Training
Get a free hour of SANS training

Experience SANS training through course previews.

Learn More
Learning Paths
Can't find what you are looking for?

Let us help.

Contact us
Resources
Join the SANS Community

Become a member for instant access to our free resources.

Sign Up
For Organizations
Interested in developing a training plan to fit your organization’s needs?

We're here to help.

Contact Us
Talk with an expert

SEC467: Social Engineering for Security Professionals

SEC467Offensive Operations
  • 2 Days (Instructor-Led)
  • 12 Hours (Self-Paced)
Course created by:
James Leyte-VidalDave Shackleford
James Leyte-Vidal & Dave Shackleford
SEC467: Social Engineering For Security Professionals
Course created by:
James Leyte-VidalDave Shackleford
James Leyte-Vidal & Dave Shackleford
  • 12 CPEs

    Apply your credits to renew your certifications

  • In-Person or Virtual

    Attend a live, instructor-led class from a location near you or virtually from anywhere

  • Beginner Level

    Course content applicable to people with limited or no cyber security experience

  • 8 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Plan, execute, and defend against social engineering attacks by mastering the psychology, tools, and techniques used by adversaries and professional testers.

Course Overview

Discover the psychology and techniques behind social engineering to enhance your penetration testing skills or defend your organization. Learn reconnaissance, phishing, pretexting, and risk management through hands-on labs and real-world examples.

What You’ll Learn

  • Understand the psychological underpinnings of social engineering
  • Execute a successful social engineering test in your company or as a consultant
  • Develop new variations of social engineering attacks or increase your snare rate
  • Navigate the ethical challenges and risks associated with social engineering engagements
  • Enhance other penetration testing disciplines by understanding human behavior and how to exploit it

Business Takeaways

  • Broaden skill set for penetration testers and red teamers
  • Strengthen defense strategies for blue teamers and security leaders
  • Improve ability to communicate risk to stakeholders and leadership
  • Uncover risks that cannot be found with traditional testing
  • Prepare teams to recognize, resist, and report attacks

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC467: Social Engineering for Security Professionals.

Section 1:Social Engineering Fundamentals, Recon, and Phishing

Section one covers key social engineering concepts, goals, and reconnaissance tools to prepare for successful campaigns. You will complete exercises on phishing—the most popular and scalable attack—understanding how to execute attacks, discovering what works and what doesn’t, and learning how to report findings to improve defenses.

Topics covered

  • Psychology of Social Engineering
  • Targeting and Recon
  • Secure and Convincing Phishing
  • Tracking Clicks
  • Secure Phishing Forms

Labs

  • Recon and Profiling
  • Tracking Clicks
  • SET Site Cloning
  • Data Logging

Section 2Defense in Depth

Section two dives into crafting effective payloads, covering evasion, risk reduction, and building believable snares. You will learn pretexting to boost success, then apply your skills in a Capture-the-Human exercise, finishing with key “dos” and “don’ts” for successful social engineering engagements.

Topics covered

  • USB and Media Drops
  • Building a Payload
  • Successful Pretexting
  • Tailgating and Physical Access
  • Social Engineering Reports

Labs

  • PowerShell Payloads
  • Roll Your Own Payload
  • Pretty Payloads
  • Pretexting
  • Capture the Human

Things You Need To Know

Relevant Job Roles

Application Pen Tester

Offensive Operations

Application penetration testers probe the security integrity of a company’s applications and defenses by evaluating the attack surface of all in-scope vulnerable web-based services, clientside applications, servers-side processes, and more. Mimicking a malicious attacker, app pen testers work to bypass security barriers in order to gain access to sensitive information or enter a company’s internal systems through techniques such as pivoting or lateral movement.

Explore learning path

Course Schedule & Pricing

Looking for Group Purchasing Options?Contact Us
Filter by:
  • Location & instructor

    Chicago, IL, US & Virtual (live)

    Instructed by Dave Shackleford
    Date & Time
    Fetching schedule..View event details
    Course price
    $3,505 USD*Prices exclude applicable local taxes
    Enrollment options
  • Location & instructor

    Virtual (live)

    Instructed by James Leyte-Vidal
    Date & Time
    Fetching schedule..View event details
    Course price
    $3,505 USD*Prices exclude applicable local taxes
    Enrollment options
  • Location & instructor

    Virtual (live)

    Instructed by James Leyte-Vidal
    Date & Time
    Fetching schedule..View event details
    Course price
    $3,505 USD*Prices exclude applicable local taxes
    Enrollment options
Showing 3 of 3

Benefits of Learning with SANS

Instructor teaching class with code in the background

Get feedback from the world’s best cybersecurity experts and instructors

Learning via laptop

Choose how you want to learn - online, on demand, or at our live in-person training events

Learning via laptop

Get access to our range of industry-leading courses and resources