← All cheat sheets

SOCIAL-ENGINEERING

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: Red-Team Comms Builder

Comprehensive reference for understanding and defending against
social engineering attacks. For authorized testing only.

PSYCHOLOGICAL PRINCIPLES#

Robert Cialdini's 6 Principles of Influence:
  1. Reciprocity:    People feel obligated to return favors
  2. Commitment:     People want to be consistent with past actions
  3. Social proof:   People follow what others do
  4. Authority:      People comply with perceived authority figures
  5. Liking:         People comply with those they like
  6. Scarcity:       People act urgently when things are limited

Additional principles used in attacks:
  - Urgency:         "Act now or face consequences"
  - Fear:            "Your account will be suspended"
  - Curiosity:       "See who viewed your profile"
  - Greed:           "You've won a prize"
  - Helpfulness:     Exploiting desire to help others
  - Trust:           Leveraging established relationships

PHISHING (EMAIL)#

Types:
  Bulk phishing:     Mass emails to large audience
  Spear phishing:    Targeted at specific individuals
  Whaling:           Targeted at executives (CEO, CFO, CTO)
  Clone phishing:    Copy of legitimate email with malicious payload
  Lateral phishing:  Sent from compromised internal account

Common phishing techniques:
  - Lookalike domains (examp1e.com, example-security.com)
  - Unicode/homograph attacks (using similar-looking characters)
  - Link manipulation (display text differs from URL)
  - HTML rendering tricks (invisible text, hidden elements)
  - QR code phishing (quishing) - embed QR code in email
  - Attachment-based (macro-enabled docs, HTML files, ISOs)
  - Thread hijacking (reply to legitimate email thread)

Phishing email red flags:
  - Sender domain mismatch
  - Generic greeting ("Dear Customer")
  - Urgency and threats
  - Spelling and grammar errors
  - Suspicious links (hover to check)
  - Unexpected attachments
  - Request for credentials or sensitive data
  - "Click here" or "Login now" buttons

Testing tools:
  GoPhish:
    - Open-source phishing framework
    - Email templates, landing pages, tracking
    - Campaign management and reporting
    - Install: go install github.com/gophish/gophish@latest
    - Docker: docker pull gophish/gophish

  King Phisher:
    - Open-source phishing toolkit
    - Template management
    - Two-factor phishing pages

  Evilginx2:
    - Advanced phishing with real-time MitM
    - Captures session tokens (bypasses MFA)
    - Reverse proxy approach
    - Phishlets for many services

  SET (Social Engineering Toolkit):
    - Multi-vector attack platform
    - Credential harvester, website cloner
    - Part of Kali Linux

Spear phishing methodology:
  1. OSINT: Research target (LinkedIn, social media, company site)
  2. Identify: pretext aligned with target's role/interests
  3. Craft: personalized email with relevant context
  4. Infrastructure: register lookalike domain, SSL cert, SPF/DKIM
  5. Send: during business hours, match target's timezone
  6. Track: opens, clicks, credential submissions
  7. Report: metrics and findings

VISHING (VOICE PHISHING)#

Concept: Social engineering over phone calls.

Common scenarios:
  IT Help Desk:
    "This is [name] from IT support. We detected unusual activity
    on your account. I need to verify your identity to secure it.
    Can you confirm your username and current password?"

  Bank/Financial:
    "This is [bank] fraud department. We've detected suspicious
    transactions on your account. I need to verify your account
    number and PIN to block the transactions."

  Executive impersonation:
    "This is [CEO name]. I need you to process an urgent wire
    transfer. I'm in a meeting so email me the confirmation."

  Vendor/Supplier:
    "I'm calling from [vendor]. Our banking details have changed.
    Please update the account for future payments."

Caller ID spoofing tools:
  - SpoofCard
  - SpoofTel
  - SIP/VoIP clients with custom caller ID
  - Asterisk PBX with custom CID

Vishing best practices (for testing):
  - Script key talking points but be natural
  - Have a cover story for being transferred
  - Know the organization chart and terminology
  - Record calls (with proper authorization and legal compliance)
  - Have an abort plan if the target becomes suspicious
  - Document: who answered, what info was disclosed, how long

Voice modulation:
  - Confidence and authority in tone
  - Match pace and energy of target
  - Use technical jargon appropriate to pretext
  - Background noise matching (office sounds for IT pretext)

SMISHING (SMS PHISHING)#

Concept: Phishing via SMS/text messages.

Common smishing messages:
  "Your package delivery failed. Reschedule: [link]"
  "Unusual sign-in to your account. Verify: [link]"
  "Your bank account has been locked. Unlock: [link]"
  "[Company] IT: Your email password expires today. Reset: [link]"
  "You've won a $500 gift card! Claim: [link]"

Techniques:
  - Short URLs to hide destination
  - Lookalike domains optimized for mobile (small screen)
  - SMS spoofing (sender name manipulation)
  - iMessage/RCS rich link previews
  - MMS with malicious attachments (less common)

PRETEXTING#

Concept: Creating a fabricated scenario (pretext) to gain trust
and extract information or access.

Key elements of a good pretext:
  1. Plausible context that explains why you're contacting them
  2. Legitimate-sounding reason for the request
  3. Enough knowledge to answer follow-up questions
  4. Appropriate urgency (not too much, not too little)
  5. Props and appearance matching the pretext

Pretext development checklist:
  [ ] Who am I pretending to be?
  [ ] Why would I contact this person?
  [ ] What information do I need to know?
  [ ] What questions might they ask?
  [ ] What artifacts support the pretext? (email, badge, uniform)
  [ ] What is my exit strategy?

