Physical OSINT

Lukas McCullough

DEF CON 32 Creator Stage · Day 1 · Creator Stage

Overview

In his DEF CON 32 talk, "Physical OSINT," Lukas McCullough, a graduate student specializing in cybersecurity and criminal justice, illuminated the critical, yet often underestimated, intersection of open-source intelligence (OSINT) and physical security. McCullough, drawing from his experience with the Physical Security Village and his foundational work with Trace Labs, presented a compelling case for how publicly available information can be meticulously gathered and weaponized to facilitate physical security breaches, social engineering attacks, and ultimately, gain unauthorized access to facilities. The talk served as a stark reminder that robust digital defenses can be circumvented if physical vulnerabilities, exposed through OSINT, are not adequately addressed.

Watch on YouTube

Visual summary for Physical OSINT by Lukas McCullough
Visual summary for Physical OSINT by Lukas McCullough

Key moments

  1. 0:00 Speaker introduction and defining open source intelligence
  2. 2:00 The security risk of posting new employee badges
  3. 2:25 Maltego, Whois, and Shodan for OSINT investigations
  4. 3:30 Using Wigle.net for war driving and WiFi networks
  5. 4:05 Exploring OSINT frameworks to find useful tools
  6. 5:00 Google dorking to uncover building floor plans
  7. 6:00 Discovering Master Lock's 'restricted' firing template publicly
  8. 6:45 Identifying social engineering leads from public company contracts

Physical OSINT

Speakers: Lukas McCullough

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=ksbFhXdF2EI

Overview

In his DEF CON 32 talk, "Physical OSINT," Lukas McCullough, a graduate student specializing in cybersecurity and criminal justice, illuminated the critical, yet often underestimated, intersection of open-source intelligence (OSINT) and physical security. McCullough, drawing from his experience with the Physical Security Village and his foundational work with Trace Labs, presented a compelling case for how publicly available information can be meticulously gathered and weaponized to facilitate physical security breaches, social engineering attacks, and ultimately, gain unauthorized access to facilities. The talk served as a stark reminder that robust digital defenses can be circumvented if physical vulnerabilities, exposed through OSINT, are not adequately addressed.

McCullough defined OSINT broadly as any usable information found on the internet that does not require hacking or payment, emphasizing a "broke college student" approach to intelligence gathering. This talk is particularly relevant in an era where digital footprints are vast, and the line between online persona and real-world vulnerability is increasingly blurred. By demonstrating how seemingly innocuous details – from social media posts about new employment badges to publicly listed commercial property floor plans – can be pieced together, McCullough underscored the imperative for individuals and organizations alike to re-evaluate their information exposure and its potential physical security ramifications.

The presentation was not merely theoretical; it provided practical methodologies and toolsets that bridge the gap between digital reconnaissance and tangible, real-world actions. McCullough’s insights are crucial for security professionals, red teamers, and anyone responsible for organizational security, offering a comprehensive look at how to leverage OSINT for both offensive physical penetration testing and, more importantly, for developing proactive defensive strategies against such threats. It highlights that understanding the attacker's perspective, rooted in accessible public data, is the first step toward building resilient physical security postures.

Background

▶ Watch: Speaker introduction and defining open source intelligence (0:00)

The concept of Open-Source Intelligence (OSINT) has gained significant traction in the cybersecurity community, primarily focusing on digital reconnaissance – gathering information about targets from publicly available online sources. Lukas McCullough's journey into OSINT began with Trace Labs, a non-profit organization that crowdsources OSINT investigations to help find missing persons. This experience honed his skills in identifying actionable intelligence from vast amounts of public data, a methodology he credits in part to mentors like Joe Gray from Ocention.

Traditionally, OSINT applications have centered on profiling individuals or organizations through their digital presence. Common resources include social media platforms like LinkedIn, Instagram, and Facebook, where individuals often post details about their careers, personal lives, and aspirations. Attackers can leverage this information to construct detailed profiles of targets, identify their social networks, and even "insert themselves into their story" through social engineering. A particularly salient example highlighted by McCullough is the seemingly innocent act of posting a photo of a new employee badge on social media. While intended as a celebratory gesture, such an act immediately reveals the badge's appearance, the employee's role, and their status as a "new person," making them a prime target for social engineering and potentially aiding in the creation of convincing fake credentials or impersonation.

