awesome-social-engineering/README.md

13 KiB
Raw Blame History

Awesome Social Engineering

Awesome

A curated list of awesome social engineering resources, inspired by the awesome-* trend on GitHub, especially Awesome Infosec.

Those resources and tools are intended only for cybersecurity professional, penetration testers and educational use in a controlled environment. Do not harm anyone! No humans were manipulated to make this list.

Table of Contents

  1. Massive Online Open Courses
  2. Capture the Flag
  3. Psychology Resources
  4. Social Engineering Books
  5. OSINT
  6. Documentation
  7. Tools
  8. Miscellaneus
  9. Contributing
  10. License

Massive Online Open Courses

Social-Engineer.com - Social Engineering Training

If you are looking for a serious training with a certification path, then you should check the courses provided by Social-Engineer.com which are among the best social engineering courses available.

IntelTechniques.com - Online OSINT Training Course

This online training is designed for individuals who would like to learn and understand cutting edge open source intelligence techniques without traveling to attend an event.

Udemy - Learn Social Engineering from Scratch

Learn how to hack into secure systems like a real hacker & how to secure yourself from hackers. In this course, you will start as a beginner with no previous knowledge about penetration testing or hacking, you will start with the basics of social engineering, and by end of it you'll be able to hack into all major operating systems (windows, OS X and Linux), generate different types of trojans and deliver them using smart social engineering techniques.

Cybrary - Social Engineering and Manipulation

In this online, self-paced Social Engineering and Manipulation training class, you will learn how some of the most elegant social engineering attacks take place. Learn to perform these scenarios and what is done during each step of the attack.

Capture the Flag

Social-Engineer.com - The SECTF, DEFCON

From the site: "This truly unique event will challenge you and test your abilities to use social engineering skills to gather small amounts of data from unsuspecting companies over the phone. Each contestant will be assigned a target company. Each contestant will be provided with flags, a sample report and their call time. You will be given three weeks (STRICT, NO EXCEPTIONS) to work on your information gathering and reporting."

Psychology Resources

University of Toronto - Introduction to Psychology

As a social engineer you have to understand human psychology, so the more you know about psychology, the better.
This course will highlight the most interesting experiments within the field of psychology, discussing the implications of those studies for our understanding of the human mind and human behavior. We will explore the brain and some of the cognitive abilities it supports like memory, learning, attention, perception and consciousness.

The University of Queensland - The Science of Everyday Thinking

You will explore the psychology of our everyday thinking: why people believe weird things, how we form and change our opinions, why our expectations skew our judgments, and how we can make better decisions. This course will provide you tools for improving your everyday thinking, tips and tricks for changing peoples minds . Also, you'll be able to use techniques for learning and retaining information longer and how to distinguish fact from fiction.

Psychology Books

Social Engineering Books

Social Engineering: The Art of Human Hacking

The first book to reveal and dissect the technical aspect of many social engineering maneuvers From elicitation, pretexting, influence and manipulation all aspects of social engineering are picked apart, discussed and explained by using real world examples, personal experience and the science behind them to unraveled the mystery in social engineering.

Social Engineering: The Art of Human Hacking - Chris Hadnagy

No tech Hacking

As professional hackers, Johnny Long and Kevin Mitnick get paid to uncover weaknesses in those systems and exploit them. Whether breaking into buildings or slipping past industrial-grade firewalls, their goal has always been the same: extract the information using any means necessary. After hundreds of jobs, they have discovered the secrets to bypassing every conceivable high-tech security system. This book reveals those secrets; as the title suggests, it has nothing to do with high technology.

No Tech Hacking - Johnny Long, Kevin D. Mitnick

The Art of Deception: Controlling the Human Element of Security

Mitnick explains why all the firewalls and encryption protocols in the world will never be enough to stop a savvy grifter intent on rifling a corporate database or an irate employee determined to crash a system. Mitnick offers advice for preventing these types of social engineering hacks through security protocols, training programs, and manuals that address the human element of security.

The Art of Deception: Controlling the Human Element of Security

Phishing Dark Waters: The Offensive and Defensive Sides of Malicious Emails

Phishing Dark Waters addresses the growing and continuing scourge of phishing emails, and provides actionable defensive techniques and tools to help you steer clear of malicious emails. Phishing is analyzed from the viewpoint of human decisionmaking and the impact of deliberate influence and manipulation on the recipient. With expert guidance, this book provides insight into the financial, corporate espionage, nation state, and identity theft goals of the attackers, and teaches you how to spot a spoofed email or cloned website.

Phishing Dark Waters: The Offensive and Defensive Sides of Malicious Emails

OSINT

OSINT Resources

OSINT Tools

  • Intel Techniques Online Tools - Use the links to the left to access all of the custom search tools.
  • Buscador - A Linux Virtual Machine that is pre-configured for online investigators
  • Maltego - Proprietary software for open source intelligence and forensics, from Paterva.
  • theHarvester - E-mail, subdomain and people names harvester
  • creepy - A geolocation OSINT tool
  • exiftool.rb - A ruby wrapper of the exiftool, a open-source tool used to extract metadata from files.
  • metagoofil - Metadata harvester
  • Google Hacking Database - a database of Google dorks; can be used for recon
  • Google-dorks - Common google dorks and others you prolly don't know
  • GooDork - Command line go0gle dorking tool
  • dork-cli - Command-line Google dork tool.
  • Shodan - Shodan is the world's first search engine for Internet-connected devices
  • recon-ng - A full-featured Web Reconnaissance framework written in Python
  • github-dorks - CLI tool to scan github repos/organizations for potential sensitive information leak
  • vcsmap - A plugin-based tool to scan public version control systems for sensitive information
  • Spiderfoot - multi-source OSINT automation tool with a Web UI and report visualizations
  • DataSploit - OSINT visualizer utilizing Shodan, Censys, Clearbit, EmailHunter, FullContact, and Zoomeye behind the scenes.
  • snitch - information gathering via dorks

Documentation

Social Engineer resources

  • The Social-Engineer portal - Everything you need to know as a social engineer is in this site. You will find podcasts, resources, framework, informations about next events, blog ecc...

Tools

Useful tools

  • Tor - The free software for enabling onion routing online anonymity
  • SET - The Social-Engineer Toolkit from TrustedSec

Phishing tools

  • Gophich - Open-Source Phishing Framework
  • King Phisher - Phishing campaign toolkit used for creating and managing multiple simultaneous phishing attacks with custom email and server content.
  • wifiphisher - Automated phishing attacks against Wi-Fi networks
  • PhishingFrenzy - Phishing Frenzy is an Open Source Ruby on Rails application that is leveraged by penetration testers to manage email phishing campaigns.
  • Evilginx - MITM attack framework used for phishing credentials and session cookies from any Web service

Miscellaneus

Slides

Videos

Articles

Movies