Uploaded August 2025 | Updated September 2026, 2 weeks ago
๐ Join us in-person and virtually at our Wild West Hackin' Fest: information security conferences โ wildwesthackinfest.com
๐ Register for Infosec Webcasts, Anti-casts & Summits. โ poweredbybhis.com
This presentation will explore the strategic use of social engineering in penetration testing. Attendees will learn tactics such as pretexting, tailgating, baiting, and phishing, all designed to manipulate human behavior and bypass physical security.
I will cover the importance of crafting a believable pretext, from creating fake work orders to using props like ID badges and uniforms, demonstrate techniques for gaining access to restricted areas, and how to navigate the target environment, avoid detection, and plant a symbolic flag.
Finally, the session will discuss post-engagement reporting and recommendations for strengthening defenses against social engineering attacks.
This talk emphasizes the ethical considerations and the need for careful planning, confidence, and adaptability throughout the operation.
00:00 - Intro/disclaimer
00:21 - What is social engineering?
01:45 - Four phases of social engineering
03:23 - Reconnaissance
05:11 - Building rapport
06:11 - Elicitation
07:11 - Pretexting
09:33 - The escape clause
10:05 - Execute a plan to gain entry
11:45 - Woman in a red dress example
12:32 - Taking advantage of distraction
14:54 - The โget out of jailโ card
15:59 - Document your findings
16:33 - Ethics
16:56 - Move in pairs
19:00 - Blending in
19:42 - Avoid suspicion
19:51 - Leave no trace
20:13 - Do not pretext as a law enforcement officer!
20:27 - Look for targets of opportunity
21:44 - Dumpster diving
21:56 - USB drop strategy
22:32 - Shoulder surfing
23:48 - Security camera
24:49 - Wi-Fi deauthentication attack
29:44 - Mainframe hacking
30:04 - Securing your server
30:32 - Abusing cleaning staff privs
31:57 - Console Cowboys sharing techniques
35:14 - Post-engagement reporting
35:45 - Cleanup and conclusions
36:03 - Q&A - Personality and personas
36:50 - Q&A - Making mistakes during the engagement
37:50 - Q&A - Defense against social engineering
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) โ Wild West Hackin' Fest: wildwesthackinfest.com
๐ Join us in-person and virtually at our Wild West Hackin' Fest: information security conferences โ wildwesthackinfest.com
๐ Register for Infosec Webcasts, Anti-casts & Summits. โ poweredbybhis.com
This presentation will explore the strategic use of social engineering in penetration testing. Attendees will learn tactics such as pretexting, tailgating, baiting, and phishing, all designed to manipulate human behavior and bypass physical security.
I will cover the importance of crafting a believable pretext, from creating fake work orders to using props like ID badges and uniforms, demonstrate techniques for gaining access to restricted areas, and how to navigate the target environment, avoid detection, and plant a symbolic flag.
Finally, the session will discuss post-engagement reporting and recommendations for strengthening defenses against social engineering attacks.
This talk emphasizes the ethical considerations and the need for careful planning, confidence, and adaptability throughout the operation.
00:00 - Intro/disclaimer
00:21 - What is social engineering?
01:45 - Four phases of social engineering
03:23 - Reconnaissance
05:11 - Building rapport
06:11 - Elicitation
07:11 - Pretexting
09:33 - The escape clause
10:05 - Execute a plan to gain entry
11:45 - Woman in a red dress example
12:32 - Taking advantage of distraction
14:54 - The โget out of jailโ card
15:59 - Document your findings
16:33 - Ethics
16:56 - Move in pairs
19:00 - Blending in
19:42 - Avoid suspicion
19:51 - Leave no trace
20:13 - Do not pretext as a law enforcement officer!
20:27 - Look for targets of opportunity
21:44 - Dumpster diving
21:56 - USB drop strategy
22:32 - Shoulder surfing
23:48 - Security camera
24:49 - Wi-Fi deauthentication attack
29:44 - Mainframe hacking
30:04 - Securing your server
30:32 - Abusing cleaning staff privs
31:57 - Console Cowboys sharing techniques
35:14 - Post-engagement reporting
35:45 - Cleanup and conclusions
36:03 - Q&A - Personality and personas
36:50 - Q&A - Making mistakes during the engagement
37:50 - Q&A - Defense against social engineering
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) โ Wild West Hackin' Fest: wildwesthackinfest.com










