Lab 1.1: Social Engineering Techniques & Reconnaissance
CompTIA Security+ Module 01
Overview
In-depth hands-on laboratory exploring the social engineering attack landscape and reconnaissance techniques. This comprehensive module equipped me with the knowledge and practical skills to identify, analyze, and defend against sophisticated social engineering attacks—a critical component of modern cybersecurity operations.
Core Competencies Developed
🎯 Social Engineering Attacks
- • Phishing & Variants: Spear phishing, whaling, vishing, smishing
- • Physical Attacks: Shoulder surfing, tailgating, dumpster diving, baiting
- • Digital Methods: Typosquatting, hoaxes, identity theft, credential harvesting
- • Channel-Based: Spam, SPIM (SMS/IM), malware attachments
🔧 Kali Linux Tools & Techniques
- • Recon-ng: Automated reconnaissance framework for OSINT gathering
- • theHarvester: Email and subdomain enumeration tool
- • Nmap: Network discovery and port scanning for live host detection
- • DNS & Wireshark: DNS querying and network packet analysis
📚 Module Exercises & Topics
Exercise 1: Social Engineering Fundamentals
Explored the psychological and technical foundations of social engineering attacks, analyzing how attackers manipulate human behavior to bypass security controls.
Topics Covered:
- Phishing Attacks: Website spoofing, credential harvesting, pharming, and DNS cache poisoning techniques
- Phishing Variants: Spear phishing (targeted), whaling (executive-focused), and prepending (machine learning-enhanced)
- Attack Vectors: Email, malicious websites, in-person manipulation, and phone calls
- Success Factors: Lack of user awareness, visual deception, and psychological manipulation
Exercise 2: Social Engineering Principles & Methods
Analyzed the psychological principles attackers exploit and diverse attack methodologies used in real-world scenarios.
Attack Methodologies:
- Authority: Impersonating law enforcement or IT personnel to pressure victims
- Trust & Relationship Building: Establishing rapport before information extraction
- Physical Attacks: Shoulder surfing, tailgating, baiting with infected USB drives, dumpster diving
- Digital Exploitation: Typosquatting, hoaxes, SPIM, and instant messenger attacks
- Identity Compromise: Identity theft, invoice scams, impersonation campaigns
Exercise 3: Reconnaissance & Footprinting
Practical reconnaissance lab utilizing Kali Linux tools to conduct OSINT gathering, network enumeration, and system fingerprinting.
Hands-On Skills:
- DNS Querying: Performing nslookup and dig commands to identify target infrastructure
- Recon-ng: Executing automated reconnaissance modules for email discovery and subdomain enumeration
- theHarvester: Harvesting email addresses and metadata from open sources
- Network Discovery: Identifying live hosts on target networks using Ping scans
- Port Scanning: Conducting Nmap port scans to identify open services and running software
- System Fingerprinting: OS and application version detection for vulnerability assessment
- Packet Analysis: Using Wireshark to analyze network traffic and identify reconnaissance patterns
🛠️ Technical Skills Acquired
Reconnaissance Tools
- • Recon-ng
- • theHarvester
- • Nmap
- • dig/nslookup
- • Wireshark
Analysis Techniques
- • OSINT Gathering
- • Network Enumeration
- • System Fingerprinting
- • Attack Surface Mapping
- • Vulnerability Identification
Security Knowledge
- • Social Engineering Tactics
- • Threat Assessment
- • Risk Evaluation
- • Defense Strategies
- • User Awareness Training
💡 Key Insights & Applications
- Human Factor: Social engineering exploits human psychology rather than technical vulnerabilities—making user education critical for defense
- Multi-Vector Attacks: Sophisticated threats combine phishing, OSINT gathering, and technical reconnaissance for targeted campaigns
- Reconnaissance Value: Open-source intelligence gathering can reveal substantial attack surface without triggering security alerts
- Layered Defense: Effective security requires combining technical controls, user training, and process improvements
- Practical Impact: Understanding attacker methodologies directly improves incident response and threat modeling capabilities
📋 CompTIA Security+ Alignment
This lab directly addresses Security+ Exam Objective 1.1: "Compare and contrast different types of social engineering techniques."
Covered Techniques
- Phishing (all variants)
- Vishing & Smishing
- Spear phishing & Whaling
- Physical social engineering
- OSINT reconnaissance
Practical Application
- Hands-on tool usage
- Attack scenario analysis
- Vulnerability assessment
- Defense strategy development
- Incident response preparation