Ecosyste.ms: Awesome
An open API service indexing awesome lists of open source software.
https://github.com/giuliacassara/awesome-social-engineering
A curated list of awesome social engineering resources.
https://github.com/giuliacassara/awesome-social-engineering
List: awesome-social-engineering
awesome-list infosec osint psychology social-engineering
Last synced: 6 days ago
JSON representation
A curated list of awesome social engineering resources.
- Host: GitHub
- URL: https://github.com/giuliacassara/awesome-social-engineering
- Owner: giuliacassara
- Created: 2017-05-12T12:22:59.000Z (over 7 years ago)
- Default Branch: master
- Last Pushed: 2023-04-05T10:31:18.000Z (over 1 year ago)
- Last Synced: 2024-12-01T02:02:06.055Z (11 days ago)
- Topics: awesome-list, infosec, osint, psychology, social-engineering
- Homepage:
- Size: 70.3 KB
- Stars: 2,739
- Watchers: 107
- Forks: 390
- Open Issues: 5
-
Metadata Files:
- Readme: README.html
- Contributing: CONTRIBUTING.md
Awesome Lists containing this project
- Hacking-Awesome - - List of awesome social engineering resources (Uncategorized / Uncategorized)
- jimsghstars - giuliacassara/awesome-social-engineering - A curated list of awesome social engineering resources. (Others)
README
README
body {
font-family: Helvetica, arial, sans-serif;
font-size: 14px;
line-height: 1.6;
padding-top: 10px;
padding-bottom: 10px;
background-color: white;
padding: 30px; }body > *:first-child {
margin-top: 0 !important; }
body > *:last-child {
margin-bottom: 0 !important; }a {
color: #4183C4; }
a.absent {
color: #cc0000; }
a.anchor {
display: block;
padding-left: 30px;
margin-left: -30px;
cursor: pointer;
position: absolute;
top: 0;
left: 0;
bottom: 0; }h1, h2, h3, h4, h5, h6 {
margin: 20px 0 10px;
padding: 0;
font-weight: bold;
-webkit-font-smoothing: antialiased;
cursor: text;
position: relative; }h1:hover a.anchor, h2:hover a.anchor, h3:hover a.anchor, h4:hover a.anchor, h5:hover a.anchor, h6:hover a.anchor {
background: url(data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABAAAAAQCAYAAAAf8/9hAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAA09pVFh0WE1MOmNvbS5hZG9iZS54bXAAAAAAADw/eHBhY2tldCBiZWdpbj0i77u/IiBpZD0iVzVNME1wQ2VoaUh6cmVTek5UY3prYzlkIj8+IDx4OnhtcG1ldGEgeG1sbnM6eD0iYWRvYmU6bnM6bWV0YS8iIHg6eG1wdGs9IkFkb2JlIFhNUCBDb3JlIDUuMy1jMDExIDY2LjE0NTY2MSwgMjAxMi8wMi8wNi0xNDo1NjoyNyAgICAgICAgIj4gPHJkZjpSREYgeG1sbnM6cmRmPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5LzAyLzIyLXJkZi1zeW50YXgtbnMjIj4gPHJkZjpEZXNjcmlwdGlvbiByZGY6YWJvdXQ9IiIgeG1sbnM6eG1wPSJodHRwOi8vbnMuYWRvYmUuY29tL3hhcC8xLjAvIiB4bWxuczp4bXBNTT0iaHR0cDovL25zLmFkb2JlLmNvbS94YXAvMS4wL21tLyIgeG1sbnM6c3RSZWY9Imh0dHA6Ly9ucy5hZG9iZS5jb20veGFwLzEuMC9zVHlwZS9SZXNvdXJjZVJlZiMiIHhtcDpDcmVhdG9yVG9vbD0iQWRvYmUgUGhvdG9zaG9wIENTNiAoMTMuMCAyMDEyMDMwNS5tLjQxNSAyMDEyLzAzLzA1OjIxOjAwOjAwKSAgKE1hY2ludG9zaCkiIHhtcE