The Pentesting Kit: Hardware and Tools for Physical Assessments
A physical pentesting kit is only as good as the engagement it is built for. That said, there is a core set of hardware that covers most scenarios. Here is what goes in the bag.
Network implants
- LAN Turtle - USB Ethernet adapter with a hidden Linux box inside. Plug it between a workstation and the network drop, get remote access via reverse SSH. Invisible to the user.
- Shark Jack - Automated network attack tool. Plug into an open port, it runs your payload (nmap scan, loot grab, reverse shell) and stores results onboard.
- Packet Squirrel - Inline network implant for packet capture and man-in-the-middle. Sits between a device and the network transparently.
- Raspberry Pi - The Swiss army knife. Load it with Kali or P4wnP1 ALOA, configure as a drop box with LTE uplink for persistent remote access.
Wireless
- Alfa AWUS036ACH - Dual-band USB WiFi adapter with monitor mode and packet injection. The standard for wireless assessments.
- WiFi Pineapple - Rogue AP platform. Evil twin attacks, captive portal credential harvesting, WPA handshake capture. The Mark VII is the current generation.
- HackRF One - Software-defined radio covering 1 MHz to 6 GHz. Useful for analyzing proprietary wireless protocols, garage door openers, key fobs, alarm systems.
- Ubertooth One - Bluetooth sniffing and injection. Captures Bluetooth Classic and BLE traffic.
- Flipper Zero - Multi-tool for sub-GHz, NFC, RFID, infrared, and GPIO. Good for quick recon and proof-of-concept demonstrations.
RFID and access control
- Proxmark3 RDV4 - The gold standard for RFID/NFC research. Reads, clones, and emulates low-frequency (125 kHz) and high-frequency (13.56 MHz) cards. Supports HID, EM4100, MIFARE Classic, DESFire, iCLASS.
- ACR122U - Budget NFC reader/writer. Good enough for reading card UIDs and basic MIFARE operations.
- iCopy-X - Standalone RFID cloner. No laptop needed. Read a badge, write it to a blank card in seconds.
USB attacks
- USB Rubber Ducky - Keystroke injection tool disguised as a USB flash drive. Types pre-programmed payloads at 1000+ WPM. Bypass endpoint protection by acting as a keyboard, not storage.
- Bash Bunny - Multi-vector USB attack platform. Can emulate keyboards, ethernet adapters, serial devices, and mass storage simultaneously.
- O.MG Cable - Looks exactly like a normal USB cable. Contains a WiFi-enabled implant for remote keystroke injection. Undetectable by visual inspection.
Physical bypass
- Lock pick set - A quality set with tension wrenches, hooks, rakes, and diamonds. Peterson or Sparrows are solid brands.
- Bypass tools - Shove knives, traveler hooks, under-door tools. Many commercial locks can be bypassed without picking.
- Bump keys - Work on pin tumbler locks. Carry a set covering common keyways (Schlage, Kwikset, Yale).
The bag itself
Use something inconspicuous. A laptop backpack or camera bag, not a tactical MOLLE pack. The whole point of physical assessment is blending in. Label everything clearly so you can demonstrate to security guards that you are authorized if challenged.
Every engagement is different. Scope determines which tools go in the bag. A corporate office assessment needs different gear than a data center or manufacturing facility. Build your kit around your most common engagement types and expand from there.