forgettable, not famous: avoid overhype (3:30)
The talk presents several key findings and philosophical tenets central to successful and ethical covert entry assessments:
- Simplicity Trumps Complexity: The most effective bypasses are often the simplest. Instead of attempting to pick complex locks like a Medeco or an ASSA ABLOY, assessors should look for easier vulnerabilities such as exposed hinge screws on a padlock or accessible rooftop entry points (as demonstrated by simply getting an adjacent hotel room). Overly complex "Hollywood" methods are rarely necessary or practical.
- Understand the "Why," Not Just the "How": It's crucial to understand the underlying reasons why a vulnerability exists or a tool works, rather than just knowing how to operate it. This deep understanding allows for adaptive problem-solving and prevents over-reliance on a specific tool or technique, echoing Bruce Lee's sentiment of fearing the person who practiced one technique 10,000 times.
- Social Engineering is Paramount and Nuanced: While commonly recognized, the depth of social engineering is often underestimated. It's not just about lying; it involves understanding regional psychology (e.g., people in the Midwest/South being more helpful), building rapport (e.g., becoming "acquaintances" with a security guard to get keys), and adapting to specific situations. Impersonating law enforcement, firefighters, or postal workers is illegal and should never be part of a professional assessment.
- Disguises for Superficial Changes, Not Transformation: True "Mission Impossible" level disguises are impractical and unnecessary. Effective disguises involve superficial changes like hair length, clothing color, or even altering gait to avoid recognition, especially during re-tests or after public appearances. The goal is to blend in and be "the most boring person ever," not to completely transform identity.
- High-Tech Tools Don't Save a Bad Plan: Fancy gadgets like the Flipper Zero or advanced badge cloners are useless without a solid plan, a believable story, and thorough reconnaissance. Many primitive and simple methods, such as piggybacking with a forged badge in a sleeve, remain highly effective. Tools like the Prox Mark III or IC copy X are valuable for testing badge system encryption, but not a primary reliance.
- Ethical Conduct and Client Empathy are Non-Negotiable: Assessors must always comply with security personnel, never run, and avoid being confrontational. The objective is to help the client, not to embarrass or cause harm. This includes never naming individuals in reports for negative findings to prevent job loss and framing observations in a positive, constructive light, focusing on systemic issues rather than individual failures. Commending good practices is as important as reporting vulnerabilities.
- Meticulous Planning and Scope Definition: Detailed Rules of Engagement (ROE) and Statement of Work (SOW) are critical. This includes clarifying whether incident response, alarm testing, or destructive entry are in scope. Understanding who manages physical security systems (building management vs. tenant) is vital to avoid unintended damage or legal issues. Leaving a rogue Access Point (AP) with default settings or weak encryption introduces significant risk and is unprofessional.
Technical Deep Dive
▶ Watch: Hollywood myth vs. reality: You're not Jason Bourne (4:10)
The talk delves into several specific technical aspects and methodologies for covert entry, emphasizing practical considerations over theoretical possibilities.
Physical Bypass Techniques:
The speakers highlight that sophisticated lockpicking is often unnecessary. Instead, they advocate for observing and exploiting simpler physical vulnerabilities. For instance, rather than picking a high-security lock like a Medeco or ASSA ABLOY, an assessor should first check for externally facing screws on hinges or easily bypassed padlocks. They mention tools like a crash bar tool which can engage an emergency exit bar, but warn that modern systems often include a rec sensor (reed switch sensor) tied to an alarm system. In such cases, a two-person team might be needed: one to engage the crash bar and another to use canned air to trip the sensor, simulating someone legitimately leaving the room and preventing an alarm.
Alarm Systems and Tamper Evidence:
Alarm systems are crucial compensating controls that must be considered. Simply "popping a door open" can trigger a door force alarm state or a silent sensor. More advanced systems include tamper evidence switches. For example, when attempting to implant a device behind a badge reader, pulling it away from the wall can trigger an alarm if the internal distance sensor is active. Similarly, access control panels like Lineer and Door King often have tamper switches. Assessors using default keys (e.g., a Lineer key bought at DEF CON) to open these panels must be aware that an unheard alarm might still be activated. This underscores the need for thorough reconnaissance and understanding the target's specific security infrastructure.
Badge Cloning and Access Control:
While often portrayed as high-tech, badge cloning is presented as a method that requires social engineering and careful execution. The speakers note that for years, they primarily relied on piggybacking with forged badges in matching lanyards, as it was effective 90% of the time. However, testing badge system encryption is now critical, requiring tools like the IC copy X or Prox Mark III. They demonstrate methods for covert cloning:
- The "Mr. Robot" Method: Using a HID garage reader (with its larger antenna) integrated with an Arduino or Raspberry Pi inside a bag or clipboard for longer-range reads, including high-frequency badges that a Flipper Zero (which typically handles low frequency) might struggle with. This allows for discreet cloning by "bumping" into targets.