1NOkluc3RhbmNlSUQ9InhtcC5paWQ6OUM2NjlDQjI4ODBGMTFFMTg1ODlEODNERDJBRjUwQTQiIHhtcE1NOkRvY3VtZW50SUQ9InhtcC5kaWQ6OUM2NjlDQjM4ODBGMTFFMTg1ODlEODNERDJBRjUwQTQiPiA8eG1wTU06RGVyaXZlZEZyb20gc3RSZWY6aW5zdGFuY2VJRD0ieG1wLmlpZDo5QzY2OUNCMDg4MEYxMUUxODU4OUQ4M0REMkFGNTBBNCIgc3RSZWY6ZG9jdW1lbnRJRD0ieG1wLmRpZDo5QzY2OUNCMTg4MEYxMUUxODU4OUQ4M0REMkFGNTBBNCIvPiA8L3JkZjpEZXNjcmlwdGlvbj4gPC9yZGY6UkRGPiA8L3g6eG1wbWV0YT4gPD94cGFja2V0IGVuZD0iciI/PsQhXeAAAABfSURBVHjaYvz//z8DJYCRUgMYQAbAMBQIAvEqkBQWXI6sHqwHiwG70TTBxGaiWwjCTGgOUgJiF1J8wMRAIUA34B4Q76HUBelAfJYSA0CuMIEaRP8wGIkGMA54bgQIMACAmkXJi0hKJQAAAABJRU5ErkJggg==) no-repeat 10px center;
text-decoration: none; }h1 tt, h1 code {
font-size: inherit; }h2 tt, h2 code {
font-size: inherit; }h3 tt, h3 code {
font-size: inherit; }h4 tt, h4 code {
font-size: inherit; }h5 tt, h5 code {
font-size: inherit; }h6 tt, h6 code {
font-size: inherit; }h1 {
font-size: 28px;
color: black; }h2 {
font-size: 24px;
border-bottom: 1px solid #cccccc;
color: black; }h3 {
font-size: 18px; }h4 {
font-size: 16px; }h5 {
font-size: 14px; }h6 {
color: #777777;
font-size: 14px; }p, blockquote, ul, ol, dl, li, table, pre {
margin: 15px 0; }hr {
background: transparent url(data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAYAAAAECAYAAACtBE5DAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAyJpVFh0WE1MOmNvbS5hZG9iZS54bXAAAAAAADw/eHBhY2tldCBiZWdpbj0i77u/IiBpZD0iVzVNME1wQ2VoaUh6cmVTek5UY3prYzlkIj8+IDx4OnhtcG1ldGEgeG1sbnM6eD0iYWRvYmU6bnM6bWV0YS8iIHg6eG1wdGs9IkFkb2JlIFhNUCBDb3JlIDUuMC1jMDYwIDYxLjEzNDc3NywgMjAxMC8wMi8xMi0xNzozMjowMCAgICAgICAgIj4gPHJkZjpSREYgeG1sbnM6cmRmPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5LzAyLzIyLXJkZi1zeW50YXgtbnMjIj4gPHJkZjpEZXNjcmlwdGlvbiByZGY6YWJvdXQ9IiIgeG1sbnM6eG1wPSJodHRwOi8vbnMuYWRvYmUuY29tL3hhcC8xLjAvIiB4bWxuczp4bXBNTT0iaHR0cDovL25zLmFkb2JlLmNvbS94YXAvMS4wL21tLyIgeG1sbnM6c3RSZWY9Imh0dHA6Ly9ucy5hZG9iZS5jb20veGFwLzEuMC9zVHlwZS9SZXNvdXJjZVJlZiMiIHhtcDpDcmVhdG9yVG9vbD0iQWRvYmUgUGhvdG9zaG9wIENTNSBNYWNpbnRvc2giIHhtcE1NOkluc3RhbmNlSUQ9InhtcC5paWQ6OENDRjNBN0E2NTZBMTFFMEI3QjRBODM4NzJDMjlGNDgiIHhtcE1NOkRvY3VtZW50SUQ9InhtcC5kaWQ6OENDRjNBN0I2NTZBMTFFMEI3QjRBODM4NzJDMjlGNDgiPiA8eG1wTU06RGVyaXZlZEZyb20gc3RSZWY6aW5zdGFuY2VJRD0ieG1wLmlpZDo4Q0NGM0E3ODY1NkExMUUwQjdCNEE4Mzg3MkMyOUY0OCIgc3RSZWY6ZG9jdW1lbnRJRD0ieG1wLmRpZDo4Q0NGM0E3OTY1NkExMUUwQjdCNEE4Mzg3MkMyOUY0OCIvPiA8L3JkZjpEZXNjcmlwdGlvbj4gPC9yZGY6UkRGPiA8L3g6eG1wbWV0YT4gPD94cGFja2V0IGVuZD0iciI/PqqezsUAAAAfSURBVHjaYmRABcYwBiM2QSA4y4hNEKYDQxAEAAIMAHNGAzhkPOlYAAAAAElFTkSuQmCC) repeat-x 0 0;
border: 0 none;
color: #cccccc;
height: 4px;
padding: 0;
}body > h2:first-child {
margin-top: 0;
padding-top: 0; }
body > h1:first-child {
margin-top: 0;
padding-top: 0; }
body > h1:first-child + h2 {
margin-top: 0;
padding-top: 0; }
body > h3:first-child, body > h4:first-child, body > h5:first-child, body > h6:first-child {
margin-top: 0;
