/awesome-social-engineering

A curated list of awesome social engineering resources.

Awesome Social Engineering

Awesome

A curated list of awesome social engineering resources, inspired by the awesome-* trend on GitHub.

Those resources and tools are intended only for cybersecurity professional, penetration testers and educational use in a controlled environment.

No humans were manipulated to make this list.

Table of Contents

  1. Online Courses
  2. Capture the Flag
  3. Psychology Resources
  4. Social Engineering Books
  5. OSINT
  6. Documentation
  7. Tools
  8. Miscellaneus
  9. Contribution
  10. License

Online Courses

Social-Engineer.com - Social Engineering Training

If you are looking for a serious training with a certification path, then you should check the courses provided by Social-Engineer.com which are among the best social engineering courses available.

IntelTechniques.com - Online OSINT Training Course

This online training is designed for individuals who would like to learn and understand cutting edge open source intelligence techniques without traveling to attend an event.

Udemy - Learn Social Engineering from Scratch

Learn how to hack into secure systems like a real hacker & how to secure yourself from hackers. In this course, you will start as a beginner with no previous knowledge about penetration testing or hacking, you will start with the basics of social engineering, and by end of it you'll be able to hack into all major operating systems (windows, OS X and Linux), generate different types of trojans and deliver them using smart social engineering techniques.

Cybrary - Social Engineering and Manipulation

In this online, self-paced Social Engineering and Manipulation training class, you will learn how some of the most elegant social engineering attacks take place. Learn to perform these scenarios and what is done during each step of the attack.

Capture the Flag

Social-Engineer.com - The SECTF, DEFCON

From the site: "This truly unique event will challenge you and test your abilities to use social engineering skills to gather small amounts of data from unsuspecting companies over the phone. Each contestant will be assigned a target company. Each contestant will be provided with flags, a sample report and their call time. You will be given three weeks (STRICT, NO EXCEPTIONS) to work on your information gathering and reporting."

Psychology Resources

University of Toronto - Introduction to Psychology

As a social engineer you have to understand human psychology, so the more you know about psychology, the better.
This course will highlight the most interesting experiments within the field of psychology, discussing the implications of those studies for our understanding of the human mind and human behavior.

The University of Queensland - The Science of Everyday Thinking

You will explore the psychology of our everyday thinking: why people believe weird things, how we form and change our opinions, why our expectations skew our judgments, and how we can make better decisions. This course will provide you tools for improving your everyday thinking, tips and tricks for changing people’s minds . Also, you'll be able to use techniques for learning and retaining information longer and how to distinguish fact from fiction.

Psychology Books

Most of these books covers the basics of psychology useful for a social engineer.

Social Engineering Books

Social Engineering: The Art of Human Hacking

The first book to reveal and dissect the technical aspect of many social engineering maneuvers From elicitation, pretexting, influence and manipulation all aspects of social engineering are picked apart, discussed and explained by using real world examples, personal experience and the science behind them to unraveled the mystery in social engineering.

Unmasking the Social Engineer: The Human Element of Security

Learn to identify the social engineer by non-verbal behavior Unmasking the Social Engineer: The Human Element of Security focuses on combining the science of understanding non-verbal communications with the knowledge of how social engineers, scam artists and con men use these skills to build feelings of trust and rapport in their targets. The author helps readers understand how to identify and detect social engineers and scammers by analyzing their non-verbal behavior

Phishing Dark Waters: The Offensive and Defensive Sides of Malicious Emails

Phishing Dark Waters addresses the growing and continuing scourge of phishing emails, and provides actionable defensive techniques and tools to help you steer clear of malicious emails. Phishing is analyzed from the viewpoint of human decision–making and the impact of deliberate influence and manipulation on the recipient. With expert guidance, this book provides insight into the financial, corporate espionage, nation state, and identity theft goals of the attackers, and teaches you how to spot a spoofed e–mail or cloned website.

Social Engineering in IT Security: Tools, Tactics, and Techniques

Conduct ethical social engineering tests to identify an organization's susceptibility to attack. Written by a global expert on the topic, Social Engineering in IT Security discusses the roots and rise of social engineering and presents a proven methodology for planning a test, performing reconnaissance, developing scenarios, implementing the test, and accurately reporting the results. Specific measures you can take to defend against weaknesses a social engineer may exploit are discussed in detail. This practical guide also addresses the impact of new and emerging technologies on future trends in social engineering.

No tech Hacking

As professional hackers, Johnny Long and Kevin Mitnick get paid to uncover weaknesses in those systems and exploit them. Whether breaking into buildings or slipping past industrial-grade firewalls, their goal has always been the same: extract the information using any means necessary. After hundreds of jobs, they have discovered the secrets to bypassing every conceivable high-tech security system. This book reveals those secrets; as the title suggests, it has nothing to do with high technology.

