
Explore how social engineering exploits the human factor, learn to detect and prevent attacks, and apply practical defenses for individuals and organizations.
An 18-year cyber security veteran with incident response, malware analysis, and ISMS ISO 27001 governance, now focusing on social engineering and training across government, international consulting, and banking.
Provides a disclaimer that the instructor's opinions come from over 18 years in IT security and do not represent any past, present, or future employer.
IMPORTANT: You need to watch a linked YouTube video to proceed with this course at this stage. I cant incorporate it into the course for legal reasons so please watch this video before continuing to the next lectures. Its very important to watch this 2 minute video as we will continuously analyze and explain it.
LINK: https://www.youtube.com/watch?v=xuYoMs6CLEw
Discover trigger points in social engineering that exploit spoofed caller IDs, familiar names, and urgency to build trust, induce helplessness, and pressure a cellphone provider.
Explore how social engineering began by showing early tricks to obtain free pizza and other favors, using manipulation, fake testers, complaints, and dating tactics to influence people.
Explore how the human risk factor drives social engineering, leveraging trust, timing, and emotion to bypass defenses, hacking human firewalls, and learn defensive awareness to protect passwords.
Cyber awareness is the most crucial defense, outweighing tech alone. Social engineering and phishing exploit human errors, so educating people helps detect, prevent, and protect the organization.
Social engineering remains low-cost and low-risk, delivered via phone, email, or websites, with breaches costing about 3.6 million and figures like Kevin Mitnick and Christopher Hegarty shaping the space.
New employees top the list for falling for social engineering at 41 percent, while IT professionals, clients, partners, contractors, and top management also face attacks.
Analyze sensitive, social, and non-sensitive information, illustrating how passwords and personal data enable hacking, while non-sensitive details can still pose security risks when shared online.
Explore how non-sensitive information can enable password resets to hack your Google Mail, iCloud Drive, and other accounts, underscoring the need to secure your primary email.
Never answer security questions truthfully; adopt a private password reset phrase, and enable two-factor authentication with a cell phone or hardware token, via Microsoft Authenticator or Google Authenticator.
Explore nine specific types of social engineering, such as fishing, spear fishing, whaling, smashing, impersonation, dumpster diving, baiting, and tailgating, with practical examples of attacks.
Phishing uses broad emails and messages to steal credentials or plant malware by prompting users to click links or open attachments, while spear phishing tailors attacks to individuals for success.
Examine real life phishing examples, from PayPal and DHL scams to malicious links and attachments. Learn how spear phishing and macro-enabled documents compromise security.
Explore smishing, phishing via text messages and apps, aimed at stealing credentials and multi-factor codes. Learn to recognize malicious links, hover before clicking, and avoid fake bank transfer scams.
Targeting executives and accounting staff, whaling impersonates the CEO to prompt fraudulent wire transfers.
Explore vishing as a form of social engineering that uses phone calls to obtain sensitive information and authorize actions, and learn how to prevent phishing.
Learn to prevent vishing by verifying callers with name and return number, asking the call’s purpose, and blocking suspicious numbers via IT while staying aware of AI voice cloning.
Explore impersonation as a social engineering tactic to bypass security and gain physical access by posing as security guards or technicians and exploiting human trust in access scenarios.
Enforce consistent uniforms and photo badges with entrance authentication to prevent impersonation. Ask questions, verify company affiliation, and uphold standardized physical security to guard against information leakage.
Learn how dumpster diving can recover seemingly deleted data from trash, including PINs, credit cards, paychecks, and private information, and how to securely destroy data before discarding.
Baiting is a social engineering tactic to infiltrate or exploit trade data, using usb sticks or mailed media that deploy malware and capture keystrokes.
Disable USB access for everyone and require approvals from managers and leadership, with automatic revocation. Avoid untrusted USB devices, disable auto start, and use a user account with up-to-date antivirus.
Explore tailgating or piggybacking as a common social engineering attack that exploits kindness to bypass physical security, urging vigilance to verify badges and the legitimacy of people entering secure premises.
