Ethical Hacking: Social Engineering

Ethical Hacking: Social Engineering

1h 34mBeginner2021-06-22

Authors

Lisa Bock

Lisa Bock

Security ambassador with a broad range of IT skills and knowledge

Course details

Social engineering is a technique hackers use to manipulate end users and obtain information about an organization or computer systems. In order to protect their networks, IT security professionals need to understand social engineering, who is targeted, and how social engineering attacks are orchestrated.

In this course, cybersecurity expert Lisa Bock discusses the methods a hacker might use, including embedding malicious links and attachments in emails and using mobile devices and social media to deploy an attack. She discusses the concept of "misuse of trust"—how hackers use charm, power, and influence to penetrate an organization—and why you need to be extra cautious with the disgruntled employee. Finally, Lisa discusses countermeasures security professionals can take to address these attacks.

Topics include:
Visualizing the victim
Recognizing an attack
Using charm, power, and influence
Manipulating with social media
Preventing insider attacks
Stealing identities
Pen testing with social engineering
Taking countermeasures

Skills covered

Security AwarenessCert PrepCybersecurity

Concepts

Introduction

  • Defining social engineering
  • What you should know
  • Hacking ethically

Grasping Social Engineering

  • Hacking the human
  • Visualizing the victim
  • Skills of a social engineer
  • Recognize an attack

Social Engineering Mechanisms

  • Using charm, power, and influence
  • Employing browsers for social engineering
  • Evaluating add-ons and extensions
  • Deploying mobile-based attacks
  • Manipulating with social media
  • Disclosing private information
  • Challenge - Avoiding online dating scams
  • Solution - Avoiding online dating scams

Misusing Trust

  • Disgruntled employees
  • Steal an identity
  • Challenge - Monitoring your employees
  • Solution - Monitoring your employees

Penetration Testing with Social Engineering

  • Using email and websites in social engineering
  • In person and on the phone
  • Exploring the social engineering toolkit
  • Going phishing
  • Using the social engineering toolkit

Avoiding Social Engineering

  • Defending against social engineering
  • Understanding spam
  • Preventing spoofed email
  • Preventing insider attacks
  • Properly disposing of data and media

Conclusion

  • Next steps
40,000 Toman