Social Engineering & Human Hacking: Advanced Psychological Techniques for Security Professionals
- From Phishing Campaigns to Physical Infiltration — A CEH Professional’s Complete Guide
- About the Author
- Preface
Chapter 1: Introduction to Social Engineering
- 1.1 Defining Social Engineering
- 1.2 Why Humans Are the Weakest Link
- 1.3 Historical Examples
- 1.4 CEH Relevance
- 1.5 Ethical and Legal Boundaries
Chapter 2: Psychology of Influence
- 2.1 Why Psychology Matters to Security Professionals
- 2.2 Cialdini’s Six Principles of Influence
- 2.3 Cognitive Biases Exploited by Attackers
- 2.4 Fear, Urgency, and the Bypass of Rational Thinking
- 2.5 The Role of Pretexting
Chapter 3: OSINT for Social Engineering
- 3.1 The Intelligence Foundation
- 3.2 Target Profiling Using LinkedIn
- 3.3 Facebook and Other Social Platforms
- 3.4 OSINT Tools
- 3.5 Building a Target Dossier
- 3.6 Identifying Organizational Hierarchy and Key Contacts
Chapter 4: Phishing Campaigns
- 4.1 Phishing Overview
- 4.2 GoPhish: Setup and Configuration
- 4.3 Sending Profiles Configuration
- 4.4 Crafting Convincing Phishing Emails
- 4.5 Spam Filter Bypass Techniques
- 4.6 Tracking Opens and Clicks
- 4.7 Spear Phishing vs. Mass Phishing
Chapter 5: Advanced Email Attacks
- 5.1 Spear Phishing and Whaling
- 5.2 Business Email Compromise (BEC)
- 5.3 Email Spoofing Techniques
- 5.4 DKIM/SPF/DMARC Bypasses
- 5.5 Pretexting Scenarios for Email
Chapter 6: Vishing (Voice Phishing)
- 6.1 Vishing Fundamentals
- 6.2 Caller ID Spoofing
- 6.3 Call Scripts for Different Pretexts
- 6.4 Extracting Information via Phone
- 6.5 Handling Objections
- 6.6 Recording and Documenting Calls
Chapter 7: Smishing & Other Vectors
- 7.1 Smishing (SMS Phishing)
- 7.2 QR Code Attacks (Quishing)
- 7.3 USB Drop Attacks
- 7.4 Watering Hole Attacks
- 7.5 Evil Twin WiFi Attacks
Chapter 8: Physical Security Testing
- 8.1 Physical Security Assessment Overview
- 8.2 Pretexting for Physical Access
- 8.3 Tailgating and Piggybacking
- 8.4 Badge Cloning with Proxmark3
- 8.5 Lock Picking Basics
- 8.6 Dumpster Diving for Information
- 8.7 Building Security Assessment Methodology
Chapter 9: Red Team Campaign Planning
- 9.1 Social Engineering in the Red Team Context
- 9.2 Rules of Engagement
- 9.3 Scope Definition
- 9.4 Documenting a Realistic Adversary Simulation
- 9.5 Integrating with Technical Red Team Operations
Chapter 10: Defense — Security Awareness Training
- 10.1 Why Most Security Awareness Training Fails
- 10.2 What Makes Security Awareness Programs Effective
- 10.3 Phishing Simulation Programs
- 10.4 Measuring Awareness
- 10.5 Creating a Security Culture
- 10.6 NIST 800-50 Guidance
Chapter 11: Reporting Social Engineering Engagements
- 11.1 Documentation During the Engagement
- 11.2 Evidence Capture
- 11.3 Metrics and Findings
- 11.4 Communicating Risk to Leadership
- 11.5 Detailed Technical Findings
Chapter 12: Legal and Ethical Considerations
- 12.1 The Authorization Framework
- 12.2 Relevant Legal Framework
- 12.3 When Tests Go Wrong
- 12.4 Protecting Client Data
- 12.5 Real-World Case Studies of Social Engineering Gone Wrong
- Appendix A: Social Engineering Toolkit Reference
- Appendix B: Sample Engagement Checklist
- Appendix C: Recommended Reading and References
Lists
- Numbered Lists
- Bulleted Lists
- Definition Lists
About These Chapters
- Read on…
Book Resources
Tables
Code Blocks
Images
YouTube Videos
Math Blocks
Asides and Blurbs
- Read on…
External Resources
Including a Code File
Other External Types
- Read on…
Cross-references
Linking to a Heading
Linking to a Figure or Table
Choosing What the Link Shows
- Read on…
Footnotes and Endnotes
Inserting a Note
Editing a Note
Note IDs
- Read on…
Indexing Your Book
Entries and Sub-entries
Viewing Your Index
Previewing and Publishing
- Previewing Your Book
- Publishing Your Book
This Is A Book
- Read on…