Social Engineering Penetration Testing: Executing Social Engineering Pen Tests, Assessments and Defense

Social Engineering Penetration Testing: Executing Social Engineering Pen Tests, Assessments and Defense

ISBN-10:
0124201245
ISBN-13:
9780124201248
Pub. Date:
04/25/2014
Publisher:
Elsevier Science
ISBN-10:
0124201245
ISBN-13:
9780124201248
Pub. Date:
04/25/2014
Publisher:
Elsevier Science
Social Engineering Penetration Testing: Executing Social Engineering Pen Tests, Assessments and Defense

Social Engineering Penetration Testing: Executing Social Engineering Pen Tests, Assessments and Defense

$49.95
Current price is , Original price is $49.95. You
$49.95 
  • SHIP THIS ITEM
    In stock. Ships in 1-2 days.
  • PICK UP IN STORE

    Your local store may have stock of this item.


Overview

Social engineering attacks target the weakest link in an organization's security human beings. Everyone knows these attacks are effective, and everyone knows they are on the rise. Now, Social Engineering Penetration Testing gives you the practical methodology and everything you need to plan and execute a social engineering penetration test and assessment. You will gain fascinating insights into how social engineering techniques including email phishing, telephone pretexting, and physical vectors can be used to elicit information or manipulate individuals into performing actions that may aid in an attack. Using the book's easy-to-understand models and examples, you will have a much better understanding of how best to defend against these attacks.

The authors of Social Engineering Penetration Testing show you hands-on techniques they have used at RandomStorm to provide clients with valuable results that make a real difference to the security of their businesses. You will learn about the differences between social engineering pen tests lasting anywhere from a few days to several months. The book shows you how to use widely available open-source tools to conduct your pen tests, then walks you through the practical steps to improve defense measures in response to test results.


Product Details

ISBN-13: 9780124201248
Publisher: Elsevier Science
Publication date: 04/25/2014
Pages: 390
Product dimensions: 7.50(w) x 9.10(h) x 0.90(d)

About the Author

Gavin is the Professional Services Manager at RandomStorm and is responsible for devising and also delivering innovative testing services offered to clients, including the full range of penetration testing and social engineering engagements. Gavin has worked in IT for many years, focusing for the past five years on delivering internal and external penetration tests and social engineering engagements for multiple clients across all verticals.

Andrew is the co-founder and Technical Director at RandomStorm and is responsible for the formulation and execution of strategy for the technical department within RandomStorm. Andrew has over 20 years experience in IT with recent years focused on Internet security, offering board-level consultancy to numerous enterprise customers within disparate geographical regions. Andrew has authored several infosec titles for McGraw Hill and Cisco Press. His most recent publications have been focused on Firewalls and Threat Mitigation from common vulnerabilities. Andrew has also contributed to several books on networking topics as well as writing numerous articles for online and print trade journals and newspapers including the Sunday Times. Based in the UK, RandomStorm is a global infosec services consultancy providing turnkey solutions to organizations of any size. RandomStorm has offices in UK, US, Canada, Jordan and UAE.

Richard is a Senior Security Engineer for RandomStorm and is involved in the conducting penetration testing and social engineering assessments for clients across all verticals.

Table of Contents

Introduction to Social Engineering
Why People are the Weakest Link in your Security
Basic Techniques, Deception, and Manipulation
Assessment Prerequisites
Reconnaissance: Building the Foundation of an Assessment
Ensuring Value Through Effective Threat Modeling
Designed Targeted Scenarios
A Model for Creating Plausible Situations
The Email Attack Vector - Spear Phishing
The Telephone Attack Vector
The Physical Attack Vector
Supporting an Attack with Technology
Difference between "Long Game" and "Short Game" Attack Strategies
Writing the Report
Creating Hardened Policies and Procedures
Reclassifying Information
Improving Physical Security Controls
Designing and Conducting Effective Staff Awareness Training
Internal Social Engineering Assessments

What People are Saying About This

From the Publisher

A practical guide to planning and executing an effective social engineering security assessment and defense

From the B&N Reads Blog

Customer Reviews