Skip to main content

Physical Red Team Wiki

Welcome to the Physical Red Team Wiki, a centralized, community-oriented knowledge repository focused on physical penetration testing, mechanical bypass techniques, access control hardware, and security assessments.

Disclaimer & Authorized Use Policy

All information, research, and technical material published on this website and wiki are strictly intended for authorized physical security assessments, academic research, and defensive educational purposes.

Attempting to bypass, tamper with, or manipulate locks, security mechanisms, or physical access control systems without prior, explicit, and written authorization from the verified property or system owner is illegal and punishable under applicable local, state, and federal laws. The author assumes no responsibility or liability for any misuse, damage, or unlawful actions conducted with the information provided on this platform.


Purpose

Physical security knowledge is often decentralized—scattered across individual blogs, security conference presentations, specialized forums, and field notes.

The goal of this wiki is to consolidate practical, structured research into an easily navigable reference covering:

  • Field Identification: Recognizing cylinders, multiplex keyways, credentials, exterior laser markings, and hardware in the field.
  • Lock Mechanisms: Pin tumbler, wafer, tubular, Small & Large Format Interchangeable Cores (SFIC/LFIC), mechanical safe locks, and contactless RFID systems.
  • Obstacles & Defenses: Perimeter barriers, door assemblies, egress hardware, commercial burglary safes (UL 687), GSA security containers, and electronic access controls.
  • Bypass Techniques: Single pin picking, optical key reading, master key mathematical reconstruction, mechanical safe manipulation, keypad brute-forcing, and RFID exploits.
  • Tools & Equipment: Picks, tensioners, code origination machines (HPC Blitz), electronic diagnostic gear (Proxmark3, ESPkey), and standardized elevator service keys.
  • Standards & Field Ops: Pinning specifications, ASIS/IES defense-in-depth standards, TSA travel regulations, and operational Letters of Authorization (LoA).

Wiki Directory

Quickly explore the main categories of the wiki:

SectionDescriptionQuick Link
IdentificationField workflows, cylinder formats, multiplex keyways, and RFID credential laser markings.Explore Identification
MechanismsPin tumbler, wafer, tubular, SFIC/LFIC dual shear lines, safe wheel packs, and RFID/1-Wire.Explore Mechanisms
Obstacles & DefensesDoors, egress devices, commercial safes (UL 687), GSA security containers, and electronic access.Explore Obstacles
TechniquesLock picking, key decoding math, safe manipulation graphing, pushbutton brute-forcing, and RFID attacks.Explore Techniques
Tools & EquipmentPicks, bypass gear, HPC code machines, Proxmark3, ESPkey, and ubiquitous elevator service keys.Explore Tools
Resources & StandardsPinning matrices, ASIS/IES standards, TSA travel regulations, glossary, and engineering archives.Explore Resources

Project Structure & Curation

  • Curated By: Bryan Wendt
  • Philosophy: Open-source knowledge sharing, continuous refinement, and practical defensive insight through red team understanding.
  • Coverage: Content is continuously updated as new tools, mechanisms, and real-world observations are documented.

Feedback & Contributions

If you spot inaccuracies, outdated information, or have suggestions for new tools and techniques to document, please open an issue or reach out via GitHub or Discord.