Low Tech Hacking

Low Tech Hacking teaches your students how to avoid and defend against some of the simplest and most common hacks. Criminals using hacking techniques can cost corporations, governments, and individuals millions of dollars each year. This book focuses on the everyday hacks that, while simple in nature, actually add up to the most significant losses.

The Art of Deception: Controlling the Human Element of Security

Mitnick explains why all the firewalls and encryption protocols in the world will never be enough to stop a savvy grifter intent on rifling a corporate database or an irate employee determined to crash a system. Mitnick offers advice for preventing these types of social engineering hacks through security protocols, training programs, and manuals that address the human element of security.

Ghost in the Wires: My Adventures as the World's Most Wanted Hacker

Kevin Mitnick was the most elusive computer break-in artist in history. He accessed computers and networks at the world's biggest companies, and however fast the authorities were, Mitnick was faster, sprinting through phone switches, computer systems, and cellular networks. Ghost in the Wires is a thrilling true story of intrigue, suspense, and unbelievable escape, and a portrait of a visionary whose creativity, skills, and persistence forced the authorities to rethink the way they pursued him, inspiring ripples that brought permanent changes in the way people and companies protect their most sensitive information.

The Art of Invisibility: The World's Most Famous Hacker Teaches You How to Be Safe in the Age of Big Brother and Big Data

In this explosive yet practical book, Kevin Mitnick illustrates what is happening without your knowledge--and he teaches you "the art of invisibility." He provides both online and real life tactics and inexpensive methods to protect you and your family, in easy step-by-step instructions. He even talks about more advanced "elite" techniques, which, if used properly, can maximize your privacy. Invisibility isn't just for superheroes--privacy is a power you deserve and need in this modern age.

The Social Engineer's Playbook: A Practical Guide to Pretexting

The Social Engineer's Playbook is a practical guide to pretexting and a collection of social engineering pretexts for Hackers, Social Engineers and Security Analysts. Build effective social engineering plans using the techniques, tools and expert guidance in this book.

OSINT

OSINT Resources

OSINT Tools

  • Intel Techniques Online Tools - Use the links to the left to access all of the custom search tools.
  • Buscador - A Linux Virtual Machine that is pre-configured for online investigators
  • Maltego - Proprietary software for open source intelligence and forensics, from Paterva.
  • theHarvester - E-mail, subdomain and people names harvester
  • creepy - A geolocation OSINT tool
  • exiftool.rb - A ruby wrapper of the exiftool, a open-source tool used to extract metadata from files.
  • metagoofil - Metadata harvester
  • Google Hacking Database - a database of Google dorks; can be used for recon
  • Google-dorks - Common google dorks and others you prolly don't know
  • GooDork - Command line go0gle dorking tool
  • dork-cli - Command-line Google dork tool.
  • Shodan - Shodan is the world's first search engine for Internet-connected devices
  • recon-ng - A full-featured Web Reconnaissance framework written in Python
  • github-dorks - CLI tool to scan github repos/organizations for potential sensitive information leak
  • vcsmap - A plugin-based tool to scan public version control systems for sensitive information
  • Spiderfoot - multi-source OSINT automation tool with a Web UI and report visualizations
  • DataSploit - OSINT visualizer utilizing Shodan, Censys, Clearbit, EmailHunter, FullContact, and Zoomeye behind the scenes.
  • snitch - information gathering via dorks
  • Geotweet_GUI - Track geographical locations of tweets and then export to google maps.

Documentation

Social Engineer resources

  • The Social-Engineer portal - Everything you need to know as a social engineer is in this site. You will find podcasts, resources, framework, informations about next events, blog ecc...

Tools

Useful tools

  • Tor - The free software for enabling onion routing online anonymity
  • SET - The Social-Engineer Toolkit from TrustedSec

Phishing tools

  • Gophich - Open-Source Phishing Framework
  • King Phisher - Phishing campaign toolkit used for creating and managing multiple simultaneous phishing attacks with custom email and server content.
  • wifiphisher - Automated phishing attacks against Wi-Fi networks
  • PhishingFrenzy - Phishing Frenzy is an Open Source Ruby on Rails application that is leveraged by penetration testers to manage email phishing campaigns.
  • Evilginx - MITM attack framework used for phishing credentials and session cookies from any Web service
  • Lucy Phishing Server - (commercial) tool to perform security awareness trainings for employees including custom phishing campaigns, malware attacks etc. Includes many useful attack templates as well as training materials to raise security awareness.

Miscellaneous

Slides

Videos

Articles

Movies

Contribution

Your contributions and suggestions are heartily♥ welcome. (✿◕‿◕). Please check the Contributing Guidelines for more details.

License

License

Creative Commons License

This work is licensed under a Creative Commons Attribution 4.0 International License