Social engineering is the art of convincing people to reveal confidential information. Social engineers depend on the fact that people are aware of valuable information and are not usually diligent in protecting it.


The objective of this lab is to:
  • Protect the network from phishing attacks
To do this lab, you need:
  • A computer running Kali Linux operating System
  • A web browser with Internet access


Social engineering is essentially the art of gaining access to buildings, systems, or data by exploiting human psychology, rather than by breaking in or using technical hacking techniques. The term social engineering can also mean an attempt to gain access to information, primarily through misrepresentation, and often relies on the trusting nature of most individuals. For example, instead of trying to find software vulnerability, a social engineer might call an employee and pose as an IT support person, trying to trick the employee into divulging his password.


Shane MacDougall, a hacker/security consultant, duped a Wal-Mart employee into giving him information that could be used in a hacker attack to win a coveted black badge in the œsocial engineering contest at the Defcon hackers conference in Las Vegas.

Social Engineering Penetration Testing

The Security Analyst Exercises / Social Engineering Penetration Testing contains the following Exercises:

  • Social Engineering Penetration Testing using Social Engineering Toolkit (SET)
  • Intrusion Detection Using KFSensor Honeypot IDS

