RT-SOEN – Social Engineering
RT-SOEN – Social Engineering
About Course
*** Currently available at a reduced price while video lessons are in production. Video content will be added over the coming months at no additional cost to enrolled students. ***
This course lays out a complete, professional curriculum for authorized offensive social engineering within red-team programs. You will learn human-centric tradecraft from first contact to closeout: elicitation, influence, pretext design, and how to blend these skills with physical covert campaigns and hybrid ops. The course covers target research, story framing, voice and presence, space cues, timing, and escalation control, all anchored to clear Rules of Engagement and safety protocols. Learners practice comms and deconfliction, document every action for audit, and produce reusable artifacts such as pretext briefs, wardrobe and prop lists, comms trees, and AAR templates. The result is a team that executes cleanly, protects the client and the operator, and can prove its work.
This course may include AI-assisted writing, images, diagrams, examples, or quizzes. All materials are reviewed and edited before publication. AI-assisted visuals are illustrative only and are not presented as real photographs, evidence, or operational records unless specifically stated.
What Will You Learn?
- Design and validate social engineering campaigns that support covert and hybrid engagements
- Create ethical, authorized pretexts and escalation paths for human interaction testing
- Map human attack surface including suppliers, contractors, and employee behaviors
- Convert social findings into operational inputs, detection tests, and mitigations
- Coordinate social campaigns with physical and tech-based actions
Course Content
1.0 Foundations of Social Engineering
-
1.1 Social Engineering: Definitions and Scope
-
1.2 Ethical Boundaries in Social Engineering Testing
-
1.3 Authorization Requirements for Social Engineering Engagements
-
1.4 Balancing Realism with Safety in SE Testing
-
1.5 Cyber Social Engineering: Phishing and Smishing
-
1.6 Physical vs. Digital Social Engineering: When to Use Each
-
C4-T1: Social Engineering in Red Team Operations
2.0 Human Attack Surface
-
2.1 Identifying Target Roles in Human Attack Surface Research
-
2.2 Mapping Vendor Touchpoints in the Human Attack Surface
-
2.3 Building Social Graphs for Social Engineering Operations
-
2.4 Prioritizing Targets in Human Attack Surface Research
-
2.5 Documenting Human Intelligence in SE Operations
3.0 Pretext Development & Narrative Design
-
3.1 What Makes a Believable Pretext
-
3.2 Building Backstories
-
3.3 Persona Development
-
3.4 Delivery and Vendor Pretexts
-
3.5 Contractor Pretexts
-
3.6 Authority Figure Pretexts
-
3.7 Validation and Rehearsal
-
3.8 Kill-Switches and Abort Scenarios
4.0 Elicitation & Influence
-
4.1 Open vs Closed Elicitation
-
4.2 Framing and Mirroring
-
4.3 Cialdini’s Principles Applied to Red Teaming
-
4.4 Time-Based Elicitation
-
4.5 Safe Disengagement
-
4.6 Documenting Elicitation
5.0 In-Person SE Operations
-
5.1 Approach Patterns
-
5.2 Body Language and Confidence
-
5.3 Managing Suspicion
-
5.4 Exit Strategies
-
5.5 Safety in In-Person Operations
6.0 Props, Attire & Physical Elements
-
6.1 Attire Selection by Role
-
6.2 Vendor Uniforms
-
6.3 Executive and Business Attire
-
6.4 Maintenance/Service Attire
-
6.5 Props Psychology
-
6.6 Business Cards and Documents
-
6.7 Branded Items and Signage
-
6.8 Vehicle Appearance
-
6.9 Props Storage and Transport
7.0 Badge Creation & RFID Cloning for SE
-
7.1 Badge Design Principles
-
7.2 Creating Replica Badges
09:27 -
7.3 Security Features on Access Badges
-
7.4 RFID Badge Cloning During Operations
-
7.5 Legal and Ethical Considerations for Badge Operations
8.0 Digital SE Overview
-
8.1 Phishing Campaign Design
-
8.2 Landing Pages and Tracking
-
8.3 Safety Controls for Phishing Engagements
-
8.4 Coordination with Blue Team
9.0 Vendor Social Engineering
-
9.1 Targeting Third Parties: Vendors, Suppliers, and Contractors
-
9.2 Delivery Process Exploitation
-
9.3 Payment and Procurement Spoofing
-
9.4 Vendor Coordination Templates
10.0 Physical SE Integration
-
10.1 Coordinating Social Engineering with Physical Operations
-
10.2 Delivery Narratives for Physical Access
-
10.3 Escort and Visitor Management Exploitation
-
10.4 Timing and Sequencing in Combined Operations
11.0 Legal & Psychological Safety
-
11.1 Authorization Sign-Offs for Social Engineering Engagements
-
11.2 Psychological Safety in Social Engineering Engagements
-
11.3 Debriefing and Post-Engagement Support

