Fitness of Physical Red Teamers
Lucas Rooyakkers, Billy Graydon
DEF CON 32 Creator Stage · Day 1 · Creator Stage
Overview
In "Fitness of Physical Red Teamers," Lucas Rooyakkers and Billy Graydon deliver a compelling presentation that transcends typical discussions of digital vulnerabilities, delving into the often-underestimated realm of physical security bypasses facilitated by human physical capabilities. The talk highlights how the human body, when appropriately trained, can exploit design flaws and structural weaknesses in commercial and residential buildings, often without the need for specialized tools. This presentation is critical for physical security professionals, red teamers, and anyone involved in designing or securing physical spaces, as it exposes a significant blind spot in many conventional threat models.

Key moments
- 0:00 Introduction to physical red teaming and techniques
- 2:00 Demonstrating brute force door deformation technique
- 2:40 Utilizing building features for climbing and vertical access
- 4:00 Accessing secure areas via false floors/ceilings
- 4:50 Quick video demonstration of barbed wire fence bypass
- 5:50 Introduction to fitness for red team engagements
- 6:20 The life-extending benefits of consistent exercise
Fitness of Physical Red Teamers
Speakers: Lucas Rooyakkers, Billy Graydon
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=ocXSZRKmI0I
Overview
In "Fitness of Physical Red Teamers," Lucas Rooyakkers and Billy Graydon deliver a compelling presentation that transcends typical discussions of digital vulnerabilities, delving into the often-underestimated realm of physical security bypasses facilitated by human physical capabilities. The talk highlights how the human body, when appropriately trained, can exploit design flaws and structural weaknesses in commercial and residential buildings, often without the need for specialized tools. This presentation is critical for physical security professionals, red teamers, and anyone involved in designing or securing physical spaces, as it exposes a significant blind spot in many conventional threat models.
The speakers systematically break down various physical entry techniques, from brute-forcing doors to scaling building exteriors and navigating internal utility shafts. Crucially, they link these bypass methods directly to the physical attributes and fitness levels required of a red team operator. The latter half of the talk pivots to a practical guide on physical training, emphasizing the fundamental movements and workout planning necessary to cultivate the strength, endurance, and flexibility essential for successful physical penetration testing. This holistic approach underscores that effective physical red teaming is not just about technical knowledge but also about the physical readiness of the operator.
The importance of this talk lies in its ability to shift perspectives on physical security. It challenges the assumption that robust locks and access control systems alone constitute adequate protection. By demonstrating how readily an agile and strong individual can exploit architectural and structural vulnerabilities, Rooyakkers and Graydon advocate for a more comprehensive threat model that integrates the human element. For organizations, understanding these physical bypass techniques is paramount to identifying and mitigating real-world risks that often go unaddressed, ultimately leading to more resilient physical security postures.
Background
▶ Watch: Introduction to physical red teaming and techniques (0:00)
The landscape of physical security often prioritizes technological solutions—advanced locks, biometric scanners, surveillance cameras, and alarm systems—while overlooking the fundamental interactions between human physical capabilities and the built environment. This oversight creates a significant gap in an organization's overall security posture. Many building designs and security implementations do not adequately account for the potential for human brute force, climbing, or contortion to bypass what are perceived as secure barriers. The problem isn't necessarily a failure of individual components, but rather a systemic failure in the threat model that governs the design and assessment of physical spaces.
Historically, physical security discussions at conferences like DEF CON's Physical Security Village, particularly in sessions like "Bypass 101," have illuminated the ease with which various locks and access control mechanisms can be defeated using specialized tools or basic lockpicking skills. However, this talk extends that conversation by focusing on tool-less bypasses that rely solely on the physical prowess and understanding of structural weak points by an attacker. The speakers emphasize that these vulnerabilities exist because the original security models for these spaces did not contemplate the human body as an offensive "tool."
