← Reconnaissance
Social Engineering Reconnaissance
You are authorized to conduct social engineering reconnaissance as part of a red team engagement. Plan the information gathering phase before any social engineering attempt. **Target Employee Profiling** - What OSINT sources provide the most valuable employee information? (LinkedIn, Twitter/X, GitHub, company bios) - How do you build a realistic pretext using information found about specific employees? - What does an employee's public content reveal about their technical knowledge level? **Organizational Mapping** - How do you map the organizational hierarchy using publicly available information? - How do you identify which employees handle IT, finance, HR, and executive functions? - What org chart information is typically visible on LinkedIn and how is it useful for pretexts? **Pretext Development** - What makes a pretext believable vs obviously suspicious? - How do you use legitimate company information (email format, tools used, ongoing projects) to build credibility? - What is a believable pretense for contacting IT helpdesk vs a CEO's assistant? **Information Security Posture Indicators** - What does a company's public security policy page, bug bounty program, and security job listings reveal? - How do security-related job postings expose defensive tooling and monitoring capabilities? - What does the absence of a security awareness program suggest? **Scope & Ethics** - What does explicit authorization for social engineering look like in an engagement contract? - How do you document social engineering activities for the report? - What is the difference between authorized vishing/phishing testing and unauthorized manipulation? Output: - Employee profiling checklist - Pretext quality checklist (what makes it believable) - Social engineering scope documentation requirements
You are authorized to conduct social engineering reconnaissance as part of a red team engagement. Plan the information gathering phase before any social engineering attempt.
Target Employee Profiling
- What OSINT sources provide the most valuable employee information? (LinkedIn, Twitter/X, GitHub, company bios)
- How do you build a realistic pretext using information found about specific employees?
- What does an employee's public content reveal about their technical knowledge level?
Organizational Mapping
- How do you map the organizational hierarchy using publicly available information?
- How do you identify which employees handle IT, finance, HR, and executive functions?
- What org chart information is typically visible on LinkedIn and how is it useful for pretexts?
Pretext Development
- What makes a pretext believable vs obviously suspicious?
- How do you use legitimate company information (email format, tools used, ongoing projects) to build credibility?
- What is a believable pretense for contacting IT helpdesk vs a CEO's assistant?
Information Security Posture Indicators
- What does a company's public security policy page, bug bounty program, and security job listings reveal?
- How do security-related job postings expose defensive tooling and monitoring capabilities?
- What does the absence of a security awareness program suggest?
Scope & Ethics
- What does explicit authorization for social engineering look like in an engagement contract?
- How do you document social engineering activities for the report?
- What is the difference between authorized vishing/phishing testing and unauthorized manipulation?
Output:
- Employee profiling checklist
- Pretext quality checklist (what makes it believable)
- Social engineering scope documentation requirements