SOCIAL-ENGINEERING
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tool: Red-Team Comms Builder
Comprehensive reference for understanding and defending against social engineering attacks. For authorized testing only.
PSYCHOLOGICAL PRINCIPLES#
Robert Cialdini's 6 Principles of Influence: 1. Reciprocity: People feel obligated to return favors 2. Commitment: People want to be consistent with past actions 3. Social proof: People follow what others do 4. Authority: People comply with perceived authority figures 5. Liking: People comply with those they like 6. Scarcity: People act urgently when things are limited Additional principles used in attacks: - Urgency: "Act now or face consequences" - Fear: "Your account will be suspended" - Curiosity: "See who viewed your profile" - Greed: "You've won a prize" - Helpfulness: Exploiting desire to help others - Trust: Leveraging established relationships
PHISHING (EMAIL)#
Types:
Bulk phishing: Mass emails to large audience
Spear phishing: Targeted at specific individuals
Whaling: Targeted at executives (CEO, CFO, CTO)
Clone phishing: Copy of legitimate email with malicious payload
Lateral phishing: Sent from compromised internal account
Common phishing techniques:
- Lookalike domains (examp1e.com, example-security.com)
- Unicode/homograph attacks (using similar-looking characters)
- Link manipulation (display text differs from URL)
- HTML rendering tricks (invisible text, hidden elements)
- QR code phishing (quishing) - embed QR code in email
- Attachment-based (macro-enabled docs, HTML files, ISOs)
- Thread hijacking (reply to legitimate email thread)
Phishing email red flags:
- Sender domain mismatch
- Generic greeting ("Dear Customer")
- Urgency and threats
- Spelling and grammar errors
- Suspicious links (hover to check)
- Unexpected attachments
- Request for credentials or sensitive data
- "Click here" or "Login now" buttons
Testing tools:
GoPhish:
- Open-source phishing framework
- Email templates, landing pages, tracking
- Campaign management and reporting
- Install: go install github.com/gophish/gophish@latest
- Docker: docker pull gophish/gophish
King Phisher:
- Open-source phishing toolkit
- Template management
- Two-factor phishing pages
Evilginx2:
- Advanced phishing with real-time MitM
- Captures session tokens (bypasses MFA)
- Reverse proxy approach
- Phishlets for many services
SET (Social Engineering Toolkit):
- Multi-vector attack platform
- Credential harvester, website cloner
- Part of Kali Linux
Spear phishing methodology:
1. OSINT: Research target (LinkedIn, social media, company site)
2. Identify: pretext aligned with target's role/interests
3. Craft: personalized email with relevant context
4. Infrastructure: register lookalike domain, SSL cert, SPF/DKIM
5. Send: during business hours, match target's timezone
6. Track: opens, clicks, credential submissions
7. Report: metrics and findings
VISHING (VOICE PHISHING)#
Concept: Social engineering over phone calls.
Common scenarios:
IT Help Desk:
"This is [name] from IT support. We detected unusual activity
on your account. I need to verify your identity to secure it.
Can you confirm your username and current password?"
Bank/Financial:
"This is [bank] fraud department. We've detected suspicious
transactions on your account. I need to verify your account
number and PIN to block the transactions."
Executive impersonation:
"This is [CEO name]. I need you to process an urgent wire
transfer. I'm in a meeting so email me the confirmation."
Vendor/Supplier:
"I'm calling from [vendor]. Our banking details have changed.
Please update the account for future payments."
Caller ID spoofing tools:
- SpoofCard
- SpoofTel
- SIP/VoIP clients with custom caller ID
- Asterisk PBX with custom CID
Vishing best practices (for testing):
- Script key talking points but be natural
- Have a cover story for being transferred
- Know the organization chart and terminology
- Record calls (with proper authorization and legal compliance)
- Have an abort plan if the target becomes suspicious
- Document: who answered, what info was disclosed, how long
Voice modulation:
- Confidence and authority in tone
- Match pace and energy of target
- Use technical jargon appropriate to pretext
- Background noise matching (office sounds for IT pretext)
SMISHING (SMS PHISHING)#
Concept: Phishing via SMS/text messages. Common smishing messages: "Your package delivery failed. Reschedule: [link]" "Unusual sign-in to your account. Verify: [link]" "Your bank account has been locked. Unlock: [link]" "[Company] IT: Your email password expires today. Reset: [link]" "You've won a $500 gift card! Claim: [link]" Techniques: - Short URLs to hide destination - Lookalike domains optimized for mobile (small screen) - SMS spoofing (sender name manipulation) - iMessage/RCS rich link previews - MMS with malicious attachments (less common)
PRETEXTING#
Concept: Creating a fabricated scenario (pretext) to gain trust and extract information or access. Key elements of a good pretext: 1. Plausible context that explains why you're contacting them 2. Legitimate-sounding reason for the request 3. Enough knowledge to answer follow-up questions 4. Appropriate urgency (not too much, not too little) 5. Props and appearance matching the pretext Pretext development checklist: [ ] Who am I pretending to be? [ ] Why would I contact this person? [ ] What information do I need to know? [ ] What questions might they ask? [ ] What artifacts support the pretext? (email, badge, uniform) [ ] What is my exit strategy? Common pretexts: - IT support (password reset, software update) - Auditor (compliance, financial, safety) - New employee (first day, lost, need help) - Vendor/contractor (maintenance, delivery) - Executive assistant (acting on behalf of CEO) - Journalist (interview request) - Job applicant (visiting for interview) - Building maintenance (HVAC, plumbing, electrical)