A critical underlying issue is the common architectural and security design flaw where doors and other access points are secured primarily for ingress, but their egress functionality is overlooked as a potential entry vector. For instance, a door to a roof may be robustly secured from the ground floor, but once an attacker reaches the roof via climbing, that same door might only be secured in the "exit direction," making it easy to open from the roof side to gain internal building access. This highlights a pervasive design philosophy that often fails to consider multi-faceted attack paths, leaving significant vulnerabilities for those willing and able to physically exploit them.
Key Findings
▶ Watch: Utilizing building features for climbing and vertical access (2:40)
The core findings of this presentation reveal that many common physical security measures are surprisingly vulnerable to human physical exploitation, often without requiring any specialized tools. The speakers detail several categories of bypasses that demonstrate these vulnerabilities:
- Door Deformation and Latch Disengagement:
- Double Doors with Center Mullion: By applying sufficient force and leverage, red teamers can deform the center mullion (the vertical post between the two doors). This deformation allows the door to bow inwards, causing the latch mechanism to disengage from the frame, effectively opening the door. This method exploits the flexibility and structural weakness of the mullion and door frame.
- Double Doors without Center Mullion: In designs where double doors are pinned at the top and bottom but lack a central mullion, pulling hard enough can cause the entire door assembly to bow out of its frame, leading to a complete bypass.
- Pulling Doors Sideways: Applying lateral force to a door within its frame can disengage the latch from the strike plate, opening the door.
- Lifting and Pulling Double-Latch Doors: Certain double-latch door systems can be defeated by a combination of lifting and pulling, unpinning them.
- Garage Door Exploitation:
- Many commercial or residential garage doors have access control on their motorized lifting mechanisms but lack simple physical pinning to secure them in the closed position. A physically capable individual can often reach under the bottom segment of the door and lift it high enough to roll underneath, gaining entry.
- Vertical and Exterior Climbing:
- Rusticated Masonry: Building exteriors with decorative rustication (roughened stone blocks or patterns) provide perfect handholds and footholds, allowing an attacker to climb to upper-story windows or roofs.
- Scaffolding: Temporary construction scaffolding is a significant vulnerability, offering an easy, often unmonitored, pathway to higher floors or the roof. Once on the roof, doors designed for emergency exit (secured only in the "exit direction") can provide easy internal access.
- Fences and Gates: Even seemingly formidable barriers like barbed wire fences can be bypassed. A video demonstration showed an attacker using a fence post for leverage to climb over a barbed wire fence in approximately five seconds, completely defeating its deterrent purpose. Beefy gates can also be climbed over if an individual is agile enough.
- Ladder Cages: While designed to prevent unauthorized climbing, poorly installed or designed ladder cages can sometimes be climbed from the back, or the cage itself can be climbed directly with sufficient upper body strength.
- Internal Vertical Access Exploits:
- False Floors and Ceilings: In server rooms or other sensitive areas, false floors (for cabling) and false ceilings (for utilities) can often be popped open. This allows an attacker to slide underneath or climb through, bypassing conventional room entry points.
- Pipe and Utility Shafts: In multi-tenant high-rise buildings, an attacker gaining access to a less secure adjacent office can exploit pipe shafts, utility shafts, or elevator shafts. By climbing these shafts, they can ascend to a target office's floor and emerge into internal mechanical rooms, bypassing all perimeter security of the target unit. This requires significant physical ability to navigate tight spaces and manipulate delicate ceiling brackets without causing damage.
A recurring theme in these findings is the "anyone can do it" threat model. The speakers emphasize that because many of these bypasses require no specialized tools, they are accessible to a wider range of threat actors, not just highly skilled specialists. This broadens the attack surface significantly and necessitates a re-evaluation of physical security assumptions.
Technical Deep Dive
▶ Watch: Accessing secure areas via false floors/ceilings (4:00)
The technical depth of these physical bypasses lies in understanding the interplay between structural engineering, mechanical design, and human biomechanics. Many of the vulnerabilities highlighted by the speakers stem from designs that prioritize convenience, aesthetics, or cost-effectiveness over comprehensive security, failing to account for specific points of failure under stress or unconventional access methods.