The underlying problem that enables physical OSINT is a combination of pervasive digital oversharing and the inherent transparency required for many commercial and public operations. Companies, in their efforts to attract tenants or customers, often publish detailed information about their premises, including floor plans, amenities, and even other high-profile tenants. Similarly, public records, commercial databases, and even seemingly benign platforms like Google Maps and review sites, inadvertently expose critical physical security details. This wealth of readily available information creates a fertile ground for adversaries seeking to bypass physical controls, making the bridge between digital OSINT and real-world physical security a critical area of focus.

Key Findings

▶ Watch: Maltego, Whois, and Shodan for OSINT investigations (2:25)

McCullough's presentation unveiled several critical findings demonstrating the potent capabilities of physical OSINT:

  • Ubiquitous Exposure of Sensitive Corporate Documents: A significant discovery was the ease with which sensitive internal corporate documents can be uncovered through simple Google Dorking. McCullough illustrated this with Master Lock, where a specific search query (Master Lock [address] filetype:pdf) yielded a "restricted information" document detailing their employee termination procedures. Similarly, a contract between Master Lock and the State of Wisconsin, found publicly, exposed specific contact names, phone numbers, and emails, creating a direct avenue for social engineering attacks by enabling an attacker to act as a "middleman" between two parties. This highlights a pervasive issue where organizations inadvertently publish data that, while perhaps not classified, becomes highly exploitable in context.
  • Commercial Property Information as a Goldmine: A core finding was that commercial rental properties, especially high-rises, are an invaluable source of physical intelligence. Because few companies own their offices, landlords frequently publish detailed floor plans, lists of prominent tenants, and building specifications to attract renters. These plans are often uniform across multiple floors, meaning one publicly available floor plan can provide a complete layout for an entire building. This information is a critical resource for planning physical reconnaissance or penetration tests, revealing entry points, internal layouts, and potential access control weaknesses.
  • Geolocation Tools Provide Actionable Baselines: Tools like GeoSpy AI were shown to provide a robust initial assessment of an image's geographic origin. While not always pinpoint accurate (e.g., mistaking Shanghai for Hong Kong, a 760-mile difference), McCullough demonstrated its utility in narrowing down locations significantly, often to within a few kilometers. This capability provides a crucial starting point for further, more precise, manual verification, drastically reducing the time and effort required for geographical reconnaissance.
  • Public Image Repositories Reveal Physical Security Details: Platforms like Google Review Images and Google Maps Street View were presented as rich, underutilized sources for physical security information. McCullough showcased how images posted by customers in reviews can expose internal layouts, the presence and placement of security monitors, and the locations of internal cameras. Similarly, Street View allows for a virtual walkthrough of a building's exterior, revealing external camera placements, blind spots, entrances, and egresses. These findings underscore that seemingly benign user-generated content directly contributes to a comprehensive physical security profile of a target.
  • The Power of Combining Disparate Data: Ultimately, the key finding is the synergy achieved by combining various OSINT techniques and tools. From linking domain names to server IPs via Whois and then to exposed technologies via Shodan, to correlating Wi-Fi network data from Wigle.net with physical observations from Google Street View, McCullough illustrated how diverse data points coalesce to form a comprehensive intelligence picture, enabling sophisticated physical security assessments and social engineering campaigns.

Technical Deep Dive

▶ Watch: Exploring OSINT frameworks to find useful tools (4:05)

McCullough delved into a suite of powerful OSINT tools and techniques, demonstrating their application in building a comprehensive physical intelligence picture.

The initial phase of any OSINT investigation often begins with Maltego. This graphical link analysis tool allows investigators to connect disparate pieces of information – such as names, email addresses, phone numbers, or company identifiers – and visualize the relationships between them. Maltego aggregates data from numerous public databases and APIs, acting as a central hub for discovering new leads and expanding the scope of an investigation. While McCullough acknowledged not having accessed all its APIs, he emphasized its utility as a powerful starting point for any OSINT inquiry, revealing connections that might otherwise remain hidden.

For corporate targets, understanding their digital infrastructure is often a precursor to physical reconnaissance. Whois is a fundamental tool for this, translating domain names into server IP addresses. This step is crucial for transitioning from a company's web presence to its underlying network infrastructure. Once an IP address is identified, Shodan becomes invaluable. Often dubbed the "search engine for the Internet of Things," Shodan scans the internet for publicly accessible devices and services, revealing open ports, running services, banner information, and even the operating systems hosted on specific server IPs. This provides an attacker with a detailed technological fingerprint of a company's exposed infrastructure, which can indicate potential vulnerabilities or even the types of physical devices present on a network.

