Fundamentals
Social engineering exploits the person, not the machine. In most real intrusions the first access comes through a human who clicks, answers the phone, or lets someone in. This card covers the psychological principles, the attack cycle, and the ethical/legal framework required to do it in an authorized engagement.
Why it works: principles of influence
Section titled “Why it works: principles of influence”Authority "I'm from IT / management / the tax office" -> obedience without verifyingUrgency "your account locks in 1h" -> bypasses reflective thinkingScarcity "only X left / limited offer" -> quick decisionSocial proof "all your colleagues already did it" -> conformityLiking empathy, rapport, shared interests -> lowered guardReciprocity a small favor -> the victim wants to reciprocateCommitment a small "yes" chains into a bigger one (foot-in-the-door)These are Cialdini’s principles: the attacker combines several so the victim acts before thinking.
Cognitive biases exploited
Section titled “Cognitive biases exploited”- authority bias and trust in known brands/logos- fear (of losing access, a fine, getting in trouble) as a driver- curiosity ("look at this photo", "attached invoice", "you were mentioned")- workload/distraction: busy people verify lessThe social engineering attack cycle
Section titled “The social engineering attack cycle”1. RECON/OSINT gather target info (see se-pretexting): org chart, emails, vendors, internal jargon, social media2. PRETEXT build the credible story and the channel (email, phone, in person)3. HOOK contact: the message/call that triggers the action4. EXPLOITATION the victim acts: click, credentials, transfer, physical access5. EXIT achieve persistence/objective and withdraw without raising alarmsVectors (area overview)
Section titled “Vectors (area overview)”Phishing mass or targeted email (spear/whaling) -> see se-phishingVishing by voice/phone; Smishing by SMS -> see se-vishingPretexting elaborate story, often in person or by phone -> see se-pretextingPhysical tailgating, USB drop, in-person impersonation -> see se-physicalEthical and legal framework (MANDATORY)
Section titled “Ethical and legal framework (MANDATORY)”- WRITTEN authorization with explicit scope BEFORE any testing- define what's allowed: phone pretext? physical access? who NOT to touch?- mind the human factor: don't humiliate; the goal is to IMPROVE, not punish- data protection: OSINT and captured credentials are personal data (GDPR)- reporting aimed at training and controls, not at naming specific peopleWithout authorization these techniques are crimes (fraud, impersonation, trespass). The value of social red teaming is measuring and improving human resilience with consent.
Defense (overview)
Section titled “Defense (overview)”- Ongoing awareness and simulations (see Phishing campaigns) measured by click/report rate.
- Out-of-band verification procedures for sensitive requests (payments, account changes).
- Phishing-resistant MFA (FIDO2/passkeys), and technical controls that reduce the impact of a click.
- A “report without fear” culture: make the report button easy and don’t punish those who fall for it.
Real-world cases
Section titled “Real-world cases”- Twitter (2020): vishing of employees → access to internal tools and hijacking of verified accounts.
- RSA SecurID (2011): spear-phishing with a malicious Excel → compromise of token seeds.
- MGM / Caesars (2023): Scattered Spider used help-desk vishing to reset MFA.
- Phishing/social engineering leads the initial-breach vector in DBIR reports year after year.
Testing checklist
Section titled “Testing checklist”- Written authorization and scope (channels, targets, exclusions) confirmed
- Target OSINT completed (see Pretexting & target OSINT)
- Pretext credible and consistent with the gathered info
- Influence principles chosen (authority/urgency/…)
- Channel and pretext aligned (email/voice/physical)
- Evidence captured without over-exposing personal data
- Report aimed at training and controls, not at people