
PHYTRE
Physical Security Tactical Research and Exercises
A shared language for physical security
Cyber security teams have long had MITRE ATT&CK, a structured catalogue of how attackers operate. Physical security has no widely used equivalent. Drills are often scripted from experience, audits vary from one assessor to the next, and it is hard to say whether a site has been tested against the threats that matter most.
PHYTRE takes the same approach to the physical world. It models an intrusion into a protected site as a chain of stages, organised by what the adversary is trying to achieve. A drill planner can pick an intent, trace a realistic path through the chain, and test the defences at every step along it.
- Stage
- Version 0.1, in development
- Scope
- Any protected site, across sectors
- Use
- Drill design, security audits, training
- Access
- Restricted to vetted organisations
How it is structured
Three layers, each feeding the next. Together they let a team describe an attack on a site precisely enough to rehearse it.
- 01
Intent
What the adversary wants: to steal, to disrupt, to gather intelligence, to cause harm. The intent decides which path is worth modelling.
- 02
Kill chain
The stages an intrusion moves through, from first reconnaissance of a site to the final act. Every stage is a chance for the defence to stop it.
- 03
Techniques
The specific methods an adversary can use at each stage. Each one is something a guard force can be trained to spot and a drill can test.
Where physical meets digital
Physical defences increasingly depend on electronic systems such as access control, CCTV and alarms. PHYTRE also covers the points where a physical intrusion leans on a digital weakness.

Perimeter security relies just as much on access controls, cameras, and alarm panels as physical barriers. Omitting electronic systems from a drill leaves half the perimeter unverified.

From framework to drill
- 1
Pick an intent
Start from what an adversary would want at this site. That decides which path is worth rehearsing.
- 2
Trace the path
Follow the kill chain across the real site plan, from first reconnaissance to the final act.
- 3
Mark where it can be stopped
At each stage, note which guard, barrier, camera or alarm should catch it, and what happens if it does not.
- 4
Run it and audit it
Turn the path into a drill narrative for the red team and a checklist for the auditors, so both test the same thing.
Who it is for

Critical infrastructure
Operators of power, telecom, transport and industrial sites who need to test their protection against a realistic adversary.

Police & CAPF trainers
Training institutions and units that design security drills and want them built around how intrusions actually unfold.

Corporate facility security
Security teams and facility operators who run audits and want a consistent way to find and rank their gaps.
Where it is heading
- Building a kill chain around one specific adversary intent, so a drill follows a believable path from start to finish.
- Adapting the framework to different kinds of site without rewriting it for each sector.
- Covering the points where physical and digital attack paths meet.
- Turning a chosen kill chain into a ready drill narrative for the red team and a checklist for the audit.
Access
A detailed catalogue of intrusion techniques is useful to defenders and to attackers alike, so PHYTRE is not public. We share it with organisations that have a clear defensive need.
Once the framework has matured and been tested in the field, we intend to consider a wider release, as MITRE did with ATT&CK.
PHYTRE is being built with practitioners. We are looking for people who have done this work.
Help build it
→Security officers, red-team operators, drill planners and auditors with field experience. Help us test the framework against what really happens on the ground.
Request access
→Organisations responsible for protecting a site or training a security force. Tell us who you are and what you want to use it for.