Physical reconnaissance also heavily relies on understanding wireless networks. Wigle.net serves as a public repository for war-driving data, containing a vast database of Wi-Fi networks, their SSIDs, and associated MAC addresses. By analyzing Wigle.net data for a target location, an investigator can identify active Wi-Fi networks, infer the presence of specific hardware manufacturers (based on MAC address prefixes), and cross-reference this with visual information (e.g., a Cisco router seen in a Google review image) to confirm the specific network infrastructure in use.

Beyond individual tools, McCullough highlighted the importance of OSINT frameworks. These are curated, often web-based, collections of categorized tools and resources designed to guide investigators through various types of information gathering, from email addresses and usernames to language preferences and financial data. These frameworks help structure investigations and introduce users to a wide array of specialized tools, enabling them to build personalized routines for their OSINT operations.

A cornerstone of physical OSINT, as demonstrated by McCullough, is advanced Google Dorking. This technique involves using specific search operators to refine Google queries and uncover information not easily found through standard searches. For physical security, this includes:

  • filetype:pdf combined with an address or company name to locate floor plans, rental agreements, internal policies, or contracts. McCullough's example of finding Master Lock's employee firing template and a contract exposing contact details perfectly illustrates the power of this technique for uncovering sensitive documents that could be leveraged for social engineering or understanding internal operations.
  • Searching for commercial property listings ([city] [address] office for rent) can yield detailed floor plans, virtual tours, and lists of other tenants, providing invaluable intelligence on building layouts, security features, and potential access points. McCullough noted that high-rise buildings often have uniform floor plans, meaning one discovered plan can serve as a blueprint for multiple floors.

Finally, McCullough introduced GeoSpy AI, a novel tool for image geolocation. By uploading an image, GeoSpy AI attempts to determine its approximate location. While he noted its occasional inaccuracies (e.g., 760 miles off between Shanghai and Hong Kong), he emphasized its utility in providing a "good baseline" for further manual verification, noting another instance where it was only 3 kilometers off. This tool significantly accelerates the initial stages of geographically-focused investigations, allowing investigators to quickly narrow down potential locations for further analysis using tools like Google Maps Street View or satellite imagery.

Demo / Proof of Concept

▶ Watch: Google dorking to uncover building floor plans (5:00)

Lukas McCullough presented a compelling "applied OSINT vignette" to demonstrate the practical application of these techniques, focusing on a real-world investigation of a massage parlor for a local department. This case study effectively illustrated how seemingly innocuous public information can be pieced together to build a detailed physical security profile.

The investigation began with Google Review Images. McCullough highlighted specific images posted by customers:

  • One image showed a hallway with three distinct doors, providing an initial layout of internal spaces.
  • Another image revealed a monitor within a room. Critically, McCullough noted that "every single room has one," and these monitors display "every camera location." This single piece of information, publicly available, provided a comprehensive overview of the target's internal surveillance system from an attacker's perspective.
  • A third image clearly depicted one of these cameras positioned directly above a door, confirming the visual evidence from the monitor.

Building on this internal reconnaissance, McCullough then moved to external analysis using Google Maps Street View. By dropping a pin on the location and virtually navigating around the building, he identified several key external security features:

  • A large camera on the roof, strategically positioned to cover the first three parking lot spots and the area further behind them. This immediately identified a primary external surveillance zone.
  • A second camera, highlighted in red, was clearly visible facing the main entrance door, ensuring a recording of anyone attempting to enter the front.
  • Further investigation revealed a back door to the premises. Crucially, a camera was also present at this back entrance, but McCullough observed that it was "only facing one way." This critical detail immediately suggested a potential blind spot: "if you wanted to enter from the back, you could go... from the west and then you no one would know."

This vignette served as a powerful proof of concept, demonstrating how a combination of user-generated content (Google Review Images) and publicly accessible mapping services (Google Maps Street View) can yield a comprehensive understanding of a target's physical security posture – including internal layouts, surveillance system coverage, and potential vulnerabilities like camera blind spots – without ever having to physically visit the location. The implications for planning a physical penetration test or a social engineering attempt are profound, as an attacker could meticulously plan their approach based on this intelligence.

