Skip to content

Pretexting & target OSINT

The pretext is the credible story that holds up any social engineering attack, and OSINT (open-source intelligence) is what makes it credible. This card covers how to research a target legally and how to build a solid pretext in an authorized engagement.

Organization org chart, roles, vendors, technology (job ads reveal the stack)
People name/role/email, internal jargon, schedules, interests (LinkedIn, X, Instagram)
Email address format (first.last@) -> infer any employee's address
Leaks prior breaches (have i been pwned), reused passwords, leaked documents
Technical domain/subdomain recon, emails in metadata of public documents
Physical sites, schedules, uniforms, access control (see se-physical)

For technical recon (domains, subdomains, emails) see recon and ad-enum. Here the focus is the person and the context.

theHarvester emails, subdomains, names associated with a domain
Maltego relationship graph (people, domains, infra)
LinkedIn + X informal org chart, jargon, travel/absences
hunter.io corporate email format and discovery
haveibeenpwned email exposure in breaches (password reuse)
Google dorks public documents, exposed panels, indexed info
exiftool metadata (author, username, software) of public PDFs/images
Elements of a good pretext:
- coherent IDENTITY (a role that justifies the request: IT, vendor, auditor, courier)
- plausible, seemingly verifiable MOTIVE ("email migration", "payroll issue")
- real DETAILS from OSINT (names, projects, jargon) to build trust
- the right CHANNEL (email for mass, voice for pressure, in person for physical access)
- prepared EXIT: answers to verification questions and a reason for the urgency
OSINT: "the company uses Microsoft 365; IT outsourced to VendorX; a migration is underway (a job ad mentions it)"
Pretext: call/email from "VendorX" about the M365 migration, asking to validate access
-> matches the target's reality = high credibility
- use separate accounts/infra (sock puppets) and a VPN; don't contaminate with your real identity
- record sources and dates (data changes); respect legal collection limits
- minimize personal data collected to what's needed for scope (GDPR)
  • Reduce the public footprint: review what the website, job ads, social media, and document metadata reveal.
  • Train high-value employees on their exposure; policies on what to publish about the company.
  • Out-of-band verification for requests invoking “vendor/IT/management”.
  • Monitor breaches affecting corporate emails and enforce rotation/MFA.
  • RSA (2011) and Ukraine (2015, blackout): spear-phishing leaned on precise target OSINT.
  • Groups like Scattered Spider stand out for their OSINT and help-desk pretexting (see Vishing & smishing).
  • Countless BEC schemes are built with vendor OSINT and real payment calendars.
  • Authorization and OSINT scope (allowed sources, targets)
  • Corporate email format inferred
  • Org chart/roles and internal jargon gathered
  • Breach exposure (credential reuse) reviewed
  • Metadata of public documents analyzed
  • Pretext coherent with the OSINT (identity, motive, channel)
  • Data minimization and investigator OPSEC