Prevent tailgating and piggybacking with turnstiles, badge policies, and vigilant staff. Use color-coded visitor badges and biometric options to strengthen access control at doors and high-security areas.
Explore the social engineering framework detailing how attackers invest most time in open source intelligence, storytelling, and planning, with minimal time for the attack and thorough documentation to reveal gaps.
Open source intelligence (OSINT) gathers publicly available information from media, websites, and social accounts, and tools like LinkedIn, Indeed, and showdown reveal vulnerabilities.
Build a believable social engineering narrative using open source intelligence to craft an attacking identity, leverage job postings and hr interactions, and plan multi-step information-gathering attacks.
Identify how a social engineering attack plan targets the HR department, using a believable CV and a macro malware to gain access, timed for Friday 10:00 a.m.
Execute a social engineering attack on an hr department by building trust via calls, sending a malware-laden cv email, and gaining remote access through a crafted attachment.
Document the entire social engineering process with clear findings and a formal report, prioritizing training for externally facing departments and identifying crown jewels to close gaps.
Learn how the social engineering toolkit (set) in Kali Linux supports penetration testers with spear phishing, website cloning, credential grabbing, rogue access points, and QR code attacks for security testing.
Discover how attackers clone login pages to harvest usernames and passwords, including via rogue wifi hotspots, and why password reuse increases risk. Learn to verify sites and use unique passwords.
Explore the obligation social engineering tactic used to gain physical access by exploiting guards' willingness to help, and learn how to verify badges and prevent unauthorized entry.
Learn how social engineers use shared interests to build rapport, move through departments, and coax a security check pass by exploiting trust and insider help.
Examine social engineering tactics through impersonating HR and payroll to obtain personal data via spoofed internal calls. Discover defense measures like call-backs and report-driven verification to stop tailored phishing attempts.
The lecture shows how social engineering and a hardware key logger capture all keystrokes via piggybacking and impersonation, underscoring urgent reporting and incident response.
Develop the ability to detect and prevent social engineering threats for your organization, and engage with a cybersecurity experts chat group for ongoing support, questions, and safe practices.
Hacking people is the most effective hacking technique, has the highest success rate and is very difficult to detect and prevent against. Learn how to hack the human firewall and how to protect yourself and your organization against so called social engineering attacks where people get manipulated to do things they usually would not do and companies get way too easy hacked with the support of their own employees without them noticing.
This course is for non-IT people/absolute beginners up to cyber security professionals that want to get into social engineering.
Your teacher has over 18 years experience including a bachelor and master in Cyber Security and was within various expert and head of positions in the security government area, large international consulting and the banking industry.
Course Overview (around 3.5 hours of valuable content)
What is social engineering and how does it work
The human risk factor
Sensitive vs. non-sensitive information
Hacking into your e-mails, icloud and fotos with very little effort and information
How to protect against password reset attacks
Why social engineering is so dangerous
Types of Social Engineering (Phishing, Smishing, Whaling, Vishing, Impersonation, Dumpster Diving, Baiting, Tailgating)
How to prevent all those Social Engineering attacks
Social Engineering Framework and how to plan and perform a social engineering attack (Open Source Intelligence, Built Your Story, Attack Plan, Attack, Documentation)
(BONUS) Real life Social Engineering Scenarios and how to protect against them
What you can expect from this course:
Sharing long time experience in this area
Lots of practical and real life examples instead of just theoretical frameworks
A trainer that is motivated helping you to easily understand social engineering and protect yourself and your organization against these attacks
The content is shared in easy to understand language so that everyone (even non-IT people or absolute beginners) can learn social engineering and how to protect themselves
You´ll be provided the possibility to join a Cyber Security experts chat group and contact the instructor for questions
IMPORTANT: You will need to watch within lecture four a video on youtube as it shows you a practical social engineering attack that we will analyze and discuss in our course. This video cant be incorporated into the udemy plattform for legal / copyright reasons. Therefore you will need an active internet connection for this small part. The video only lasts 2 minutes.