- The Coffee Cup/Clipboard Method: Integrating a Prox Mark III (or similar device) into a Starbucks coffee cup or a specially designed covert clipboard. This allows for natural social interaction (e.g., chatting at a smoke break or lunch spot) while subtly positioning the cloner near a target's badge. The clipboard can also house a badge writer to immediately create a cloned badge.
- The Flipper Zero Coin Toss: A more theatrical, but effective, misdirection technique where a coin is tossed to distract a target, allowing the Flipper Zero to quickly clone a badge that might be hanging at the hip. The speakers note that most consumer-grade badge cloners require close proximity or even touching the badge. They also differentiate between low frequency (easier to clone) and high frequency/NFC (requiring more advanced tools).
Rogue Access Points and Implants:
Planting devices that broadcast Wi-Fi or create rogue APs (like a Pineapple or Doppelganger reader) introduces significant risk. The speakers strongly caution against leaving default settings, using weak encryption, or failing to update firmware, as this creates new vulnerabilities for the client. They also discuss the ESP3 (likely referring to an ESP32-based tool for network access), emphasizing the need for proper punch-down tools to avoid damaging connectors or wires when installing it behind a badge reader. While destructive entry with tools like the ESP key is often met with client resistance due to potential damage or de-certification of secure rooms (SCIFs), they suggest using proof-of-concept videos or lab demonstrations to illustrate the vulnerability without actual destruction on site.
Covert Carry and Reconnaissance:
Successful covert entry relies heavily on discreet movement and equipment. The speakers demonstrate covert carry techniques using specialized clothing designed for operators, featuring hidden pockets and compartments for tools. For surveillance, they advise against obvious behavior like "driving in circles" in a rental car. Instead, they recommend using multiple rental cars, disabling exit lights, learning the car's features to avoid accidental alarms, and practicing long-distance photography with an understanding of camera settings, especially in low light. Radio communication should be minimal, encrypted, and use codes to avoid broadcasting sensitive information.
Demo / Proof of Concept
▶ Watch: Real-world roof entry demonstration video (5:10)
The talk includes several compelling demonstrations and anecdotes that serve as practical proofs of concept for their methodologies:
- Rooftop Entry via Adjacent Hotel Room: A video shows Brent White gaining entry to a target building's roof from an adjacent hotel window. This wasn't a "Mission Impossible" stunt but a simple exploit of building adjacency. By requesting a specific floor and side of a hotel room, they were able to open their window directly onto the target's roof. The rooftop door was then easily bypassed, having been deadbolted from the outside (likely to prevent people from jumping off, not to secure against entry). This highlights that the path of least resistance is often the most effective.
- Social Engineering for Key Handover: Brent describes a situation where Tim built such strong rapport with a security guard that the guard "handed over keys to Tim" with the instruction to "just bring these back when you're ready." This demonstrates the power of human connection and trust in bypassing physical controls, rather than relying on brute force or technical exploits.
- Covert Badge Cloning with Everyday Objects:
- The Starbucks Coffee Cup: Tim and Brent act out a scenario where a badge cloner hidden inside a Starbucks coffee cup is used during a casual conversation at a smoke break or lunch area. While engaging an employee about their "SANS institute lanyard," Tim subtly positions the cup near the employee's badge, cloning it without suspicion. This emphasizes the importance of natural movements and social acceptability.
- The Covert Clipboard: Brent demonstrates an original iteration of their "covert clipboard." This device, which inspired a scene in "Mr. Robot," contains a disassembled Prox Mark III and multiple antennas, along with a badge writer. When brought close to a target's badge, it clones the badge and can alert the assessor's phone. A cloned badge can then be retrieved from a Velcro-secured compartment within the clipboard. Brent recounts an instance where he "badged in with a muffin bag" (containing a cloner) while a security guard was playing on his phone, completely unnoticed.
- Flipper Zero Coin Toss for Misdirection: Brent describes an assessment where Tim used a Flipper Zero. The target employee's badge was sticking out at the hip while sitting at a table. Tim tossed a quarter in the opposite direction, and as the employee looked away, Tim quickly reached out and cloned the badge. This illustrates how simple misdirection can facilitate the use of even common tools like the Flipper Zero in close-quarters cloning.
- Bypassing a Parking Garage Gate: A video shows Brent and Tim bypassing a parking garage gate. Instead of climbing a high hole or cutting fences, Tim steps on Brent's shoulders to reach a mechanism that had the default key still on it, allowing them to push it open. This again underscores the principle of finding the path of least resistance and avoiding unnecessary risk or destructive actions.
Defensive Implications
▶ Watch: Simple hotel room access for roof entry explanation (6:00)
The insights shared by Brent White and Tim Roberts offer critical defensive implications for organizations aiming to bolster their physical security posture:
- Comprehensive Scope Definition for Assessments: Organizations must insist on clearly defined Rules of Engagement (ROE) and Statement of Work (SOW) for physical security assessments. This includes explicitly determining if incident response, alarm testing, or destructive entry are in scope. Ambiguity can lead to unintended consequences, legal issues, or damage.
