Offensive security assessments
Social Engineering
We validate this area during scoped assessments, documenting impact and remediation guidance.
Why it matters
- [ ] Use ethical phishing techniques to gather information (obtain informed consent). - [ ] Attend events, conferences, or gatherings where the target may be present.
How we test it
Our operators follow a structured checklist for this topic, adapted to your API surface and authentication model.
Testing approach
- Structured validation of Social Engineering during scoped assessment.
- Evidence captured with reproducible steps for your engineering team.
What we look for
- Misconfigurations and control gaps related to Social Engineering.
- Exploitable paths that could affect confidentiality, integrity, or availability.
Engagement checklist
Items we validate during scoping and execution for this topic.
What we assess
- Use ethical phishing techniques to gather information (obtain informed consent).
- Attend events, conferences, or gatherings where the target may be present.
Related topics
| Topic | Summary |
|---|---|
| Core Concepts | OSINT (Open Source Intelligence) is the practice of collecting and analyzing publicly available information about a target (organization, domain, person, or asset) without touching the target directly. The goal is to map the attack surface and human footprint that an adversary c… |
| Dark Web | We validate this area during scoped assessments, documenting impact and remediation guidance. |
| Information Gathering | We validate this area during scoped assessments, documenting impact and remediation guidance. |
| Online Sources | We validate this area during scoped assessments, documenting impact and remediation guidance. |
| Verification | We validate this area during scoped assessments, documenting impact and remediation guidance. |