Social Engineering Assessments
Social engineering assessments are authorized tests of whether people and business processes resist deceptive requests. They measure reporting, verification, escalation, and control behavior without collecting real credentials or singling out individuals.
itOffensive security and application security | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Intro
Social Engineering Assessments
A social engineering assessment is an authorized security test of how people, procedures, and supporting controls respond to a deceptive request. It tests the human element alongside technical controls. The target is an organizational behavior or control, not an employee's character or job performance.
NIST describes social engineering as an attempt to trick someone into revealing information that could be used to attack systems or networks. The assessment use of that technique is narrower and governed by written permission. It asks a defined question, such as whether a recipient reports a suspicious message, verifies an unusual payment request through an independent channel, or follows a help-desk identity-check procedure.
Assessment boundary
Authorization is part of the assessment design. A signed rules of engagement defines the sponsor, assessment purpose, targets and exclusions, approved channels, time window, allowed data, emergency contacts, stop conditions, and evidence handling. It also names who can pause or stop the work. A platform feature or a realistic scenario never expands that boundary.
For a phishing assessment, the boundary should state whether messages are sent only to managed mailboxes, whether simulated landing pages record only an event, and whether credentials, personal data, attachments, or external recipients are forbidden. A safe design records the minimum event needed to answer the question. It does not retain a submitted password, collect production authentication tokens, impersonate emergency services, or create a real business obligation.
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/115/final
Supports
- Security-assessment purpose, methodology, planning, execution, analysis, reporting, and mitigation
- Social engineering as a target-vulnerability validation technique
- The course's authorized-assessment framing and limitations
- https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=152164
Supports
- Social engineering definition, channels, human-element and procedure testing, and use of results to improve security rather than single out individuals
- Rules-of-engagement planning, constraints, management approval, contacts, and execution within the plan
- Quiz answers about scope, incident escalation, and safe assessment design
- https://csrc.nist.gov/glossary/term/rules_of_engagement
Supports
- Rules of engagement as detailed guidelines and constraints that grant authority for defined security-testing activities
- Quiz answers about authorization and third-party scope
- https://www.cisa.gov/sites/default/files/2022-11/Capacity_Enhancement_Guide-Counter-Phishing_Recommendations_for_Federal_Agencies_1_0.pdf
Supports
- Counter-phishing program context and relationship to CISA's Phishing Campaign Assessment
- Reference-path rationale for phishing resilience and response
- https://www.cisa.gov/resources-tools/services/phishing-campaign-assessment
Supports
- CISA's Phishing Campaign Assessment as an engagement that evaluates susceptibility and reaction to phishing email
- Reference-path rationale for a public assessment service example
- https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-get-started
Supports
- Managed phishing simulations, recipients, schedules, payloads, social-engineering techniques, and training responses
- Microsoft Attack Simulation Training Landscape placement
- https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-insights
Supports
- Actual compromised rate, total targeted users, clicked-user count, repeat-simulation reporting, and training-completion reporting
- Metric and quiz claims about denominators and contextual comparison
- https://github.com/sindresorhus/awesome
Supports
- Discovery route from the Awesome index to its Security category and relevant security Awesome lists
- https://github.com/sbilly/awesome-security
Supports
- Discovery of Gophish in the Social Engineering category
- Gophish Awesome Links inclusion
- https://github.com/eudk/awesome-cybersecurity-tools
Supports
- Discovery of King Phisher in the Phishing and Social category
- King Phisher Awesome Links inclusion
- https://getgophish.com/documentation/
Supports
- Gophish documentation as a project-owned resource for testing organizational phishing exposure
- Gophish Awesome Links rationale and Landscape placement
- https://github.com/CrimsonForge-io/king-phisher
Supports
- King Phisher as a phishing campaign toolkit for legal, explicitly authorized use
- Maintainer notice that King Phisher is no longer maintained
- King Phisher Awesome Links rationale
- https://www.proofpoint.com/us/products/mitigate-human-risk
Supports
- Proofpoint risk-based security-awareness training, targeted education, simulations, reporting, and behavior-change tracking
- Proofpoint Landscape placement
- https://www.knowbe4.com/products/phishing-security-test
Supports
- KnowBe4 phishing-security testing Landscape placement
- https://cofense.com/product/phishme/
Supports
- Cofense PhishMe phishing-simulation Landscape placement
- https://www.hoxhunt.com/platform
Supports
- Hoxhunt phishing-simulation and reporting Landscape placement