- Test Compensating Controls: Physical security is not just about locks and doors. Assessors should be authorized to test compensating controls like alarm systems. Defenders should ensure their alarm systems are not easily bypassed (e.g., that rec sensors are tied to alarms, not just crash bars) and that tamper evidence switches on badge readers and access control panels (like Lineer and Door King) are active and monitored.
- Understand Building Management vs. Tenant Responsibilities: Before authorizing any physical security testing, clients must clarify who owns and manages the physical infrastructure. If they are leasing, or if building management controls access systems, their explicit permission is paramount to avoid angering building owners or other tenants.
- Address Social Engineering Vulnerabilities Systemically: Recognize that social engineering is a primary attack vector. Instead of blaming individuals, focus on fostering a security-minded culture rather than just "checkbox" security awareness training. Employees who have witnessed or experienced social engineering firsthand are more likely to become security evangelists. Implement policies that discourage holding doors open for strangers, even those who appear legitimate.
- Secure Badge Systems and Implement RFID Blocking: Organizations should understand the encryption level of their badge systems (low frequency, high frequency, NFC) and invest in more secure options if current ones are easily clonable. Encourage employees to use RFID blocking sleeves or wallets and to be conscious of their badge placement, especially in public areas like lunchrooms.
- Mitigate Rogue AP Risks: Any device that can broadcast a Wi-Fi signal or create a rogue AP (e.g., Pineapple, Doppelganger readers, ESP3) poses a significant risk. Organizations must have robust Wireless Intrusion Detection Systems (WIDS) and policies to detect and prevent unauthorized devices on their network. Crucially, enforce strict configuration management, ensuring all devices have default settings changed, strong encryption enabled, and up-to-date firmware.
- Physical Security Awareness Beyond the Front Door: Defenders should think beyond the main entrance. Consider vulnerabilities like adjacent buildings for rooftop access, exposed wiring closets, or unsecured conference rooms where devices could be planted. Regularly audit physical access points, including less obvious ones like maintenance entrances or parking garage mechanisms.
- Ethical Reporting and Improvement Focus: When receiving assessment reports, focus on the systemic issues and commend good practices. Resist the urge to identify or discipline specific individuals for social engineering failures. Instead, use these findings as opportunities for education and cultural improvement, transforming potential "failures" into learning experiences for the entire organization.
Key Takeaways
- Prioritize Simple Methods and Understanding: The most effective physical security bypasses often exploit basic human psychology or overlooked physical flaws, not complex "Hollywood" tactics. Understand why a vulnerability exists rather than just knowing how to use a tool.
- Social Engineering is a Critical Skill: Beyond just lying, successful social engineering requires deep psychological understanding, regional awareness, and the ability to build rapport. Impersonating law enforcement or emergency services is illegal and unprofessional.
- Meticulous Planning and Scope are Essential: Clearly define Rules of Engagement and the Statement of Work, including whether incident response, alarm testing, or destructive entry are permitted, and understand who manages the physical infrastructure (client vs. building management).
- Be Professional and Client-Focused: The goal is to help the client identify weaknesses, not to embarrass them or security personnel. Always comply with security, avoid confrontation, and never name individuals in reports to prevent job loss. Foster a "security-minded culture."
- Smart Tool Use and Risk Awareness: High-tech tools are only as good as the plan behind them. Be aware of the risks introduced by planting devices like rogue APs (e.g., default settings, weak encryption), and ensure all activities align with the agreed-upon scope and ethical guidelines.
- Discreet Reconnaissance and Covert Carry: Effective physical assessments rely on blending in, being "forgettable," and employing discreet methods for reconnaissance and tool concealment. Avoid obvious behavior and ensure communication is secure.
About the Speaker(s)
Brent White and Tim Roberts are highly experienced physical security penetration testers with over 12 years in the field. They are known for their practical, no-nonsense approach to covert entry assessments, emphasizing professionalism, client empathy, and effective methodologies. Both speakers are involved in teaching and sharing their knowledge, offering workshops on covert methods of entry and improv for social engineering. They operate the website wehackpeople.com, which serves as a resource for their in-depth discussions and materials. Their presentations are characterized by a blend of serious technical content and engaging humor, reflecting their belief that security work can be both professional and fun. They draw from extensive experience working with various companies and agencies, constantly learning from their engagements and interactions within the security community.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
White and Roberts deliver something the physical security space badly needs: a professional ethics and methodology talk that doesn't sacrifice technical substance to get there. The covert clipboard PoC, the alarm-sensor bypass choreography, and the honest treatment of scope failures make this genuinely useful for practitioners at any level.
Heather Calloway (CISO) — SOLID
A competent, practitioner-level DEF CON talk that delivers real value to physical pen testers — professional ethics, planning discipline, and tool pragmatism over Hollywood theatrics. But it stops at the operator layer and never reaches the institutional or governance level where physical security failures actually get fixed.