APCAF Fundamentals

Learn APCAF

A practical, 15-minute introduction to adversarial physical-control assessment. Master the mental model, passive inspection boundaries, and core techniques without technical fluff.

Lesson 01 2 min read

The Problem: Why "Paper Existence" Fails

In traditional compliance audits (like ISO 27001 or PCI DSS), an assessor walks through a facility with a clipboard and checks: "Is there a physical lock on the server room door? [Yes / No]".

The Fundamental Flaw:

"The door has a lock" ≠ "The door resists known bypass techniques."

A facility can have 100% paper compliance while remaining completely vulnerable to trivial, seconds-long physical bypasses. A door can have an expensive electronic lock installed, but if the contractor leaves an outward-swinging 4.5mm frame gap without an astragal guard, an attacker can slip the latch in 5 seconds with a $5 shove tool.

Traditional Checklist Approach

Verifies whether hardware is physically mounted on the door. Concludes the control is "Compliant" regardless of installation defects or bypass susceptibility.

APCAF Adversarial Assessment

Deterministically measures whether the installed hardware resists common bypass mechanics under passive 45-second verification.

Lesson 02 3 min read

The APCAF Model: The 5-Step Evaluation Chain

To replace arbitrary checklists with rigorous engineering, APCAF structures all physical assessments around a deterministic 5-step mental pipeline. We use a single server room door example throughout:

01. TACTIC
The Attacker's Goal
Portal Ingress: The adversary wants to get through the door.
02. TECHNIQUE
The Bypass Mechanism
Latch Slip (PHY-T1002): Manipulate the latch bolt through an exposed frame gap.
03. OBSERVATION
The Physical Check
Feeler Gauge: Assessor checks if frame gap > 3.2mm per NFPA 80 without an astragal.
04. ASSESSMENT
The Classification
Legacy / Soft Defect: Physical conditions allow bypass without a key.
05. REMEDIATION
The Warranty Fix
PHY-M1002: General Contractor mounts steel astragal under contract warranty ($0 capex).

Notice how Step 5 finishes with a Contractor Warranty Remediation. APCAF findings are not expensive capital requests; they are installation defects that general contractors must fix at $0 additional cost to the client before final invoice payment.

Lesson 03 2 min read

Tactics vs. Techniques: Understanding the Matrix

APCAF borrows MITRE ATT&CK's core behavioral separation:

  • Tactic = What the attacker wants to achieve (Spatial or access objective).
  • Technique = How the attacker attempts to achieve it (Specific physical/hardware mechanism).

APCAF organizes the entire physical attack surface into 5 Core Tactics:

PHY-TAC-01: Perimeter Breach — Defeating outermost fences, gates, or vehicle barriers.
Planned
PHY-TAC-02: Credential Intercept — Wireless token harvesting, cloning, or relay attacks.
PHY-T1001 Active
PHY-TAC-03: Portal Ingress — Defeating doors, latch assemblies, and exit sensors.
PHY-T1002 & T1003 Active
PHY-TAC-04: Containment Bypass — Breaching server racks, sub-floor runs, and plenums.
Planned
PHY-TAC-05: Interface & Tap — Unauthenticated physical network or serial hardware access.
PHY-T1004 Active
Lesson 04 3 min read

Passive Assessment: The Non-Invasive Safety Boundary

This is the most critical distinction in APCAF:

The Core Operational Rule:

APCAF does not require you to break or pick the control to assess it.

Many organizations avoid physical security testing because they believe it requires aggressive red-teaming: lockpicks, broken doors, or unauthorized trespassing. APCAF replaces destructive testing with non-invasive QA verification:

Active Exploitation (Red Team)

"Let me try to defeat this door."
Uses lockpicks, shove knives, or bypass tools to breach the threshold. Carries high operational risk and legal liability.

APCAF Passive Assessment (Hardware QA)

"Let me determine whether the physical conditions required for this bypass exist."
Uses pocket feeler gauges and passive RF listeners to inspect compliance with engineering standards (e.g. NFPA 80 3.2mm limit).

Because APCAF is completely passive and non-destructive, it can be executed legally during standard facility commissioning walks under a single-sentence SOW authorization.

