Book Image

Learn Social Engineering

Book Image

Learn Social Engineering

Overview of this book

This book will provide you with a holistic understanding of social engineering. It will help you to avoid and combat social engineering attacks by giving you a detailed insight into how a social engineer operates. Learn Social Engineering starts by giving you a grounding in the different types of social engineering attacks,and the damages they cause. It then sets up the lab environment to use different toolS and then perform social engineering steps such as information gathering. The book covers topics from baiting, phishing, and spear phishing, to pretexting and scareware. By the end of the book, you will be in a position to protect yourself and your systems from social engineering threats and attacks. All in all, the book covers social engineering from A to Z , along with excerpts from many world wide known security experts.
Table of Contents (16 chapters)

Tips

Consider the tips as follows:

  • There is no patch for human stupidity or, in other words, there is always a way to manipulate humans (as you will read about in this book). As a result, you or your employees are the most difficult and the biggest resource that you have to protect.
  • Conduct a user awareness session often. There is always room for improvement in any social engineering training.
  • Do not share anything sensitive with anyone. Keep in mind, once a secret is known by two people, it's not a secret anymore.
  • If you are not sure about anything, proceed with caution.
  • Ensure physical security.
  • Classify information against dumpster-diving attacks. Even big corporations used this kind of attack in the past.
  • Keep in mind, based on ISACA in 2016, social engineering was, at 52%, the top cyber threat facing organizations. Regardless of when you are reading this section, social engineering will be still one of most dangerous attack types
Refer to www.isaca.org/cyber/PublishingImages/ISACA_CSX_Facts_2016-2-L.jpg for the top three cyber threats facing organizations in 2016.