Rules for black teams: don’t be stupid, don’t get caught. Getting caught by the client can be part of the test. Getting caught by everyone else—especially when it provides the client no useful information—is another story: covertaccessteam.substack.co…
2
How can you access a client’s building AND server room—and still fail the engagement? Because breaking in wasn’t the only objective. This article looks at how a successful physical pentest can still fail to address the client’s actual security concerns: covertaccessteam.substack.co…
Made with AI
9
Want to know how to get valuable information from a seemingly normal conversation? Our virtual Elicitation Toolbox Training teaches how to guide conversations, uncover information & recognize when the same techniques are being used on you. Oct 24–25: covertaccessteam.com/elicita…
Made with AI
8
Your bank tells YOU to verify requests before handing over sensitive information. But what happens when the bank falls for the scam? Attackers reportedly tricked Revolut through a trusted government disclosure channel—and got customer data. Read: covertaccessteam.substack.co…
43
What if you were abducted, searched, and restrained? Could you actually escape? Brian Harris put his assumptions to the test at Ed Calderon’s Counter Custody course. What works in theory can fail under stress. Read his thoughts on the course: covertaccessteam.substack.co…
10
💥Our 2027 training calendar is officially live 💥 Whether you want to develop your covert access skills, conduct better physical security audits, sharpen your elicitation techniques, or strengthen your operational planning, we’ve got a full year of training ahead.
10
Careful what you post online? Your friends, old records, and company breaches can still expose you. Use OSINT to investigate yourself, find exposed information, and request its removal. Read how: covertaccessteam.substack.co… | #OSINT #OPSEC
55
Imagine: A data center hires you to stop intruders reaching its servers. But the servers depend on cooling equipment outside, behind a chain-link fence. If damaged, repairs could take weeks. Are you protecting the asset—or everything keeping it running? covertaccessteam.substack.co…
7
How much information can you get from someone without ever directly asking for it? October 24–25, we’re running our live, virtual Elicitation Toolbox Course. Learn rapport building, conversation pivoting, elicitation techniques & more: covertaccessteam.com/elicita…
16
92% of residential burglaries in England and Wales were closed with no suspect identified. Only 5% resulted in a charge or summons. Finding vulnerabilities is only half the job. Your recommendations need to address the threats your client actually faces: covertaccessteam.substack.co…
1
14
1.2 million people. Names. National ID numbers. Vehicle plates. Payment information. Home addresses. Latvia’s road authority suffered a breach connecting people to their identities, cars & homes. The entry point? Read for more: covertaccessteam.substack.co…
16
Coffee areas. Cafeterias. Employee lounges. Even bathrooms. They aren’t the mission-critical areas you’re paid to target—but they may be just as critical to the mission. Let's talk the importance of “safe zones” on physical pentests: covertaccessteam.substack.co…
Made with AI
16
11 days away. 3 seats left. 💪 There’s still time to join our final Covert Access Training course of 2026. Sept. 21–25 | Copenhagen 🇩🇰 5 days of hands-on training—from picking locks and cloning badges to flying drones and bypassing cameras. More info: covertaccessteam.com/covert-…
14
Cybersecurity is changing quickly as AI becomes part of both the attack and the defense. AI security expert Harriet Farlow talks to CAT about autonomous agents, prompt injection & why cybersecurity itself may eventually become a subset of AI security: covertaccessteam.substack.co…
25
10 hours of phone calls. 180 text messages. Files labeled “Batch 1 for Reporter” and “Batch 2 for Reporter.” A former Delta Force support employee now faces four counts under the Espionage Act. How are you protecting against insiders? Read: covertaccessteam.substack.co…
20
Want to end September with a bang? 💥 Join us Sept. 21–25 in Copenhagen for 5 days of hands-on Covert Access Training—and leave a certified Covert Access Specialist. 🔓 Bypass 🪪 RFID 🗣️ Social Engineering 👀 Recon + much more Only a couple seats left: covertaccessteam.com/covert-…
Made with AI
26
Iranian hackers knocked a UK power plant offline for four days. No blackout. No wider grid failure. But they got in. We break down the attack, PLCs, OT security, and what previous Iranian operations tell us: covertaccessteam.substack.co… #OTSecurity #Cybersecurity
35
Mayor… or foreign agent? For former California mayor Eileen Wang, the answer was BOTH. Her case offers a fascinating look at asset development—and why access, credibility, and influence matter. Read more: covertaccessteam.substack.co… #InsiderThreat #HUMINT
28
Most training courses end with a certificate. This one ends with a real physical pen test. (And then a certificate 😆) 5 days of hands-on training, cool toys, great people, and a real final engagement. 📍 Copenhagen 📅 Sept. 21–25 covertaccessteam.com/covert-…
Made with AI
23
The U.S. is preparing to let private cybersecurity companies do something they've largely been kept away from for decades: attack back. Vetted firms could be authorized to disrupt foreign criminal networks targeting Americans. Get the full details here: covertaccessteam.substack.co…
13