Door Deformation and Latching Mechanisms:
The ability to brute-force commercial doors relies on the inherent flexibility and design tolerances of their components. For double doors featuring a center mullion, the vulnerability arises from the mullion's material properties and its attachment to the door frame. When significant force is applied to one door handle, leveraging the attacker's body weight, the mullion itself acts as a lever. If the mullion is not sufficiently rigid or securely anchored, it can deform or bend laterally. This deformation creates enough lateral displacement in the door frame to cause the latch bolt—the retractable part of the lock that engages with the strike plate in the frame—to pop out of its housing. The door is then free to open. This is a classic example of exploiting structural integrity weaknesses.
For double doors without a center mullion, the attack vector shifts. These doors are typically secured by pins at the top and bottom, which engage with the door frame or floor/ceiling. When pulled with sufficient force, the entire door assembly can bow out from its frame. This bowing action, leveraging the inherent flexibility of the door materials and the clearance within the frame, can cause the top and bottom pins to disengage, allowing the door to be pulled open. Similarly, a door can be pulled to the side within its frame, causing the latch to disengage. This highlights that the tolerance between a door and its frame, intended for smooth operation, can become a security vulnerability when subjected to targeted physical stress.
Garage Door Exploitation:
The security flaw in many garage doors is a fundamental design oversight in access control. While the motor that lifts and lowers the door might be electronically secured, the door itself often lacks a simple, robust physical pinning mechanism that prevents manual lifting when the motor is disengaged or overridden. The motor's inherent resistance might be enough to deter casual lifting, but with sufficient human strength and leverage, the bottom segments of the door can be lifted manually. Once a gap is created, an individual can roll under and gain access. This exposes a critical disconnect between electronic access control and fundamental physical security.
Structural Weaknesses for Climbing:
Building exteriors often present unintended climbing aids. Rustication on masonry, while decorative, provides natural, grippable surfaces that function as a makeshift ladder. The texture and depth of these architectural features can offer perfect handholds and footholds. Scaffolding, by its very nature, is a temporary, accessible, and often unmonitored structure that provides an obvious vertical pathway. Its open framework makes it easy to ascend to multiple stories or the roof. Once on the roof, the security model often changes dramatically. Doors leading from the roof into the building core are frequently designed for emergency egress, meaning they are easy to open from the inside (the roof side) but secured from the outside (the building interior). This "exit direction" security flaw is a common oversight, allowing an attacker who has gained rooftop access to easily enter the building.
Internal Vertical Access Exploits:
Exploiting false floors and false ceilings relies on their lightweight construction and modular design. These panels, typically made of thin aluminum or composite materials, are designed for easy removal to access wiring, plumbing, or HVAC systems. A red teamer with sufficient upper body strength and agility can lift, slide, or remove these panels, creating an opening large enough to squeeze through. The challenge here is often not just strength but also body control and flexibility to navigate tight, confined spaces without causing noise or damage.
Pipe and Utility Shafts represent a more advanced and physically demanding internal bypass. These shafts, which run vertically through multi-story buildings, are conduits for essential services. If an attacker can access a shaft from a less-secure adjacent tenant's space, they can then climb upwards. This requires significant grip strength, upper body strength (lats, forearms, arms, back), and endurance. Navigating these shafts often involves scaling pipes, cables, and structural elements, and then manipulating thin, potentially delicate, ceiling brackets to pop out into a target area, often a mechanical room deep within the building's core. The ability to fit through "fatty filters"—thin gaps or tight spaces—is also crucial here, highlighting the need for body control and, in some cases, a smaller body profile.
Red Team Fitness Components:
The ability to execute these technical bypasses is directly tied to a red teamer's physical fitness. The speakers break down physical fitness into several key components:
- Cardio and Aerobic Capacity: Essential for sustained effort and rapid movement when needed.
- Pure Strength: For lifting heavy objects (e.g., garage doors), applying brute force (e.g., door deformation), and climbing.
- Power and Explosive Capacity: For quick, dynamic movements like jumping over obstacles or rapidly scaling a fence.
- Endurance: The ability to sustain a hard workload over time, crucial for prolonged climbing or navigating complex internal spaces.
