conducting-social-engineering-penetration-test - Conducting Social Engineering Penetration Test
Execute social engineering penetration tests combining OSINT target profiling with phishing, vishing, and physical pretexting to measure human security.
Tags
Updated: 2026-09-24Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Harvest target email addresses
- Profile targets using OSINT tools
- Configure GoPhish server and campaign
- Execute vishing and pretexting scenarios
- Calculate risk scores and metrics
Inputs
- Senior management written authorization
- Defined penetration test scope
- Phishing domain and VPS infrastructure
- GoPhish server instance
- OSINT reconnaissance tools
Outputs
- Harvester intelligence results
- Phishing campaign metrics dashboard
- Vishing campaign metrics dashboard
- Physical security assessment evidence
- Human attack surface risk matrix
Requirements
- Senior management written authorization
- Legal compliance review
- Linux OS with GoPhish installed
- Registered lookalike domain name
- Evilginx server for MFA testing
