Skip to main content

Social Engineering

Red Teaming: Scenario-Based Testing

··1433 words·7 mins
This article explains Scenario-Based Testing (SBT) in detail, its benefits, tools and techniques used, and provides examples of how SBT can be used in Red Team Exercises to identify vulnerabilities and weaknesses in an organization’s security defenses.

Spear phishing and whaling: OSINT, Cialdini, and the modern AiTM toolkit

··3415 words·17 mins
Operator-side walkthrough of targeted phishing. OSINT-driven target research, Cialdini’s principles applied to email lures, the technical kit (GoPhish, Evilginx, SET), what whaling actually means (and doesn’t), the mistakes that get phishing campaigns caught, and corrected case studies (the 2016 Podesta phish, the Bangladesh Bank heist, the 2023 Scattered Spider helpdesk vishing of MGM and Caesars).

Physical security testing: from RFID cloning to the dropbox in the conference room

··4313 words·21 mins
An operator’s tour of physical pen testing tradecraft. Social engineering and pretexting, lock picking and bypass, RFID and NFC cloning with the Proxmark3 and Flipper Zero, Wiegand attacks with BLEKey/ESPKey, surveillance and counter-surveillance, network dropboxes (Hak5 LAN Turtle, Packet Squirrel), HID attack tools (Bash Bunny, Rubber Ducky), and the USB-drop technique. Closes with the Coalfire Iowa courthouse arrest as a worked example of why authorization scope matters.

Pretexting: the operator side of social engineering

··1722 words·9 mins
A working operator’s view of pretexting in 2026. Cialdini’s six (plus one) principles applied to actual engagements, building a legend that survives a target’s google check, handling the “let me verify with my manager” pushback, and the modern state of the discipline after Scattered Spider’s MGM/Caesars helpdesk attacks, AI voice cloning, STIR/SHAKEN, and AiTM kits eating MFA fatigue’s lunch.

Hacking the Human: A Red Teamer's Guide to Social Engineering

··4537 words·22 mins
A working guide to social engineering for red team engagements. Covers Cialdini’s six principles of persuasion as they’re actually used in pretexting, OSINT for building a credible story, Adversary-in-the-Middle phishing against MFA-protected accounts, MFA fatigue, vishing, physical entry, and how to write findings up without throwing individual employees under the bus.