- Flexibility: Key for squeezing through tight spaces ("fatty filters"), contorting the body, and preventing injury during dynamic movements.
- Grip Strength: Absolutely critical for climbing, scaling fences, and manipulating objects while suspended.
These physical attributes are not merely supplementary; they are integral to the "technical" execution of physical bypasses. Without the requisite strength, agility, and endurance, many of the identified vulnerabilities would remain unexploitable by a human operator.
Demo / Proof of Concept
▶ Watch: Introduction to fitness for red team engagements (5:50)
The talk effectively utilized visual demonstrations and real-world examples to illustrate the feasibility and simplicity of these physical bypasses. While the transcript mentions "images" and "videos," these typically refer to short clips or still frames displayed during the live presentation rather than a continuous, elaborate demonstration. Nevertheless, the descriptions provided clearly outline the proof-of-concept for each technique.
One prominent demonstration involved the brute-force deformation of double doors with a center mullion. The speakers described and showed (via an image/video) how simply grabbing the handle and pulling hard enough, leveraging body weight, could cause the central post to deform. This deformation, in turn, allowed the door's latch to pop inwards, effectively opening the door without any tools whatsoever. A similar visual was used to explain how double doors without a central mullion could be forced open by causing them to bow out of their frame. These demonstrations underscore the fact that many commercial doors, despite appearing secure, are vulnerable to a determined individual.
Another impactful demonstration was the bypass of a barbed wire fence. A video clip showed an individual bracing themselves against a fence post and using it as leverage to quickly climb over the barbed wire, bypassing the entire barrier in approximately five seconds. This rapid, tool-less bypass highlighted how a common security feature can be rendered useless by exploiting a structural element within its own design.
The speakers also presented visual evidence of climbing techniques, showing how rustication on masonry provides natural hand and foot grips to ascend building exteriors. Images of individuals scaling scaffolding to reach upper windows or roofs further emphasized how temporary construction elements can become critical entry points. The concept of "fatty filters"—thin gaps that require significant body control and flexibility to squeeze through—was also demonstrated, with speaker Billy Graydon sharing his personal experience of how his improved fitness allowed him to navigate these once-impassable spaces.
While not explicit, the discussion of navigating false floors, false ceilings, and pipe shafts implies visual demonstrations or detailed descriptions of these maneuvers, showcasing the level of body control and upper body strength required to lift panels, squeeze through tight openings, and drop down into secure areas. These "proofs of concept," whether live or pre-recorded, served to validate the speakers' claims, making the vulnerabilities tangible and illustrating that these are not theoretical exploits but practical, real-world attack vectors.
Defensive Implications
▶ Watch: The life-extending benefits of consistent exercise (6:20)
The insights shared in "Fitness of Physical Red Teamers" carry profound defensive implications for organizations and physical security professionals. The primary takeaway is the urgent need to re-evaluate and expand existing physical threat models to include the human element, specifically the physical capabilities of an attacker and the structural weaknesses of the built environment.
- Comprehensive Door Security Audits:
- Defenders must move beyond just inspecting locks and access control systems. A thorough audit should involve physically testing doors for their susceptibility to brute-force deformation. This includes pulling double doors with significant force to check the integrity of center mullions and the rigidity of door frames.
- For garage doors, relying solely on motor-based access control is insufficient. Implement robust physical pinning mechanisms (e.g., floor bolts, heavy-duty slide locks) that secure the door independently of the motor, preventing manual lifting.
- Ensure all latching mechanisms are deeply engaged within their strike plates and that the door-to-frame tolerances are minimal to prevent lateral disengagement.
- Exterior Building Fortification and Reconnaissance:
- Conduct detailed exterior assessments to identify any features that could aid climbing. This includes removing or securing temporary structures like scaffolding promptly.
- Evaluate building facades for rustication, decorative ledges, pipes, or other architectural elements that can serve as handholds or footholds, especially near windows or roof access points. Where possible, install anti-climb measures or remove these features.
