
Social engineering is a non-technical intrusion using human interaction to trick targets and bypass security, with human-based or computer-based tactics across research, contact, relationship exploitation, and discreet exit.
Explore how to hack into a Windows machine using various techniques, access backdoors, issue commands, view system information, dump messages or logs, and remotely shut down the target.
Set up a lab before the course, explore Android dynamics, and install apps on any Android device. Learn how to install the social engineering toolkit as an application.
Install Termux, the Android terminal emulator, to provide a no-root Linux environment on any Android device, install Python and other packages, and prepare for storage setup in the next lecture.
Set up Termux storage on Android, grant storage permissions, navigate to storage and shared folders, create directories, and access internal storage from the terminal.
Install the Social-Engineer Toolkit (SET) and complete setup in about five to six minutes. Explore SET's social engineering attack models and how hackers use it, noting spoofing may not work.
Install Metasploit framework on Android via Termux, update and upgrade packages, clone the framework, and run MSF console to view available options.
Discover information-gathering as the critical first step in social engineering, learn to plan to reduce failure risk, and examine how attackers use phishing pages and mass email campaigns against targets.
Learn how to install and map the nmap tool on Android devices, review installation progress and options, and see how it enables network mapping.
Learn how to discover devices connected to a network and scan for open ports, understanding host discovery and network status through practical scanning techniques.
Discover how to perform port scanning on a remote host with nmap, identify open ports, and assess firewall responses to reveal potential exploitation vectors.
Explore phishing techniques that disguise as legitimate sites to steal usernames and passwords through fake login pages, and understand how a framework-based workflow captures credentials.
Email spoofing forges the email header to make messages appear from another person. Attackers use fake sender details to fool recipients and prompt opens or responses.
Learn how social engineering on Android without root can gain access, and examine how payloads are delivered to machines using an alphanumeric shellcode injector for Windows systems.
Learn to generate a simple payload with the social engineering toolkit, understand payload types, and configure a listener with a target ip address and port.
Explore how to use social engineering toolkit to generate a payload and demonstrate hacking a Windows machine, including sending the payload and gathering basic information through commands.
Explore how social engineering and a PowerShell injector using Metasploit create and deliver a payload to compromise a Windows machine. Understand generating shellcode and configuring a listener.
Explore how to use an online file-sharing site to upload a payload and generate a shareable link for delivery to a victim.
Learn how hackers steal passwords from machines using different techniques and how to create a key logger on a device.
Examine an open-source usb password stealer tool used to retrieve passwords stored on a victim's computer, illustrating social engineering and malware delivery through usb devices.
Investigate how attackers recover saved passwords from a remote machine by uploading tools and executing them, illustrating techniques used in social engineering attacks.
Demonstrates creating a keylogger on Android using a hacker keyboard, detailing installation, setting the keyboard as default, and testing input capture during login.
Explore phishing attacks outside the local area network using ngrok to expose a fake login page, highlighting port forwarding and external access concepts.
Learn how to create phishing pages for popular websites using the socialfish tool. Explore social engineering techniques and how credentials are captured in the process.
Learn how attackers embed and hide payloads inside everyday files such as videos and images.
Learn how attackers embed malware in pdf files and use social engineering to exploit readers, creating a malicious payload and configuring a listener to gain control.
Explore how attackers embed malware in an image to control a victim system, using payloads, Metasploit components, and listeners to deliver and execute exploits.
Explore remote system operations after a middle partition, run basic interpreter and file system commands on the target, and learn to spy by capturing keystrokes and pin machine screenshots.
Learn how to use file system commands to navigate Android targets, list directories, view file contents, and transfer data with download, upload, and directory creation.
Demonstrate spying on a target machine by capturing keystrokes and taking screenshots, using keystroke capture commands and decoding visible keystrokes.
learn to spot phishing pages by examining links and verifying their destination before entering credentials. the lecture covers recognizing fake emails, identifying non-genuine sites, and verifying url authenticity across devices.
Identify spoof emails by inspecting sender details and email information to determine if a message truly comes from your friend or a fake address.
Learn to detect malware using online scanning sites such as Nordisk, submit files, and interpret results to identify viruses and backdoors.
Learn to find malware in pdf files by using a tool to scan for suspicious elements and assess file safety.
This highly-interactive course balances practical lectures and discussion with multiple hands-on exercises, demonstrations.
In this course, I am going to take you through the various phases so as to understand what is Social Engineering, Social Engineering Life cycle, the various Techniques used in Social Engineering attacks with detailed examples and then finally conclude with the counter-measures to protect against each of the Social Engineering attack techniques.
If you are a beginner or don't having the knowledge about the hacking if you gonna take this course am sure that by the end this course you will have the advanced level knowledge about hacking or penetration testing.
This course is intended to help you better prepare your organization for the defense of social engineering attacks, as well as how to ethically use these techniques for intelligence gathering.
Did You Know?
Social engineering attacks, which are typically launched via email, include phishing, spear-phishing and Business Email Compromise (BEC). According to the FBI, BEC scams have resulted in losses of £2.4 billion ($3.1 billion) in the previous years.
NOTE: This course is created for educational purposes only and all the attacks are launched in my own lab or against devices that I have permission to test.