BAITING#
Concept: Luring victims with something enticing. Physical baiting: - USB drives in parking lots / lobbies - CDs/DVDs labeled "Salary Information" or "Confidential" - QR codes on posters or flyers Digital baiting: - Free software downloads with malware - Torrent files bundled with malware - "Leaked" documents or data - Free tools or utilities with backdoors - Fake job offers with malicious attachments
QUID PRO QUO#
Concept: Offering something in exchange for information. Examples: - "I'll fix your computer issue if you give me your login" - "Free security assessment" in exchange for network access - Technical support scams (fix nonexistent problem for payment) - Survey with gift card reward (harvesting personal data)
WATERING HOLE ATTACKS#
Concept: Compromise websites frequently visited by the target group. Methodology: 1. Research: identify websites commonly visited by target org 2. Compromise: exploit vulnerability in one of those websites 3. Inject: malicious code that targets visitors 4. Wait: for target employees to visit the compromised site 5. Exploit: deliver payload when target visits Detection challenges: - Legitimate website, so no URL filtering - May use zero-day exploits - Targeted (only specific IP ranges exploited) - Can evade email-based security controls
BUSINESS EMAIL COMPROMISE (BEC)#
Types:
CEO Fraud:
- Impersonate CEO requesting wire transfer
- Target: CFO, finance department, accounts payable
Account Compromise:
- Compromised employee email account
- Send requests to contacts (invoice redirect, data request)
Vendor Email Compromise:
- Compromise vendor's email or spoof their domain
- Request payment to new bank account
Attorney Impersonation:
- Pretend to be lawyer handling confidential matter
- Leverage urgency and confidentiality
Data Theft:
- Target HR for W-2 forms, employee PII
- Target IT for credentials or system access
BEC indicators:
- Requests to change payment details
- Urgency and secrecy ("keep this confidential")
- Request to bypass normal procedures
- Slight email address variations
- First-time communication from a "known" person
- Requests outside of business hours
BEC prevention:
- Out-of-band verification for financial requests (call back)
- Multi-person approval for wire transfers
- Domain-based authentication (SPF, DKIM, DMARC)
- Employee awareness training
- External email banners/warnings
- Invoice payment process controls
DEEPFAKE AWARENESS#
Current capabilities: - Voice cloning: few seconds of audio can clone a voice - Video deepfakes: face swapping in real-time - Text generation: AI-generated phishing content - Real-time audio deepfakes in phone calls Attack scenarios: - Fake CEO video/audio requesting urgent action - Impersonating colleagues in video calls - Generating fake evidence or compromising material - Creating fake audio recordings for pretexting Detection indicators: - Audio: unusual pauses, inconsistent background noise, flat affect - Video: facial artifacts, inconsistent lighting, blurring at edges - Behavioral: unusual requests, out-of-character communication - Technical: metadata analysis, forensic tools Defense: - Establish verification procedures for high-risk requests - Use code words or challenge-response for sensitive operations - Verify through separate, trusted channels - Train employees on deepfake awareness - Consider deepfake detection tools
DEFENSE STRATEGIES#
Technical controls:
[ ] Email authentication (SPF, DKIM, DMARC)
[ ] Email filtering and sandboxing
[ ] URL filtering and reputation checking
[ ] Multi-factor authentication (MFA)
[ ] Phishing-resistant MFA (FIDO2/WebAuthn)
[ ] External email banners ("This email originated outside the org")
[ ] USB device controls (DLP)
[ ] Network access controls (802.1X)
Process controls:
[ ] Verification procedures for financial transactions
[ ] Multi-person authorization for sensitive operations
[ ] Visitor management and escort policies
[ ] Clean desk policy
[ ] Incident reporting procedures
[ ] Vendor verification processes
Human controls:
[ ] Regular security awareness training
[ ] Simulated phishing campaigns
[ ] Social engineering penetration testing
[ ] Reward reporting culture (no blame for clicking)
[ ] Executive-specific training (whaling defense)
[ ] New employee security orientation
Metrics to track:
- Phishing simulation click rate (target: < 5%)
- Report rate (target: > 70%)
- Time to report (target: < 10 minutes)
- Repeat clicker rate
- Training completion rate
REPORTING TEMPLATE FOR SE ENGAGEMENTS#
1. Executive Summary 2. Scope and Methodology 3. Attack Vectors Tested 4. Results Summary (success/failure per vector) 5. Detailed Findings - Vector used - Target(s) - Pretext and approach - Outcome (success/failure) - Information/access obtained - Evidence (screenshots, recordings with consent) 6. Positive Observations 7. Risk Assessment 8. Recommendations 9. Employee Awareness Metrics
REFERENCES#
- The Art of Deception (Kevin Mitnick) - Social Engineering: The Science of Human Hacking (Christopher Hadnagy) - GoPhish: https://getgophish.com/ - SET: https://github.com/trustedsec/social-engineer-toolkit - KnowBe4 Research: https://www.knowbe4.com/ - Anti-Phishing Working Group: https://apwg.org/