Common pretexts:
  - IT support (password reset, software update)
  - Auditor (compliance, financial, safety)
  - New employee (first day, lost, need help)
  - Vendor/contractor (maintenance, delivery)
  - Executive assistant (acting on behalf of CEO)
  - Journalist (interview request)
  - Job applicant (visiting for interview)
  - Building maintenance (HVAC, plumbing, electrical)

BAITING#

Concept: Luring victims with something enticing.

Physical baiting:
  - USB drives in parking lots / lobbies
  - CDs/DVDs labeled "Salary Information" or "Confidential"
  - QR codes on posters or flyers

Digital baiting:
  - Free software downloads with malware
  - Torrent files bundled with malware
  - "Leaked" documents or data
  - Free tools or utilities with backdoors
  - Fake job offers with malicious attachments

QUID PRO QUO#

Concept: Offering something in exchange for information.

Examples:
  - "I'll fix your computer issue if you give me your login"
  - "Free security assessment" in exchange for network access
  - Technical support scams (fix nonexistent problem for payment)
  - Survey with gift card reward (harvesting personal data)

WATERING HOLE ATTACKS#

Concept: Compromise websites frequently visited by the target group.

Methodology:
  1. Research: identify websites commonly visited by target org
  2. Compromise: exploit vulnerability in one of those websites
  3. Inject: malicious code that targets visitors
  4. Wait: for target employees to visit the compromised site
  5. Exploit: deliver payload when target visits

Detection challenges:
  - Legitimate website, so no URL filtering
  - May use zero-day exploits
  - Targeted (only specific IP ranges exploited)
  - Can evade email-based security controls

BUSINESS EMAIL COMPROMISE (BEC)#

Types:
  CEO Fraud:
    - Impersonate CEO requesting wire transfer
    - Target: CFO, finance department, accounts payable

  Account Compromise:
    - Compromised employee email account
    - Send requests to contacts (invoice redirect, data request)

  Vendor Email Compromise:
    - Compromise vendor's email or spoof their domain
    - Request payment to new bank account

  Attorney Impersonation:
    - Pretend to be lawyer handling confidential matter
    - Leverage urgency and confidentiality

  Data Theft:
    - Target HR for W-2 forms, employee PII
    - Target IT for credentials or system access

BEC indicators:
  - Requests to change payment details
  - Urgency and secrecy ("keep this confidential")
  - Request to bypass normal procedures
  - Slight email address variations
  - First-time communication from a "known" person
  - Requests outside of business hours

BEC prevention:
  - Out-of-band verification for financial requests (call back)
  - Multi-person approval for wire transfers
  - Domain-based authentication (SPF, DKIM, DMARC)
  - Employee awareness training
  - External email banners/warnings
  - Invoice payment process controls

DEEPFAKE AWARENESS#

Current capabilities:
  - Voice cloning: few seconds of audio can clone a voice
  - Video deepfakes: face swapping in real-time
  - Text generation: AI-generated phishing content
  - Real-time audio deepfakes in phone calls

Attack scenarios:
  - Fake CEO video/audio requesting urgent action
  - Impersonating colleagues in video calls
  - Generating fake evidence or compromising material
  - Creating fake audio recordings for pretexting

Detection indicators:
  - Audio: unusual pauses, inconsistent background noise, flat affect
  - Video: facial artifacts, inconsistent lighting, blurring at edges
  - Behavioral: unusual requests, out-of-character communication
  - Technical: metadata analysis, forensic tools

Defense:
  - Establish verification procedures for high-risk requests
  - Use code words or challenge-response for sensitive operations
  - Verify through separate, trusted channels
  - Train employees on deepfake awareness
  - Consider deepfake detection tools

DEFENSE STRATEGIES#

Technical controls:
  [ ] Email authentication (SPF, DKIM, DMARC)
  [ ] Email filtering and sandboxing
  [ ] URL filtering and reputation checking
  [ ] Multi-factor authentication (MFA)
  [ ] Phishing-resistant MFA (FIDO2/WebAuthn)
  [ ] External email banners ("This email originated outside the org")
  [ ] USB device controls (DLP)
  [ ] Network access controls (802.1X)

Process controls:
  [ ] Verification procedures for financial transactions
  [ ] Multi-person authorization for sensitive operations
  [ ] Visitor management and escort policies
  [ ] Clean desk policy
  [ ] Incident reporting procedures
  [ ] Vendor verification processes

Human controls:
  [ ] Regular security awareness training
  [ ] Simulated phishing campaigns
  [ ] Social engineering penetration testing
  [ ] Reward reporting culture (no blame for clicking)
  [ ] Executive-specific training (whaling defense)
  [ ] New employee security orientation

Metrics to track:
  - Phishing simulation click rate (target: < 5%)
  - Report rate (target: > 70%)
  - Time to report (target: < 10 minutes)
  - Repeat clicker rate
  - Training completion rate

REPORTING TEMPLATE FOR SE ENGAGEMENTS#

1. Executive Summary
2. Scope and Methodology
3. Attack Vectors Tested
4. Results Summary (success/failure per vector)
5. Detailed Findings
   - Vector used
   - Target(s)
   - Pretext and approach
   - Outcome (success/failure)
   - Information/access obtained
   - Evidence (screenshots, recordings with consent)
6. Positive Observations
7. Risk Assessment
8. Recommendations
9. Employee Awareness Metrics

REFERENCES#

- The Art of Deception (Kevin Mitnick)
- Social Engineering: The Science of Human Hacking (Christopher Hadnagy)
- GoPhish: https://getgophish.com/
- SET: https://github.com/trustedsec/social-engineer-toolkit
- KnowBe4 Research: https://www.knowbe4.com/
- Anti-Phishing Working Group: https://apwg.org/