padding-top: 0; }a:first-child h1, a:first-child h2, a:first-child h3, a:first-child h4, a:first-child h5, a:first-child h6 {
margin-top: 0;
padding-top: 0; }h1 p, h2 p, h3 p, h4 p, h5 p, h6 p {
margin-top: 0; }li p.first {
display: inline-block; }
li {
margin: 0; }
ul, ol {
padding-left: 30px; }ul :first-child, ol :first-child {
margin-top: 0; }dl {
padding: 0; }
dl dt {
font-size: 14px;
font-weight: bold;
font-style: italic;
padding: 0;
margin: 15px 0 5px; }
dl dt:first-child {
padding: 0; }
dl dt > :first-child {
margin-top: 0; }
dl dt > :last-child {
margin-bottom: 0; }
dl dd {
margin: 0 0 15px;
padding: 0 15px; }
dl dd > :first-child {
margin-top: 0; }
dl dd > :last-child {
margin-bottom: 0; }blockquote {
border-left: 4px solid #dddddd;
padding: 0 15px;
color: #777777; }
blockquote > :first-child {
margin-top: 0; }
blockquote > :last-child {
margin-bottom: 0; }table {
padding: 0;border-collapse: collapse; }
table tr {
border-top: 1px solid #cccccc;
background-color: white;
margin: 0;
padding: 0; }
table tr:nth-child(2n) {
background-color: #f8f8f8; }
table tr th {
font-weight: bold;
border: 1px solid #cccccc;
margin: 0;
padding: 6px 13px; }
table tr td {
border: 1px solid #cccccc;
margin: 0;
padding: 6px 13px; }
table tr th :first-child, table tr td :first-child {
margin-top: 0; }
table tr th :last-child, table tr td :last-child {
margin-bottom: 0; }img {
max-width: 100%; }span.frame {
display: block;
overflow: hidden; }
span.frame > span {
border: 1px solid #dddddd;
display: block;
float: left;
overflow: hidden;
margin: 13px 0 0;
padding: 7px;
width: auto; }
span.frame span img {
display: block;
float: left; }
span.frame span span {
clear: both;
color: #333333;
display: block;
padding: 5px 0 0; }
span.align-center {
display: block;
overflow: hidden;
clear: both; }
span.align-center > span {
display: block;
overflow: hidden;
margin: 13px auto 0;
text-align: center; }
span.align-center span img {
margin: 0 auto;
text-align: center; }
span.align-right {
display: block;
overflow: hidden;
clear: both; }
span.align-right > span {
display: block;
overflow: hidden;
margin: 13px 0 0;
text-align: right; }
span.align-right span img {
margin: 0;
text-align: right; }
span.float-left {
display: block;
margin-right: 13px;
overflow: hidden;
float: left; }
span.float-left span {
margin: 13px 0 0; }
span.float-right {
display: block;
margin-left: 13px;
overflow: hidden;
float: right; }
span.float-right > span {
display: block;
overflow: hidden;
margin: 13px auto 0;
text-align: right; }code, tt {
margin: 0 2px;
padding: 0 5px;
white-space: nowrap;
border: 1px solid #eaeaea;
background-color: #f8f8f8;
border-radius: 3px; }pre code {
margin: 0;
padding: 0;
white-space: pre;
border: none;
background: transparent; }.highlight pre {
background-color: #f8f8f8;
border: 1px solid #cccccc;
font-size: 13px;
line-height: 19px;
overflow: auto;
