Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Gartner Security & Risk Management Summit | 22 - 24 Sep 2026

Virtual Practical Application of Social Engineering

Type Training
Organization Social-Engineer, LLC
Event Format Online
Size < 50 approximate delegates
Registration Not Free

Search for other Cybersecurity Conferences in the United States or discover other Cyber Events in Florida in 2026-2027.

Training Description

Key Takeaways

  • Five-day virtual training programme combining open-source intelligence gathering with social engineering attack methodologies
  • Designed for red-team operators, penetration testers and cybersecurity professionals conducting adversarial simulations
  • Covers phishing, vishing and smishing campaign development with live execution against human targets
  • Integrates two established curricula: Practical OSINT for Social Engineers and Social Engineering Risk Assessment
  • Emphasises pretext development, intelligence documentation and instructor-guided feedback

Introduction

The Practical Application of Social Engineering (PASE) course offers cybersecurity professionals an intensive virtual training experience focused on the human element of security testing. Delivered over five consecutive days, the programme targets red-team operators and penetration testers who need to develop sophisticated social engineering capabilities that extend beyond technical exploitation. As organisations increasingly recognise that human vulnerabilities represent their most significant attack surface, the ability to conduct realistic adversarial simulations has become an essential skill within offensive security teams.

Social engineering attacks continue to dominate breach statistics, with phishing and pretexting remaining the primary vectors through which threat actors gain initial access to corporate environments. This reality has driven demand for security professionals who can accurately replicate these attack patterns during authorised engagements, helping organisations identify weaknesses in their security awareness programmes and procedural controls before malicious actors exploit them.

About This Event

PASE consolidates two complementary training programmes into a single immersive experience. The course merges the Practical OSINT for Social Engineers curriculum, which focuses on intelligence gathering and reconnaissance techniques, with the Social Engineering Risk Assessment programme, which addresses attack planning and execution. This integration allows participants to progress through the complete lifecycle of a social engineering engagement within a structured learning environment.

The virtual delivery format enables participants to engage with the material from any location while still benefiting from live instruction and real-time feedback. Certified instructors guide attendees through each phase of the training, providing critique and refinement suggestions as participants develop and execute their attack scenarios.

Open-Source Intelligence as the Foundation for Social Engineering

Effective social engineering campaigns depend heavily on the quality of reconnaissance conducted before any direct contact with targets. The PASE curriculum dedicates substantial attention to open-source intelligence techniques, teaching participants how to extract actionable information from publicly available sources. This includes metadata analysis, which can reveal organisational structures, technology stacks and individual employee details that inform pretext development.

The intelligence gathering phase distinguishes professional red-team engagements from simplistic phishing attempts. By thoroughly researching target organisations and individuals, operators can craft communications and scenarios that appear legitimate and contextually appropriate. The course emphasises not only the collection of raw data but also its refinement and documentation in formats that support subsequent attack planning.

Attack Vector Development and Execution

The programme covers three primary communication channels used in social engineering attacks. Phishing involves crafting deceptive email communications designed to elicit specific actions from recipients, whether clicking malicious links, providing credentials or executing attachments. Vishing, or voice phishing, requires participants to develop telephone-based pretexts and conduct live calls against targets. Smishing extends these techniques to SMS and text-based messaging platforms, which have become increasingly prevalent attack vectors as mobile device usage has expanded.

A distinguishing feature of the PASE training is its use of actual human targets during simulations. Rather than relying solely on theoretical exercises or controlled laboratory environments, participants execute their developed campaigns against real individuals under instructor supervision. This approach provides authentic feedback on pretext effectiveness and helps operators understand how targets respond to various manipulation techniques in practice.

Pretext Development and Campaign Planning

Creating convincing pretexts requires understanding both the target organisation’s context and the psychological principles that influence human decision-making. The course guides participants through the process of constructing scenarios that appear plausible to recipients, incorporating details gathered during the OSINT phase to enhance credibility. Effective pretexts typically leverage authority, urgency, social proof or other influence factors that encourage compliance without triggering suspicion.

Campaign planning extends beyond individual message crafting to encompass the broader operational considerations of a social engineering engagement. This includes timing considerations, target selection strategies, escalation paths and documentation requirements that support client reporting. Professional red-team operations require meticulous planning to ensure engagements remain within authorised scope while generating meaningful security insights.

Who Should Attend

The training is designed for security professionals who conduct or support offensive security operations. Red-team operators seeking to enhance their social engineering capabilities represent the primary audience, though the programme also benefits penetration testers who wish to expand beyond technical testing into human-focused assessments. Security consultants who deliver social engineering risk assessments for clients will find the structured methodology valuable for standardising their engagement approach.

Participants should possess foundational knowledge of cybersecurity concepts and ideally have some prior experience with penetration testing or security assessments. The course assumes familiarity with common attack frameworks and the ethical considerations that govern authorised security testing activities.

The Growing Importance of Human-Focused Security Testing

Technical security controls have matured significantly over the past decade, making direct exploitation of systems increasingly difficult for attackers. This evolution has shifted adversary focus toward human targets, who often represent the path of least resistance into otherwise well-defended environments. Organisations that invest heavily in firewalls, endpoint protection and network monitoring may still fall victim to a well-crafted phishing email or a convincing telephone pretext.

Security programmes that neglect human-focused testing leave a significant blind spot in their defensive posture. By engaging professionals capable of conducting realistic social engineering simulations, organisations gain visibility into how their employees respond to manipulation attempts and can target awareness training toward demonstrated weaknesses rather than theoretical vulnerabilities.