- Address fence vulnerabilities by ensuring that fence posts are not easily used for leverage and that barbed wire or other deterrents are continuous and uncompromised.
- Secure Vertical Access Points:
- False floors and ceilings in sensitive areas (e.g., server rooms, data centers) must be secured. This might involve locking panels, using heavier-duty materials, or installing sensors that detect panel removal.
- Critically, pipe, utility, and elevator shafts in multi-tenant high-rise buildings need to be secured at all levels. This means ensuring that access to these shafts from less-secure offices is blocked, and that any internal access points from the shafts into tenant spaces (e.g., mechanical rooms) are robustly sealed and monitored. The integrity of thin aluminum ceiling brackets should not be the only barrier.
- Rethink "Exit Direction" Security:
- Any door designed primarily for egress (e.g., roof access doors, emergency exits) should be evaluated for its vulnerability as an ingress point. If an attacker can reach the "inside" of such a door (e.g., the roof), it should be as secure as any other entry point. Consider robust locking mechanisms on both sides or alarms that trigger upon unauthorized opening.
- Integrate Physical Fitness into Red Team Assessments:
- Organizations performing or commissioning physical penetration tests should ensure that their red team operators are physically capable of executing these types of bypasses. This requires red team leaders to consider the physical fitness of their team members and potentially incorporate fitness training into their professional development. A physically fit red team provides a more realistic assessment of real-world threats.
- Continuous Monitoring and Training:
- Implement regular physical security patrols that specifically look for these types of vulnerabilities.
- Train security personnel to recognize and report potential climbing aids or structural weaknesses.
- Foster a culture where everyone, from building management to employees, understands their role in maintaining physical security and reporting suspicious observations.
By proactively addressing these physical vulnerabilities, defenders can significantly enhance their overall security posture, mitigating risks that are often overlooked in a digitally focused security landscape.
Key Takeaways
- Physical Security Overlooks Human Capabilities: Many physical security designs fail to account for the strength, agility, and ingenuity of a human attacker, leading to easily exploitable vulnerabilities.
- Tool-Less Brute Force is a Real Threat: Common commercial doors, fences, and structures can be bypassed using only human physical force and leverage, often without specialized tools, by exploiting structural weaknesses like deformable mullions or unpinned garage doors.
- Vertical Access is a Major Vulnerability: Building exteriors (rusticated masonry, scaffolding) and internal shafts (pipe, utility, elevator shafts, false floors/ceilings) provide critical, often overlooked, pathways for unauthorized entry, especially in multi-tenant high-rise buildings.
- Threat Models Must Evolve: Organizations need to update their physical security threat models to include these physical bypass techniques, moving beyond just lockpicking or electronic access control vulnerabilities.
- Physical Fitness is an Essential Red Team Skill: For effective physical penetration testing, red team operators require specific physical attributes including grip strength, upper body strength, endurance, flexibility, and body control to execute these bypasses successfully.
- Fitness Benefits Extend Beyond Red Teaming: Engaging in regular moderate-to-intense exercise (recommended 150 minutes per week) not only enhances a red teamer's operational capacity but also provides significant long-term health benefits, including increased lifespan.
About the Speaker(s)
Lucas Rooyakkers is a security professional who focuses on the health and fitness aspects crucial for effective physical red teaming. In this talk, Lucas outlines the fundamental movements of the human body and provides guidance on workout planning, emphasizing how targeted physical training can significantly increase a red teamer's capacity for complex engagements. He advocates for the integration of physical fitness into a security professional's routine, highlighting its benefits for both operational success and personal well-being.
Billy Graydon is an experienced physical security expert and red team operator, deeply involved in the DEF CON Physical Security Village and "Bypass 101" sessions. Billy presented the practical, real-world physical bypass techniques, drawing from his extensive experience in penetration testing engagements. He shared personal anecdotes, including his journey of losing 100 pounds, which improved his ability to navigate tight spaces, humorously referred to as "fatty filters," underscoring the direct impact of physical fitness on operational capabilities in the field. His insights highlight how common architectural and structural elements can be exploited to gain unauthorized access.