Service 02 · Social Engineering

Phishing & Social Engineering

Realistic pretext campaigns across email, SMS, voice and physical access that measure how your people respond when an attacker actually comes knocking.

Overview

What you actually get.

Technology rarely fails first; people do. Our social engineering campaigns emulate the exact lures threat actors use against your sector, then measure who clicks, who enters credentials, and crucially who reports.

We run every campaign under strict rules of engagement with care for staff wellbeing. The goal is never to shame employees; it is to find the gaps in process and awareness before a criminal does.

octasec@redteam - ~/phishing-campaign
  • 01

    Realistic pretexts

    Lures modelled on live threat-actor campaigns, not generic templates.

  • 02

    Multi-channel

    Email, SMS (smishing), voice (vishing) and physical entry.

  • 03

    Behavioural metrics

    Click, submit and report rates segmented by team.

  • 04

    Blameless by design

    Run to improve process, with staff wellbeing protected.

Scope of testing

What we cover.

>_

Email phishing

Credential harvest and payload-delivery pretexts.

>_

Spear phishing

Targeted lures against named, high-value roles.

>_

Vishing

Phone-based pretext and help-desk impersonation.

>_

Smishing

SMS lures and mobile-first attack paths.

>_

Physical

Tailgating, drop devices and on-site access.

>_

Reporting test

How fast and how well staff raise the alarm.

How it runs

The kill chain, documented.

01

Recon

Attack-surface mapping and target profiling to find the seams.

R
02

Exploit

Manual exploitation and tooling to gain a verified foothold.

E
03

Pivot

Escalation and movement toward what matters most.

P
04

Report

Ranked, reproducible findings with proof and fixes.

R
05

Remediate

Re-testing, validation and a blue-team debrief.

R
Deliverables

What lands
on your desk.

No mystery, no filler. Every engagement ends with evidence your team and your board can act on immediately.

Request a sample report
  • 01

    Campaign report

    Full metrics with click, submit and report rates by team.

  • 02

    Risk heat-map

    Where human risk concentrates across the org.

  • 03

    Awareness gaps

    Specific behaviours and processes to fix next.

  • 04

    Debrief session

    A blameless walkthrough with leadership and staff.

Related capabilities

Goes well with.

Ready when you are

Let's put this to
the test.

Book a scoping call and we'll define objectives, rules of engagement and timelines for your social engineering engagement.