Practical Social Engineering
Joe Gray• How to use Open Source Intelligence tools (OSINT) like Recon-ng and whois
• Strategies for capturing a target’s info from social media, and using it to guess their password
• Phishing techniques like spoofing, squatting, and standing up your own webserver to avoid detection
• How to collect metrics about the success of your attack and report them to clients
• Technical controls and awareness programs to help defend against social engineering
An ethical introduction to social engineering, an attack technique that leverages psychology, deception, and publicly available information to breach the defenses of a human target in order to gain access to an asset. Social engineering is key to the effectiveness of any computer security professional.
Social engineering is the art of capitalizing on human psychology to compromise systems, not technical vulnerabilities. It’s an effective method of attack because even the most advanced security detection teams can do little to defend against an employee clicking a malicious link or opening a file in an email and even less to what an employee may say on a phone call. This book will show you how to take advantage of these ethically sinister techniques so you can better understand what goes into these attacks as well as thwart attempts to gain access by cyber criminals and malicious actors who take advantage of human nature.