Skip to content

Physical Security

The Physical Security section of the Operations module tracks data from physical penetration testing engagements, primarily through ATLAS imports. This includes field notes, points of interest, RFID cards, captured PINs, and magnetic stripe card data.

Physical security tracking in SPEAR serves to:

  • Document field observations during physical assessments
  • Track geographic points of interest with coordinates
  • Record captured access control data (RFID, PINs, magstripe)
  • Organize physical security data by project and engagement

Physical security data is organized into these categories:

TypeDescriptionKey Data
Field NotesObservations and documentationText, timestamps, locations
Points of InterestGeographic locationsCoordinates, descriptions
RFID CardsCaptured card dataFacility codes, card numbers
Captured PINsAccess control PINsPIN codes, associated cards
Magstripe CardsMagnetic stripe dataTrack data, card details

Physical security data is organized by project:

  • Each ATLAS import creates or updates a project
  • All related data is scoped to that project
  • Projects can contain multiple engagements
  • Data can span multiple dates within an engagement
🖥️ Project List View with ATLAS Data Screenshot

The Physical Security page displays a searchable list of projects that contain ATLAS import data:

  • Search: Filter projects by name or client name
  • Project Cards: Each project shows client name, total asset count, and data type breakdown
  • Statistics: Counts for notes, POIs, RFID cards, PINs, and magstripe cards
  • Navigation: Click a project card to view its detailed data

When projects exist, the page displays aggregate statistics:

MetricDescription
ProjectsTotal projects with physical security data
Field NotesTotal count across all projects
RFID CardsTotal captured cards
Captured PINsTotal captured PINs
Magstripe CardsTotal magstripe records

If no ATLAS imports exist, the page shows an empty state with a link to the Asset Import page where ATLAS files can be uploaded.

🖥️ ATLAS File Import Process Screenshot

ATLAS is a physical security data collection tool. SPEAR supports importing ATLAS export files to centralize physical security data with other assessment information.

ATLAS imports are initiated through the Operations > Assets page using the standard import flow:

  1. Navigate: Go to Operations > Assets and click Import
  2. Select File: Choose an ATLAS export JSON file
  3. Automatic Detection: System identifies the ATLAS format automatically
  4. Data Extraction: Parses all physical security data from the export
  5. Asset Creation: Creates appropriate asset records for each data type
  6. Confirmation: Displays import results with counts

After import, the data will appear in the Physical Security section.

The import system automatically detects ATLAS format by checking for:

  • ATLAS-specific JSON structure
  • Presence of physical security data types
  • ATLAS metadata fields

The ATLAS importer extracts:

  • Notes: Field observations with timestamps
  • POIs: Geographic points with coordinates and descriptions
  • RFID Cards: Card data with facility codes and card numbers
  • PINs: Captured PIN codes (derived from card data)
  • Magstripes: Magnetic stripe track data

For each data type, specialized asset types are created:

ATLAS DataAsset Type Created
NotesField Note
POIsPoint of Interest
RFID CardsRFID Card
PINsCaptured PIN
MagstripesMagstripe Card

ATLAS metadata is preserved including:

  • Client name
  • Engagement start date
  • Engagement stop date
  • Project identifier
  • Additional ATLAS-specific fields

Field notes capture observations made during physical assessments:

  • Content: Text description of the observation
  • Timestamp: When the note was recorded
  • Location: Where the observation was made
  • Context: Related engagement or activity

POIs mark significant geographic locations:

  • Coordinates: Latitude and longitude
  • Description: What makes this location significant
  • Category: Type of POI (entry point, camera, etc.)
  • Photos: Associated images (if captured)

RFID card records include:

  • Facility Code: The facility code from the card
  • Card Number: The unique card number
  • Format: Card format (e.g., H10301, H10302)
  • Raw Data: Hex representation of card data
  • Capture Method: How the card was captured

PIN records track:

  • PIN Code: The captured PIN
  • Associated Card: Link to related RFID card (if applicable)
  • Location: Where the PIN was captured
  • Timestamp: When the PIN was captured

Magnetic stripe records contain:

  • Track 1: Primary account number and cardholder name
  • Track 2: Account number and expiration date
  • Track 3: Additional data (if present)
  • Card Type: Type of card (access, credit, etc.)
🖥️ Project Detail View with Organized Asset Types Screenshot

Clicking on a project from the list navigates to a detailed view showing:

  • All imported assets organized by type
  • Individual asset details and metadata
  • Engagement date range information
  • Client information from the ATLAS export

The following visualization features are planned for future releases:

  • Physical Security Map: Geographic visualization of POIs with interactive markers
  • Card Gallery: Visual display of captured card images with lightbox viewing
  • Engagement Timeline: Chronological view of physical security activities
  • Advanced Filtering: Filter by date range, data type, and location

Physical security assets appear in the main Operations asset inventory:

  • Listed alongside network assets
  • Filterable by asset type
  • Support for tags and metadata
  • Standard CRUD operations

Physical security assets can be related to:

  • Other assets (e.g., badge to building address)
  • Projects and components
  • Findings in reports

Physical security assets support:

  • Custom tags for categorization
  • Metadata for additional context
  • Notes for analyst observations
  • Use consistent project naming for engagements
  • Tag physical security assets appropriately
  • Link related assets (cards to locations, PINs to cards)
  • Document context in field notes
  1. Complete field work with ATLAS data collection
  2. Export ATLAS data to JSON format
  3. Navigate to Operations > Assets in SPEAR
  4. Import the ATLAS JSON file through the asset import modal
  5. Review imported data in the Physical Security section
  6. Add additional context through notes and tags
  7. Link to findings in assessment reports
  • Physical security data is sensitive - maintain access controls
  • PINs and card data should be handled according to engagement rules
  • Consider data retention policies for captured credentials
  • Document chain of custody for physical evidence
  • Link physical security findings to report sections
  • Include relevant evidence in finding documentation
  • Reference POI locations in physical security narratives
  • Aggregate card capture statistics in executive summaries