๐ŸŽญ Social Engineering

Social Engineering Complete Guide

The art of manipulating people โ€” Understanding, identifying, and defending against social engineering attacks.

Introduction to Social Engineering

Social engineering is the part of cybersecurity course and the art of manipulating people into divulging confidential information or performing actions that compromise security. It exploits human psychology rather than technical vulnerabilities.

Why It Works


Types of Social Engineering Attacks

1. Phishing (Most Common)

Types:

2. Pretexting

3. Baiting

4. Quid Pro Quo

5. Tailgating/Piggybacking


Phishing: Step-by-Step Attack Breakdown

Phase 1: Reconnaissance

Phase 2: Crafting the Attack

A. Email Phishing Example

๐Ÿ“ง Phishing Email Example
From: "Amazon Support" <support@amazon-security.com>
Subject: Urgent: Unusual Login Attempt

Dear Customer,

We detected a login from Nigeria (IP: 196.xxx.xxx).
Click here to verify your account: http://amazon-verify.com/login

- Amazon Security Team

๐Ÿšฉ Red Flags: Fake domain (`amazon-verify.com`) ยท Urgency + fear tactics ยท Suspicious link

B. Clone Phishing

  1. Hack a real email thread
  2. Replace attachments/links with malicious ones

Phase 3: Delivery

Phase 4: Exploitation

Phase 5: Post-Attack


Tools Used in Phishing

Tool Purpose
Gophish Open-source phishing framework
SET (Social Engineer Toolkit) Automated phishing attacks
King Phisher Realistic phishing campaigns
Evilginx2 Advanced phishing (MFA bypass)
GoPhish Email template cloning

How to Defend Against Social Engineering

For Individuals

โœ” Verify sender emails (Check domain spelling)

โœ” Hover over links before clicking

โœ” Enable MFA (Blocks 99% of phishing)

โœ” Don't trust urgency/fear messages

โœ” Report suspicious emails to IT

For Organizations

โœ” Employee training (Phishing simulations)

โœ” Email filtering (Mimecast, Proofpoint)

โœ” DMARC/DKIM/SPF (Prevent email spoofing)

โœ” Web filtering (Block malicious sites)

โœ” Incident response plan


Ethical Phishing Testing

Steps for Legal Phishing Tests:

  1. Get written permission
  2. Use simulated domains (e.g., `company-security-test.com`)
  3. Provide training after tests
  4. Never steal real data

Tools for Security Awareness:


Real-World Case Studies

  1. 2016 DNC Hack โ€” Russian spear phishing
  2. Twitter Bitcoin Scam โ€” Celebrity accounts hacked via vishing
  3. Colonial Pipeline Attack โ€” Compromised VPN via leaked password

Conclusion

๐Ÿ”น Next Steps

๐Ÿš€ Want a hands-on phishing lab walkthrough? Let me know!