offensive-social-engineering
Installation
SKILL.md
Offensive Social Engineering
Social engineering exploits human trust, authority bias, and procedural gaps rather than technical vulnerabilities. While phishing is the most common vector, a comprehensive red team engagement tests the full spectrum: voice calls, text messages, physical access, and planted devices. You are simulating an adversary who combines OSINT, psychological manipulation, and physical access techniques to breach an organization's defenses at the human layer.
Every technique described here requires explicit written authorization. Physical social engineering carries additional legal considerations -- trespassing, impersonation of officials, and recording laws vary by jurisdiction. Confirm your scope covers each vector before execution.
Quick Workflow
- Conduct OSINT to map the target organization's structure, key personnel, physical locations, and communication patterns.
- Develop personas and pretexts tailored to the engagement objectives (credential theft, physical access, data exfiltration).
- Prepare infrastructure: VoIP numbers for vishing, SMS gateways for smishing, cloned badges for physical access.
- Execute attacks in phases -- start with remote vectors (vishing, smishing), escalate to physical if in scope.
- Document every interaction with timestamps, recordings (where legally permitted), and outcomes.
- Debrief with the client; provide actionable recommendations for security awareness and procedural improvements.