Core Service
FILE · OIU-SVC

Your Phishing Sim Is Not What Attackers Run.

Attackers adapt. Your checklist does not. Custom, targeted social engineering campaigns that mirror how real threat actors compromise organizations through your people.

Definition Social engineering testing is a controlled simulation of the pretexting, phishing, vishing, and physical manipulation techniques used by real adversaries to compromise an organization through its people, processes, and culture.

Last reviewed:

File 01 · Definition

What It Is

Social engineering testing is a controlled simulation of the psychological manipulation techniques that real adversaries use to compromise organizations. We design and execute custom campaigns: phishing, vishing, pretexting, baiting, and physical social engineering. Campaigns that target your specific employees, processes, and organizational culture.

This is not a generic phishing simulation with a canned template and a click-rate dashboard. We build campaigns from scratch using the same OSINT, pretexting, and targeting techniques that APT groups and financially motivated threat actors use. Custom domains, tailored pretexts, researched targets, and multi-stage attack chains.

The goal is not to trick your employees into feeling stupid. It is to identify systemic weaknesses in your human security layer: gaps in training, process failures, cultural blind spots, and technical controls that should have caught the attack but did not.

The human element is involved in 68% of breaches (Verizon DBIR), and every firewall, EDR, MFA, and SIEM you have bought can be bypassed by one employee clicking the wrong link or reading a credential over the phone. The question is not whether someone falls for a sophisticated attack. Some will. The question is whether your technical controls catch it, your process contains it, and your team reports it, and that is exactly what we test.

campaign-monitor · 847 targets● 3 active

File 02 · Threat Model

Why Companies Need This

  • 01 You already run phishing simulations but do not know if they are realistic. Generic templates with obvious red flags do not test real resilience. They measure awareness training compliance, not actual security posture.
  • 02 You have experienced a successful phishing or BEC attack. Post-incident, organizations need to validate that their improved controls and training actually work against sophisticated, targeted campaigns.
  • 03 You just rolled out new security awareness training. Training is only as good as its validation. Test whether employees can apply what they learned against realistic attacks, not just recognize obviously suspicious emails.
  • 04 You operate in a high-value industry. Finance, healthcare, tech, and government organizations are targeted by sophisticated threat actors who invest significant effort in social engineering. Your testing should match the threat.
  • 05 You need to test human controls alongside technical ones. Email filtering, URL reputation, credential monitoring, and incident reporting all play a role. Social engineering testing reveals whether the full chain works.

File 03 · Deliverables

What You Get

Unlimited remediation validation included. No time cap, no per-finding charge. How it works

Campaign results report

Click rates, credential submissions, and behavioral analysis across all targets

Executive summary

Which controls caught the attack, which let it through, and where to spend the next training dollar

Individual target analysis

Which roles and departments are most susceptible, and why

Awareness recommendations

Targeted training recommendations based on actual failure patterns

Real-time comms

Dedicated Slack channel where active campaigns and live captures surface as they happen

Campaign artifacts

Copies of all phishing emails, pretexts, and landing pages used in the engagement

File 04 · Methodology

Our Process

01 TARGET

Target Profiling

OSINT on your organization, key personnel, vendors, and communication patterns. Build target lists and identify high-value individuals.

02 CAMPAIGN

Campaign Design

Develop custom pretexts, register lookalike domains, build landing pages, and design multi-stage attack chains tailored to your organization.

03 EXECUTIO

Execution

Launch campaigns across agreed vectors: email phishing, vishing, SMS, physical, or combinations. Track engagement, clicks, and credential submissions in real time.

04 CREDENTI

Credential Harvesting

Capture and securely document submitted credentials. Test whether harvested credentials provide actual access to systems and data.

05 REPORT

Reporting

Detailed campaign analysis: who was targeted, who engaged, what worked, what was caught, and where technical and human controls failed.

06 AWARENES

Awareness Recommendations

Specific, actionable recommendations for training improvements, process changes, and technical controls based on observed weaknesses.

File 05 · Intel Brief

Frequently Asked Questions

Q1 How is this different from phishing simulations we already run?

Most phishing simulation platforms use template libraries with obvious red flags: misspelled domains, generic pretexts, and known payloads that email filters easily catch. We build custom campaigns from scratch using real threat actor techniques: researched pretexts, lookalike domains, multi-stage chains, and targeted delivery. A template blast tells you who clicks an obvious lure. A targeted campaign tells you who hands over credentials to an email that looks like it came from their own CFO.

Q2 Do you target specific employees?

Yes. We can target broad employee populations for awareness baseline assessment, or focus on high-value targets: executives, finance teams, IT administrators, or any role with elevated access or authority. Targeting strategy is defined during scoping based on your objectives and threat model.

Q3 What methods do you use beyond email?

Depending on scope, we deploy vishing (voice phishing), SMS/text phishing, pretexting calls, physical social engineering (tailgating, badge cloning, impersonation), USB drops, and multi-channel campaigns that combine vectors for maximum realism. Real adversaries use whatever works. So do we.

Q4 How do you handle sensitive data?

All captured credentials are encrypted and stored securely for the duration of the engagement. We never access systems beyond what's agreed in scope. Credentials are securely destroyed after reporting. Our data handling procedures align with SOC 2 and ISO 27001 requirements, and we'll sign your NDA before scoping begins.

Q5 Will employees know they're being tested?

That is your call. Some organizations prefer full transparency to build a culture of reporting. Others prefer realistic conditions where only senior leadership and legal are aware. We recommend the approach that aligns with your organizational culture and objectives. Both produce valuable results.

Talk to an Operator

The Surface Is Already Exposed. Test It First.

Find out what your shortlist will not tell you. Send the twelve-question checklist.