Lesson 05 4 min read

The Four MVP Techniques in Plain English

Here are the four active baseline techniques evaluated during an APCAF walkthrough. We explain each in human terms before referencing the technical standard ID:

1. Wireless Badge Interception (RFID Harvesting)

PHY-T1001

In Plain English: An attacker gets close to an employee's badge in a coffee shop or elevator and wirelessly copies their ID in under 3 seconds without touching them.

What is attacker trying to do?Clone authorized employee credentials to open electronic readers.
What does assessor look for?Does the badge transmit an unencrypted 125 kHz Prox carrier or static CSN instead of AES-128 crypto?
What counts as susceptible?Card immediately outputs plaintext facility code on a pocket interrogator.
Contractor Warranty Fix:Replace legacy badges with AES-128 smartcards (DESFire EV3 / Seos) under contract warranty.

2. Door Latch Manipulation (Latch Slip & UDT)

PHY-T1002

In Plain English: An attacker slips a thin plastic card or shove knife through the gap between the door and frame to pop the lock open.

What is attacker trying to do?Retract the door latch bolt without a valid key, badge, or credential.
What does assessor look for?Is the strike jamb clearance > 3.2mm (NFPA 80 / ANSI SDI limit) without a protective steel astragal plate?
What counts as susceptible?Clearance > 3.2mm with direct line-of-sight to the bevel of the latch bolt.
Contractor Warranty Fix:Install full-height continuous stainless steel security astragal latch guard.

3. Request-to-Exit Sensor Blind Activation

PHY-T1003

In Plain English: An attacker sprays cold air or slides a tool under the door to trick the interior exit sensor into unlocking the door for them from the outside.

What is attacker trying to do?Trigger the internal motion sensor (REX) to drop magnetic locks automatically.
What does assessor look for?Is the interior PIR sensor visible through door gaps without a directional deflector hood?
What counts as susceptible?Unshielded wide-angle sensor lens visible through transom or threshold sweeps.
Contractor Warranty Fix:Mount UL-listed directional deflector hoods over PIR sensors and install perimeter brush sweeps.

4. Unauthenticated Physical Network Port Tap

PHY-T1004

In Plain English: An attacker plugs a laptop or rogue mini-device into an active wall jack in a conference room and gets immediate internal network access.

What is attacker trying to do?Establish Layer 1/2 connection to internal VLANs from unrestricted public areas.
What does assessor look for?Does a passive zero-packet LED tester illuminate a solid link light on unmonitored wall drops?
What counts as susceptible?Active Layer 1 PHY link signaling without 802.1X port isolation or quarantine.
Contractor Warranty Fix:Administratively disable unassigned switch ports and enforce 802.1X Network Access Control.
Lesson 06 Interactive Sandbox

Run Your First APCAF Assessment

Put the fundamentals to work. Walk through a simulated inspection of "Acme Financial Data Center" and match each real-world observation to its corresponding APCAF technique:

Checkpoint 01 • Lobby Badge Check Tactic: Credential Access

You inspect an employee badge with a pocket interrogator. The screen immediately displays an unencrypted 125 kHz carrier transmitting a static 26-bit facility code in plaintext. Which APCAF technique applies?

Checkpoint 02 • Server Suite Door Tactic: Portal Ingress

You inspect the outward-opening server suite door. Inserting a pocket feeler gauge reveals a 4.5mm clearance gap between door edge and jamb with direct visibility to the latch bolt bevel and no steel astragal. Which APCAF technique applies?

Checkpoint 03 • Secure Portal Header Tactic: Portal Ingress

Looking through the clear glass transom above the locked door, you observe an unhooded wide-angle PIR motion sensor mounted directly above the interior frame facing the gap. Which APCAF technique applies?

Checkpoint 04 • Executive Conference Room Tactic: Interface & Tap

In a publicly accessible lounge, you insert a passive zero-packet LED tester into an RJ-45 wall drop. The link pulse LED illuminates steady green without 802.1X quarantine. Which APCAF technique applies?

Assessment Progress:
0 / 4 Verified
Select an answer for each checkpoint.

APCAF Fundamentals Verified

You have successfully completed the APCAF Fundamentals field scenarios. You understand the difference between compliance presence and adversarial resilience.

Lesson 01 / 06 The Problem: Paper vs Resilience