Defensive Implications

▶ Watch: Identifying social engineering leads from public company contracts (6:45)

The detailed insights provided by Lukas McCullough's talk on Physical OSINT offer critical defensive implications for individuals and organizations striving to bolster their security postures. Understanding how attackers leverage publicly available information is the first step toward mitigating these risks.

First and foremost, employee awareness training is paramount. Organizations must educate their staff about the dangers of oversharing on social media. Celebrating a new job with a photo of a company badge, discussing project details, or inadvertently revealing office interiors can provide invaluable intelligence to adversaries. Training should cover what constitutes sensitive information in a physical context and emphasize the importance of privacy settings and discretion when posting online.

Secondly, organizations need to conduct proactive information governance audits of their public-facing data. This involves systematically searching for company documents, floor plans, contracts, and other materials that might be inadvertently exposed through public websites, cloud storage, or even commercial rental listings. Employing Google Dorking against their own domains and associated entities (e.g., landlords, contractors) can reveal sensitive PDFs, internal templates (like Master Lock's firing policy), or contact details that could be used for social engineering. Regular review of these findings is essential to prevent such information from being weaponized.

Thirdly, physical security teams should integrate OSINT techniques into their vulnerability assessments and red teaming exercises. By adopting an attacker's mindset, defenders can use tools like Wigle.net to map out their own Wi-Fi networks, Shodan to identify exposed services, and Google Maps/Street View to identify external camera blind spots, entry/egress points, and potential areas for covert access. Analyzing Google Review Images for their own facilities can reveal how customers perceive and photograph internal spaces, potentially exposing security monitors, camera placements, or internal layouts that could be exploited. This proactive reconnaissance allows organizations to identify and remediate physical vulnerabilities before an attacker discovers them.

Furthermore, companies occupying commercial properties, especially in multi-tenant buildings, should be acutely aware of the information published by their landlords or real estate agents. Detailed floor plans and building directories can provide adversaries with comprehensive blueprints. Organizations should advocate for minimal disclosure of sensitive layout information in public listings or ensure that any published plans are sufficiently sanitized to remove critical security details.

Finally, the increasing sophistication of geolocation tools like GeoSpy AI underscores the need for caution regarding images shared online. Organizations and individuals should be mindful of metadata in photographs and consider removing it or blurring identifiable landmarks if the image is to be publicly shared, especially if it relates to sensitive locations. By implementing these defensive strategies, organizations can significantly reduce their digital footprint's contribution to physical security risks and build a more resilient defense against sophisticated, OSINT-driven attacks.

Key Takeaways

  • Physical Security is a Direct Extension of Digital OSINT: Information gathered online, from social media posts to corporate documents, directly contributes to an attacker's ability to plan and execute physical security breaches or social engineering attacks.
  • Oversharing is a Significant Threat: Both individuals (e.g., new badge photos) and organizations (e.g., publicly posted contracts, floor plans) routinely expose sensitive details that can be leveraged for reconnaissance and attack planning.
  • Powerful OSINT Tools Bridge the Digital-Physical Gap: Tools like Maltego for data correlation, Shodan for infrastructure mapping, Wigle.net for Wi-Fi reconnaissance, and GeoSpy AI for image geolocation provide comprehensive capabilities for physical intelligence gathering.
  • Google Dorking and Public Mapping Services are Invaluable: Advanced search queries can unearth restricted corporate documents, while Google Maps Street View and user-contributed review images offer detailed visual intelligence on building layouts, camera placements, and access points.
  • Commercial Property Listings are a Reconnaissance Goldmine: Rental advertisements and property websites frequently expose detailed floor plans and tenant information, providing blueprints for entire buildings, especially high-rises with uniform layouts.
  • Proactive Defense Requires an Attacker's Mindset: Organizations must conduct internal OSINT audits and red team exercises to identify their own physical vulnerabilities exposed through public information, fostering employee awareness and robust information governance.

About the Speaker(s)

Lukas McCullough is a speaker from the Physical Security Village, a community dedicated to exploring and understanding physical security. He is currently a graduate student at Boston University (BU), pursuing a dual major in Cybersecurity and Criminal Justice. McCullough's interest and expertise in Open-Source Intelligence (OSINT) were significantly shaped by his early involvement with Trace Labs, a non-profit organization that crowdsources OSINT investigations to help find missing persons. He also credits Joe Gray from Ocention as a key mentor who taught him much of what he knows in the field. McCullough's background uniquely positions him to bridge the gap between digital intelligence gathering and its real-world physical security implications.

All talks from DEF CON 32 Creator Stage