Social Engineering Assessments
Social engineering assessments are authorized tests of whether people and business processes resist deceptive requests. They measure reporting, verification, escalation, and control behavior without collecting real credentials or singling out individuals.
itOffensive security and application security | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic - Social Engineering Assessments
A social engineering assessment tests whether people and processes resist deceptive requests for information, access, or action. Common channels include email, voice, collaboration tools, physical access, and help-desk workflows. The assessment is authorized security testing, not a prank and not a hunt for individuals to blame.
NIST places this work inside planned information security testing and assessment. Define a control objective, obtain rules of engagement, and bound every action so it can be cleaned up safely. A voice test can check identity verification without recording a call or requesting a secret. A physical test can check visitor handling without entering a restricted area. If a proposed action cannot be bounded and reversed, it is not an assessment action.
Measure observables that match the objective: recognition and reporting through the approved path, independent verification before payment changes, service-desk identity checks before recovery-factor changes, or escalation under time pressure. A delivered message proves delivery. A click proves an interaction. A report proves use of the reporting path. Context matters: population, scenario, filtering, timing, and prior training all affect rates.
Do not turn a click rate into a verdict about a person or "security culture." Use repeated, approved assessments on like populations to improve processes, reporting routes, technical controls, and targeted education. NIST cautions that results should improve security rather than single out individuals.
Read the Intro for the authorized control loop. Use the Cheatsheet when you need the objective and evidence map. Landscape places assessment platforms beside related awareness tooling; Updates tracks NIST SP 800-115, the assessment guidance this course uses for planning and rules of engagement.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/115/final
Supports
- Security-assessment purpose, methodology, planning, execution, analysis, reporting, and mitigation
- Social engineering as a target-vulnerability validation technique
- The course's authorized-assessment framing and limitations
- https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=152164
Supports
- Social engineering definition, channels, human-element and procedure testing, and use of results to improve security rather than single out individuals
- Rules-of-engagement planning, constraints, management approval, contacts, and execution within the plan
- Quiz answers about scope, incident escalation, and safe assessment design
- https://csrc.nist.gov/glossary/term/rules_of_engagement
Supports
- Rules of engagement as detailed guidelines and constraints that grant authority for defined security-testing activities
- Quiz answers about authorization and third-party scope
- https://www.cisa.gov/sites/default/files/2022-11/Capacity_Enhancement_Guide-Counter-Phishing_Recommendations_for_Federal_Agencies_1_0.pdf
Supports
- Counter-phishing program context and relationship to CISA's Phishing Campaign Assessment
- Reference-path rationale for phishing resilience and response
- https://www.cisa.gov/resources-tools/services/phishing-campaign-assessment
Supports
- CISA's Phishing Campaign Assessment as an engagement that evaluates susceptibility and reaction to phishing email
- Reference-path rationale for a public assessment service example
- https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-get-started
Supports
- Managed phishing simulations, recipients, schedules, payloads, social-engineering techniques, and training responses
- Microsoft Attack Simulation Training Landscape placement
- https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-insights
Supports
- Actual compromised rate, total targeted users, clicked-user count, repeat-simulation reporting, and training-completion reporting
- Metric and quiz claims about denominators and contextual comparison
- https://github.com/sindresorhus/awesome
Supports
- Discovery route from the Awesome index to its Security category and relevant security Awesome lists
- https://github.com/sbilly/awesome-security
Supports
- Discovery of Gophish in the Social Engineering category
- Gophish Awesome Links inclusion
- https://github.com/eudk/awesome-cybersecurity-tools
Supports
- Discovery of King Phisher in the Phishing and Social category
- King Phisher Awesome Links inclusion
- https://getgophish.com/documentation/
Supports
- Gophish documentation as a project-owned resource for testing organizational phishing exposure
- Gophish Awesome Links rationale and Landscape placement
- https://github.com/CrimsonForge-io/king-phisher
Supports
- King Phisher as a phishing campaign toolkit for legal, explicitly authorized use
- Maintainer notice that King Phisher is no longer maintained
- King Phisher Awesome Links rationale
- https://www.proofpoint.com/us/products/mitigate-human-risk
Supports
- Proofpoint risk-based security-awareness training, targeted education, simulations, reporting, and behavior-change tracking
- Proofpoint Landscape placement
- https://www.knowbe4.com/products/phishing-security-test
Supports
- KnowBe4 phishing-security testing Landscape placement
- https://cofense.com/product/phishme/
Supports
- Cofense PhishMe phishing-simulation Landscape placement
- https://www.hoxhunt.com/platform
Supports
- Hoxhunt phishing-simulation and reporting Landscape placement
