Social Engineering: The Science of Human Hacking2e
Buy Rights Online Buy Rights

Rights Contact Login For More Details

  • Wiley

More About This Title Social Engineering: The Science of Human Hacking2e

English

CHRISTOPHER HADNAGY is the CEO and Chief Human Hacker of Social-Engineer, LLC as well as the lead developer and creator of the world's first social engineering framework found at social-engineer.org. He is the founder and creator of the Social Engineering Village (SEVillage) at DEF CON and DerbyCon,as well as the creator of the popular Social Engineering Capture the Flag (SECTF). He is a sought-after speaker and trainer and even has debriefed the Pentagon on these topics. He can be found tweeting at @humanhacker.

English

Acknowledgments xi

Foreword xix

Preface xxi

1 A Look into the New World of Professional Social Engineering  .

What Has Changed? 2

Why Should You Read This Book? 4

An Overview of Social Engineering 6

The SE Pyramid 11

What’s in This Book? 14

Summary 15

2 Do You See What I See? 17

A Real-World Example of Collecting OSINT 17

Nontechnical OSINT 22

Tools of the Trade 59

Summary 61

3 Profiling People Through Communication 63

The Approach 66

Enter the DISC 68

Summary 80

4 Becoming Anyone You Want to Be 83

The Principles of Pretexting 84

Summary 98

5 I Know How to Make You Like Me 101

The Tribe Mentality 103

Building Rapport as a Social Engineer 105

The Rapport Machine 120

Summary 121

6 Under the Influence 123

Principle One: Reciprocity 125

Principle Two: Obligation 128

Principle Three: Concession 131

Principle Four: Scarcity 134

Principle Five: Authority 137

Principle Six: Consistency and Commitment 142

Principle Seven: Liking 146

Principle Eight: Social Proof 148

Influence vs. Manipulation 151

Summary 156

7 Building Your Artwork 157

The Dynamic Rules of Framing 159

Elicitation 168

Summary 182

8 I Can See What You Didn’t Say 183

Nonverbals Are Essential 184

All Your Baselines Belong to Us 187

Understand the Basics of Nonverbals 196

Comfort vs. Discomfort 198

Summary 220

9 Hacking the Humans 223

An Equal Opportunity Victimizer 224

The Principles of the Pentest 225

Phishing 229

Vishing 233

SMiShing 240

Impersonation 241

Reporting 246

Top Questions for the SE Pentester 250

Summary 254

10 Do You Have a M.A.P.P.? 257

Step 1: Learn to Identify Social Engineering Attacks 259

Step 2: Develop Actionable and Realistic Policies 261

Step 3: Perform Regular Real-World Checkups 264

Step 4: Implement Applicable Security-Awareness Programs 266

Tie It All Together 267

Gotta Keep ’Em Updated 268

Let the Mistakes of Your Peers Be Your Teacher 270

Create a Security Awareness Culture 271

Summary 274

11 Now What? 277

Soft Skills for Becoming an Social Engineer 277

Technical Skills 280

Education 281

Job Prospects 283

The Future of Social Engineering 284

Index 287

loading