Engagement Objective
Devise various methods to (1) obtain confidential information which has been discarded and (2) manipulate employees to divulge confidential information (3) test physical access controls (4) test employee awareness to falling prey to phishing attacks
Alternative Engagement Components
- Phone Pretexting Attacks
- Dumpster Dive, Workplace Search and Physical Access
- Email "Phishing" Attacks
- Targeted Social Engineering Attacks (Requires analysis of your business processes in order to establish scripts)
Next Steps