Pretexting & target OSINT
The pretext is the credible story that holds up any social engineering attack, and OSINT (open-source intelligence) is what makes it credible. This card covers how to research a target legally and how to build a solid pretext in an authorized engagement.
Target OSINT (human reconnaissance)
Section titled “Target OSINT (human reconnaissance)”Organization org chart, roles, vendors, technology (job ads reveal the stack)People name/role/email, internal jargon, schedules, interests (LinkedIn, X, Instagram)Email address format (first.last@) -> infer any employee's addressLeaks prior breaches (have i been pwned), reused passwords, leaked documentsTechnical domain/subdomain recon, emails in metadata of public documentsPhysical sites, schedules, uniforms, access control (see se-physical)For technical recon (domains, subdomains, emails) see recon and ad-enum. Here the focus is the person and the context.
OSINT tools
Section titled “OSINT tools”theHarvester emails, subdomains, names associated with a domainMaltego relationship graph (people, domains, infra)LinkedIn + X informal org chart, jargon, travel/absenceshunter.io corporate email format and discoveryhaveibeenpwned email exposure in breaches (password reuse)Google dorks public documents, exposed panels, indexed infoexiftool metadata (author, username, software) of public PDFs/imagesBuilding the pretext
Section titled “Building the pretext”Elements of a good pretext:- coherent IDENTITY (a role that justifies the request: IT, vendor, auditor, courier)- plausible, seemingly verifiable MOTIVE ("email migration", "payroll issue")- real DETAILS from OSINT (names, projects, jargon) to build trust- the right CHANNEL (email for mass, voice for pressure, in person for physical access)- prepared EXIT: answers to verification questions and a reason for the urgencyExample OSINT → pretext fit
Section titled “Example OSINT → pretext fit”OSINT: "the company uses Microsoft 365; IT outsourced to VendorX; a migration is underway (a job ad mentions it)"Pretext: call/email from "VendorX" about the M365 migration, asking to validate access-> matches the target's reality = high credibilityOPSEC of your own OSINT
Section titled “OPSEC of your own OSINT”- use separate accounts/infra (sock puppets) and a VPN; don't contaminate with your real identity- record sources and dates (data changes); respect legal collection limits- minimize personal data collected to what's needed for scope (GDPR)Defense (blue team)
Section titled “Defense (blue team)”- Reduce the public footprint: review what the website, job ads, social media, and document metadata reveal.
- Train high-value employees on their exposure; policies on what to publish about the company.
- Out-of-band verification for requests invoking “vendor/IT/management”.
- Monitor breaches affecting corporate emails and enforce rotation/MFA.
Real-world cases
Section titled “Real-world cases”- RSA (2011) and Ukraine (2015, blackout): spear-phishing leaned on precise target OSINT.
- Groups like Scattered Spider stand out for their OSINT and help-desk pretexting (see Vishing & smishing).
- Countless BEC schemes are built with vendor OSINT and real payment calendars.
Testing checklist
Section titled “Testing checklist”- Authorization and OSINT scope (allowed sources, targets)
- Corporate email format inferred
- Org chart/roles and internal jargon gathered
- Breach exposure (credential reuse) reviewed
- Metadata of public documents analyzed
- Pretext coherent with the OSINT (identity, motive, channel)
- Data minimization and investigator OPSEC