Bishop Fox
Bishop Fox Social Engineering Methodology Overview
Pages
4
Time to read
4 mins
Publication
Language
English
Pages
4
Time to read
4 mins
Publication
Language
English
This document is a technical report detailing Bishop Fox’s social engineering methodology. It outlines the processes and deliverables involved in engaging clients to enhance their security awareness programs. The methodology comprises three main phases: pre-assessment, testing, and analysis & reporting. The pre-assessment phase includes an engagement kickoff meeting, open-source intelligence gathering, pretext development, content and payload development, and engagement scheduling. The testing phase involves active testing using various social engineering techniques, including phishing and vishing, while maintaining communication with the client. The final phase focuses on reporting the findings, which includes a narrative of the attack, an analysis of the vulnerabilities exploited, and tailored recommendations for improving security measures. This structured approach aims to provide clients with a comprehensive understanding of how social engineering attacks can be executed and the potential damage they can cause.