Design and execute a social engineering penetration test including phishing,
SKILL.md
Conducting Social Engineering Penetration Test
Overview
Social engineering penetration testing assesses an organization's human attack surface through controlled simulation of real-world deception techniques. According to Verizon DBIR 2024, the human element is involved in approximately 68% of all breaches, with phishing remaining the dominant initial access vector. This skill covers phishing, vishing (voice phishing), smishing (SMS phishing), and physical pretexting campaigns using tools like GoPhish, the Social Engineer Toolkit (SET), and Evilginx.
When to Use
When conducting security assessments that involve conducting social engineering penetration test
When following incident response procedures for related security events
When performing scheduled security testing or auditing activities
When validating security controls through hands-on testing
Prerequisites
Written authorization from senior management (CISO/CTO)
Legal review confirming compliance with local laws (CFAA, GDPR, etc.)
Defined scope: target employee groups, attack types, exclusions
GoPhish server, domain for phishing infrastructure, VPS
Subject: [Action Required] Mandatory Password Reset - Security Incident
From: IT Security <[email protected]>
Dear {FirstName},
Our security team has detected unauthorized access attempts on our systems.
As a precautionary measure, all employees must reset their passwords immediately.
Please click below to reset your password within the next 24 hours:
[Reset Password Now] -> {phishing_url}
Failure to comply may result in temporary account suspension.
Thank you,
IT Security Team
Template 2 — Finance Invoice:
Subject: Invoice #INV-2025-4821 - Approval Required
From: Accounts Payable <[email protected]>
Hi {FirstName},
Please review and approve the attached invoice from our vendor.
Amount: $47,250.00 | Due: March 15, 2025
[View Invoice] -> {phishing_url}
Best regards,
Accounts Payable
Phase 3 — Vishing Campaign
Call Script Template
Pretext: IT Help Desk calling about suspicious login
Caller: "Hi, this is [Name] from the IT Help Desk. Am I speaking with [Target Name]?"
[Wait for confirmation]
Caller: "We've detected some unusual login activity on your account from an
unrecognized location. For your protection, I need to verify your identity
before we can investigate further."
Caller: "Can you confirm your employee ID and the email address associated
with your account?"
[Record responses]
Caller: "Thank you. I'm going to send you a verification link to confirm
it's really you. Can you click on it and enter your credentials so we can
secure your account?"
[Send phishing link via email/SMS during call]
Caller: "Great, I can see you've been verified. Your account is now secured.
If you notice any further issues, please call the help desk at [real number]."
Vishing Metrics to Track
Metric
Description
Call answered
Target picked up the phone
Engaged
Target continued conversation past initial question
Information disclosed
Target provided credentials, employee ID, or PII
Link clicked
Target clicked the verification link
Credentials entered
Target entered credentials on phishing page
Reported
Target reported the call to security
Phase 4 — Physical Social Engineering
Physical Pretexting Scenarios
Scenario 1: Delivery Person
- Arrive with package labeled for executive
- Request access to deliver personally
- Attempt to tailgate through secure doors
- Drop USB drives in common areas
Scenario 2: IT Vendor
- Arrive with vendor badge (printed)
- Claim scheduled maintenance on network closet
- Attempt to access server rooms
- Install rogue wireless AP if access gained
Scenario 3: New Employee
- Arrive claiming first day orientation
- Request temporary badge
- Attempt to access restricted areas
- Photograph sensitive screens/documents
Evidence Collection:
- Body camera (if legally permitted and authorized)
- Photographs of accessed areas
- WiFi probe from rogue AP
- Notes on which doors/checkpoints bypassed