padding: 6px 10px;
border-radius: 3px; }pre {
background-color: #f8f8f8;
border: 1px solid #cccccc;
font-size: 13px;
line-height: 19px;
overflow: auto;
padding: 6px 10px;
border-radius: 3px; }
pre code, pre tt {
background-color: transparent;
border: none; }sup {
font-size: 0.83em;
vertical-align: super;
line-height: 0;
}kbd {
display: inline-block;
padding: 3px 5px;
font-size: 11px;
line-height: 10px;
color: #555;
vertical-align: middle;
background-color: #fcfcfc;
border: solid 1px #ccc;
border-bottom-color: #bbb;
border-radius: 3px;
box-shadow: inset 0 -1px 0 #bbb
}* {
-webkit-print-color-adjust: exact;
}
@media screen and (min-width: 914px) {
body {
width: 854px;
margin:0 auto;
}
}
@media print {
table, pre {
page-break-inside: avoid;
}
pre {
word-wrap: break-word;
}
}Awesome Social Engineering
A curated list of awesome social engineering resources, inspired by the awesome-* trend on GitHub.
Those resources and tools are intended only for cybersecurity professional, penetration testers and educational use in a controlled environment.
No humans were manipulated to make this list!
Table of Contents
- Online Courses
- Capture the Flag
- Psychology Books
- Books
- OSINT
- Documentation
- Tools
- Miscellaneus
- Contribution
- License
Online Courses
PacktPub - Learn Social Engineering From Scratch by Zaid Sabih
Cybrary - Social Engineering and Manipulation - Free Course
Capture the Flag
Social-Engineer.com - The SECTF, DEFCON
Psychology Books
Most of these books covers the basics of psychology useful for a social engineer.
The Power of Habit: Why We Do What We Do, and How to Change - Charles Duhigg
Influence: The Psychology of Persuasion Paperback – Robert B., PhD Cialdini
Emotions Revealed: Understanding Faces and Feelings - Prof Paul Ekman
The Psychology of Interrogations and Confessions: A Handbook - Gisli H. Gudjonsson
Mindfucking: A Critique of Mental Manipulation - Colin McGinn
Books
Social Engineering: The Art of Human Hacking - Chris Hadnagy
Unmasking the Social Engineer: The Human Element of Security - Christopher Hadnagy, Dr. Ekman Paul
Social Engineering in IT Security: Tools, Tactics, and Techniques, Sharon Conheady
The Art of Deception: Controlling the Human Element of Security, Kevin D. Mitnick, William L. Simon
The Social Engineer's Playbook: A Practical Guide to Pretexting - Jeremiah Talamantes
OSINT
OSINT Resources
-
Awesome OSINT - Awesome list of OSINT -
OSINT Framework - Collection of various OSInt tools broken out by category. -
Intel Techniques - A collection of OSINT tools. Menu on the left can be used to navigate through the categories. -
NetBootcamp OSINT Tools - A collection of OSINT links and custom Web interfaces to other services such as Facebook Graph Search and various paste sites. -
Automating OSINT blog - A blog about OSINT curated by Justin Seitz, the same author of BHP.
