Awesome Social Engineering
A curated list of awesome social engineering resources, inspired by
Those resources and tools are intended only for cyber security professional, penetration testers and educational use in a controlled environment.
No humans were manipulated to make this list!
Table of Contents
Online Courses
Capture the Flag
Psychology Books
Books
Documentation
Tools
Miscellaneus
OSINT
Contribution
License
Online Courses
Udemy - Learn Social Engineering from Scratch
PacktPub - Learn Social Engineering From Scratch by Zaid Sabih
Cybrary - Social Engineering and Manipulation - Free Course
Capture the Flag
Social-Engineer.com - The SECTF, DEFCON
Social-Engineer.com - DEFCON SECTF
Psychology Books
Most of these books covers the basics of psychology useful for a social engineer.
Artful Persuasion – How to command attention, Change minds and influence People – Harry Mills
What is every BODY saying – Joe Navarro
Conflict, power and persuasion – Ben Hoffman
Dealing with difficult people – McGraw Hill
Get anyone to do anything – David J Lieberman
How to start a conversation and make friends - Don Gabor
The art of Psychological Warfare – Michael T Stevens
How to Win Friends and Influence People - Dale Carnegie
The 48 Laws of Power - Robert Greene
The Psychology Book
The Power of Habit: Why We Do What We Do, and How to Change - Charles Duhigg
Influence: The Psychology of Persuasion Paperback – Robert B., PhD Cialdini
Emotions Revealed: Understanding Faces and Feelings - Prof Paul Ekman
The Psychology of Interrogations and Confessions: A Handbook - Gisli H. Gudjonsson
Mindfucking: A Critique of Mental Manipulation - Colin McGinn
Social Engineering Books
Human Hacking – Chris Hadnagy
Learn Social Engineering – Dr. Erdal Ozkaya
Social Engineering: The Art of Human Hacking - Chris Hadnagy
Social Engineering: The Science of Human Hacking
Unmasking the Social Engineer: The Human Element of Security - Christopher Hadnagy, Dr. Ekman Paul
Phishing Dark Waters: The Offensive and Defensive Sides of Malicious Emails - Christopher Hadnagy, Michele Fincher, Robin Dreeke
Social Engineering in IT Security: Tools, Tactics, and Techniques, Sharon Conheady
No Tech Hacking - Johnny Long, Kevin D. Mitnick
Low Tech Hacking: Street Smarts for Security Professionals - Jack Wiles, Terry Gudaitis, Jennifer Jabbusch, Russ Rogers
The Art of Deception: Controlling the Human Element of Security, Kevin D. Mitnick, William L. Simon
Ghost in the Wires: My Adventures as the World's Most Wanted Hacker - Kevin D. Mitnick, William L. Simon, Steve Wozniak
The Art of Invisibility: The World's Most Famous Hacker Teaches You How to Be Safe in the Age of Big Brother and Big Data - Kevin Mitnick, Robert Vamosi
The Social Engineer's Playbook: A Practical Guide to Pretexting - Jeremiah Talamantes
Learn Social Engineering - Erdal Ozkaya
COMMUNITIES
Abstract Security - community od Discord that is focused around Physical Security and it has many members that are in the buissness of Physical Security.
Documentation
Social Engineer resources
The Social-Engineer portal - Everything you need to know as a social engineer is in this site. You will find podcasts, resources, framework, informations about next events, blog ecc...
Layer 8 conference and podcast - Conference and podcast that is focused on OSINT and Social Engineering.
Tools
Useful tools
Tor - The free software for enabling onion routing online anonymity
SET - The Social-Engineer Toolkit from TrustedSec
Phishing tools
Gophish - Open-Source Phishing Framework
King Phisher - Phishing campaign toolkit used for creating and managing multiple simultaneous phishing attacks with custom email and server content.
wifiphisher - Automated phishing attacks against Wi-Fi networks
PhishingFrenzy - Phishing Frenzy is an Open Source Ruby on Rails application that is leveraged by penetration testers to manage email phishing campaigns.
Evilginx2 - MITM attack framework used for phishing credentials and session cookies from any Web service
Lucy Phishing Server - (commercial) tool to perform security awareness trainings for employees including custom phishing campaigns, malware attacks etc. Includes many useful attack templates as well as training materials to raise security awareness.
Miscellaneous
Slides
OWASP Presentation of Social Engineering - OWASP
Weaponizing data science for social engineering: Automated E2E spear phishing on Twitter - Defcon 23
Using Social Engineering Tactics For Big Data Espionage - RSA Conference Europe 2012
Videos
Chris Hadnagy - 7 Jedi Mind Tricks Influence Your Target without a Word
Robert Anderson - US Interrogation Techniques and Social Engineering
Ian Harris - Understanding Social Engineering Attacks with Natural Language Processing
Chris Hadnagy - Social Engineering for Fun and Profit
Chris Hadnagy - Decoding humans live - DerbyCon 2015
This is how hackers hack you using simple social engineering
Articles
The Limits of Social Engineering - MIT, Technology Review
The 7 Best Social Engineering Attacks Ever - DarkReading
Social Engineering: Compromising Users with an Office Document - Infosec Institute
The Persuasion Reading List - Scott Adams' Blog
How I Socially Engineer Myself Into High Security Facilities - Sophie Daniel
Movies
Tiger Team (TV series)
Catch Me If You Can
Inception
The Sting
Sneakers
OSINT
OSINT Resources
Awesome OSINT - Awesome list of OSINT
OSINT Framework - Collection of various OSInt tools broken out by category.
NetBootcamp OSINT Tools - A collection of OSINT links and custom Web interfaces to other services such as Facebook Graph Search and various paste sites.
Automating OSINT blog - A blog about OSINT curated by Justin Seitz, the same author of BHP.
OSINT Tools
XRay - XRay is a tool for recon, mapping and OSINT gathering from public networks.
Buscador - A Linux Virtual Machine that is pre-configured for online investigators
Maltego - Proprietary software for open source intelligence and forensics, from Paterva.
theHarvester - E-mail, subdomain and people names harvester
creepy - A geolocation OSINT tool
exiftool.rb - A ruby wrapper of the exiftool, a open-source tool used to extract metadata from files.
metagoofil - Metadata harvester
Google Hacking Database - a database of Google dorks; can be used for recon
Google-Dorks - Common google dorks and others you prolly don't know
GooDork - Command line go0gle dorking tool
dork-cli - Command-line Google dork tool.
Shodan - Shodan is the world's first search engine for Internet-connected devices
recon-ng - A full-featured Web Reconnaissance framework written in Python
github-dorks - CLI tool to scan github repos/organizations for potential sensitive information leak
vcsmap - A plugin-based tool to scan public version control systems for sensitive information
Spiderfoot - multi-source OSINT automation tool with a Web UI and report visualizations
DataSploit - OSINT visualizer utilizing Shodan, Censys, Clearbit, EmailHunter, FullContact, and Zoomeye behind the scenes.
snitch - information gathering via dorks
Geotweet_GUI - Track geographical locations of tweets and then export to google maps.