Skip to main content

Social Engineering Test

Social Engineering Test

The term social engineering refers to a practice aimed at obtaining confidential information through the manipulation of legitimate users. It is an attack directed at the user’s trust with the purpose of determining what sensitive information can be obtained by following a proprietary methodology developed based on internationally recognized Social Engineering techniques.

Our Social Engineering services have as their main objective to evaluate the human behavior of employees within an organization when facing the most common attacks in the field of social engineering, in order to identify strengths and weaknesses in security policies, as well as their level of knowledge and real implementation.

Confidential information within organizations is an important asset through which fraud can be committed or unauthorized access to the information system can be obtained.

The types of attacks can be very diverse:

  • Automated tools that collect email addresses from web search engines.
  • Searches on social networks for information published by employees, collaborators, etc.
  • Phone calls impersonating key personnel, support, help desk, etc.
  • Physical access to facilities by validating access controls from both outside and inside.
  • Phishing attacks.
  • Etc.

The process to follow in a social engineering test is shown in the following diagram:

 

 

After the information gathering and relationship‑building phases, the exploitation and analysis phases are carried out within an iterative process consisting, on one hand, of executing exploitation tests and, on the other, analyzing the results obtained to modify specific aspects of those tests whose outcome was not successful.

In this way, it is possible to correct those aspects that may have caused the failure in any of the tests performed.

Finally, the results are documented as follows:

  • Objectives and scope of the work.
  • Overall security rating.
  • Executive summary of the issues found.
  • Detailed (low‑level) description of all tests performed.
  • Conclusions.

What Our Clients Say


Do not hesitate to contact us if you need more information

Send us your questions and we will get in touch with you as soon as possible.
CAPTCHA