OSINT Tools
-
XRay - XRay is a tool for recon, mapping and OSINT gathering from public networks. -
Intel Techniques Online Tools - Use the links to the left to access all of the custom search tools. -
Buscador - A Linux Virtual Machine that is pre-configured for online investigators -
Maltego - Proprietary software for open source intelligence and forensics, from Paterva. -
theHarvester - E-mail, subdomain and people names harvester -
creepy - A geolocation OSINT tool -
exiftool.rb - A ruby wrapper of the exiftool, a open-source tool used to extract metadata from files. -
metagoofil - Metadata harvester -
Google Hacking Database - a database of Google dorks; can be used for recon -
Google-dorks - Common google dorks and others you prolly don't know -
GooDork - Command line go0gle dorking tool -
dork-cli - Command-line Google dork tool. -
Shodan - Shodan is the world's first search engine for Internet-connected devices -
recon-ng - A full-featured Web Reconnaissance framework written in Python -
github-dorks - CLI tool to scan github repos/organizations for potential sensitive information leak -
vcsmap - A plugin-based tool to scan public version control systems for sensitive information -
Spiderfoot - multi-source OSINT automation tool with a Web UI and report visualizations -
DataSploit - OSINT visualizer utilizing Shodan, Censys, Clearbit, EmailHunter, FullContact, and Zoomeye behind the scenes. -
snitch - information gathering via dorks -
Geotweet_GUI - Track geographical locations of tweets and then export to google maps.
Documentation
Social Engineer resources
-
The Social-Engineer portal - Everything you need to know as a social engineer is in this site. You will find podcasts, resources, framework, informations about next events, blog ecc...
Tools
Useful tools
-
Tor - The free software for enabling onion routing online anonymity -
SET - The Social-Engineer Toolkit from TrustedSec
Phishing tools
-
Gophish - Open-Source Phishing Framework -
King Phisher - Phishing campaign toolkit used for creating and managing multiple simultaneous phishing attacks with custom email and server content. -
wifiphisher - Automated phishing attacks against Wi-Fi networks -
PhishingFrenzy - Phishing Frenzy is an Open Source Ruby on Rails application that is leveraged by penetration testers to manage email phishing campaigns. -
Evilginx - MITM attack framework used for phishing credentials and session cookies from any Web service -
Lucy Phishing Server - (commercial) tool to perform security awareness trainings for employees including custom phishing campaigns, malware attacks etc. Includes many useful attack templates as well as training materials to raise security awareness.
Miscellaneous
Slides
-
OWASP Presentation of Social Engineering - OWASP -
Weaponizing data science for social engineering: Automated E2E spear phishing on Twitter - Defcon 23 -
Using Social Engineering Tactics For Big Data Espionage - RSA Conference Europe 2012
Videos
- Chris Hadnagy - 7 Jedi Mind Tricks Influence Your Target without a Word
- Robert Anderson - US Interrogation Techniques and Social Engineering.mp4
- Ian Harris - Understanding Social Engineering Attacks with Natural Language Processing
- Chris Hadnagy - Social Engineering for Fun and Profit
-
Chris Hadnagy - Decoding humans live - DerbyCon 2015 - This is how hackers hack you using simple social engineering
Articles
-
The Limits of Social Engineering - MIT, Technology Review -
The 7 Best Social Engineering Attacks Ever - DarkReading -
Social Engineering: Compromising Users with an Office Document - Infosec Institute -
The Persuasion Reading List - Scott Adams' Blog -
How I Socially Engineer Myself Into High Security Facilities - Sophie Daniel
Movies
Contribution
Your contributions and suggestions are heartily♥ welcome. (✿◕‿◕). Please check the Contributing Guidelines for more details.
License
License
This work is licensed under a Creative Commons Attribution 4.0 International License