Description
Book SynopsisReaders learn how to leverage human psychology and publicly available information to attack a target. The book includes sections on how to evade detection, spear phish, generate reports, and protect victims to ensure their well-being. Readers learn how to collect information about a target and how to exploit that information to make their attacks more effective. They also learn how to defend themselves or their workplace against social engineering attacks.
Trade Review"Gray provides a very accessible look at social engineering that should be essential reading for pentesters and ethical hackers." -Ian Barker, BetaNews "I really liked the way that [Joe] lays out tools to use, including walking through where to download them from and install them . . . as beginner-friendly and as easy to use as possible." -Patrick Laverty, Layer 8 Podcast
Table of ContentsIntroduction Part 1: The Basics Chapter 1: What is Social Engineering? Chapter 2: Ethical Considerations in Social Engineering Part 2: Offensive Social Engineering Chapter 3: Preparing for an Attack Chapter 4: Gathering Business OSINT Chapter 5: Social Media and Public Documents Chapter 6: Gathering OSINT About People Chapter 7: Phishing Chapter 8: Cloning a Landing Page Chapter 9: Detection, Measurement, and Reporting Part 3: Defending Against Social Engineering Chapter 10: Proactive Defense Techniques Chapter 11: Technical Email Controls Chapter 12: Producing Threat Intelligence Appendix A: Scoping Worksheet Appendix B: Reporting Template Appendix C: Information Gathering Worksheet Appendix D: Pretexting Samples Appendix E: Exercises to Improve Your Social Engineering