Social Engineering Awareness Cheat Sheet
Covers common social engineering attack techniques, red-flag indicators, and practical verification steps to help employees resist manipulation.
Common Attack Types
The main social engineering techniques attackers use.
- Phishing- Mass email impersonating a trusted brand to harvest credentials or deliver malware
- Spear phishing- Highly targeted phishing using personal details about the victim or organization
- Vishing- Voice-call phishing, often impersonating IT support, banks, or executives
- Smishing- Phishing via SMS text messages, frequently spoofing delivery or bank alerts
- Pretexting- Attacker invents a fabricated scenario (e.g. auditor, vendor) to extract information
- Baiting- Leaving infected USB drives or fake downloads to lure victims into executing malware
- Tailgating- Following an authorized employee through a secure door without badging in
- Quid pro quo- Offering a fake service or reward (e.g. 'free tech support') in exchange for access
Red Flags to Watch For
Signals that a message or call may be a social engineering attempt.
- Urgency- Pressure to act immediately, bypassing normal verification steps
- Authority impersonation- Sender claims to be a CEO, executive, or law enforcement to discourage questioning
- Mismatched sender domain- Display name looks legitimate but the reply-to or domain is subtly misspelled
- Unusual payment requests- Wire transfers, gift cards, or invoice changes requested outside normal process
- Generic greeting with personal ask- 'Dear user' combined with a request for sensitive credentials or data
- Unexpected attachments/links- Links or files you did not request, especially with shortened URLs
Verifying a Suspicious Link
Steps to inspect a URL before clicking, without visiting it.
# Hover over the link in your email client to preview the real URL# (do NOT click) - check the status bar or tooltip# On a suspicious link you already copied, inspect it safely:curl -sI "https://example.com/suspicious-link" | head -5 # check headers only, no rendering# Expand a shortened URL without following it (use an unshortening service)curl -sI "https://tinyurl.com/abcd1234" | grep -i location# Compare the domain against the organization's real domainwhois example.com | grep -i "creation date" # newly registered domains are a red flag
Checking Email Authenticity
Inspect SPF/DKIM/DMARC results in raw email headers to spot spoofing.
# View raw headers (Gmail: 'Show original', Outlook: 'View message details')# Look for authentication results, e.g.:# Authentication-Results: mx.example.com;# spf=fail smtp.mailfrom=attacker.com;# dkim=none;# dmarc=fail (p=REJECT) header.from=yourbank.com# spf=fail -> sending server not authorized for that domain# dkim=fail -> message content/signature does not match# dmarc=fail -> policy says reject/quarantine unauthenticated mail
What To Do When Targeted
Recommended response steps for suspected social engineering attempts.
- Do not respond directly- Never reply to or call numbers provided in the suspicious message
- Verify out-of-band- Call the person or company using a known, previously saved phone number
- Report to security team- Forward phishing emails to your organization's designated abuse/security mailbox
- Do not enter credentials- Never log in via a link from an unsolicited email; navigate to the site directly
- Preserve evidence- Keep the original email/message headers intact for incident response analysis
Reading Email Headers for Spoofing
Trace the real sending path and authentication results before trusting a message.
# Key headers to check (View Source / Show Original in most mail clients)Received: from mail.attacker-infra.net (unverified [203.0.113.45]) by mx.company.com; Wed, 21 Jul 2026 09:14:02 -0700# ^ trace top-to-bottom: the FIRST 'Received' from the bottom is closest to originReturn-Path: <[email protected]># ^ often differs from the visible 'From' - a mismatch is a red flagAuthentication-Results: mx.company.com; spf=fail (sender IP does not match SPF record) smtp.mailfrom=company.com; dkim=fail (signature did not verify) header.d=company.com; dmarc=fail action=quarantine header.from=company.com# ^ SPF/DKIM/DMARC all failing while the From: domain claims to be your own# company is a strong indicator of domain spoofing
Business Email Compromise (BEC) Patterns
Specific fraud patterns that go beyond generic phishing, targeting finance and payroll workflows.
- CEO fraud- Attacker impersonates an executive requesting an urgent, confidential wire transfer
- Invoice/vendor fraud- Compromised or spoofed vendor email requests bank details be updated before next payment
- Payroll diversion- Attacker poses as an employee asking HR to change direct-deposit details
- Lookalike domain (typosquat)- 'company-lnc.com' or 'cornpany.com' registered to intercept misdirected replies
- Thread hijacking- Attacker replies inside a real, previously compromised email thread to appear legitimate
- Attorney/urgency impersonation- Poses as legal counsel demanding secrecy and immediate action on a wire transfer
Reporting Pipeline: From User Report to Blocklist
How a reported phishing email should flow through a security team's tooling.
# User forwards suspicious email to abuse mailbox / clicks 'Report Phishing' button# (e.g. via a plugin like Cofense Reporter or Google Workspace's built-in report)# Extract indicators from the reported .eml for triagepython3 -c "import emailmsg = email.message_from_file(open('reported.eml'))print('From:', msg['From'])print('Return-Path:', msg['Return-Path'])print('Reply-To:', msg['Reply-To'])"# Detonate any links/attachments in an isolated sandbox (never on a corp endpoint)# then push confirmed-bad indicators to blocking controls:# Email gateway blocklistblocklist add domain totally-not-a-scam.example --reason "BEC campaign 2026-07-21"# SOC/SIEM correlation search - find who else received or clickedsearch index=mail sender="*totally-not-a-scam.example*" | stats count by recipient,clicked
Vishing & AI Voice/Deepfake Defenses
Countermeasures for voice-based social engineering, including synthetic voice fraud.
- Out-of-band callback verification- Hang up and call the person back using a known number from the directory, never a number given in the call
- Shared verification phrase- Pre-agreed code word for high-risk requests (wire transfers, credential resets) that a deepfake cannot know
- Treat urgency + secrecy as a combined red flag- Legitimate finance/legal requests rarely require both speed and confidentiality from normal approval flow
- Verify via a second channel- Confirm an unusual request through chat or in person, not by replying on the same channel it arrived on
- Caller ID is not proof- Caller ID and even voice can be spoofed/synthesized; it is not, on its own, evidence of identity
Measuring Program Effectiveness
Metrics security teams track to evaluate and improve awareness training over time.
- Phish-prone percentage- Share of employees who click a simulated phishing link; benchmark and trend quarter over quarter
- Report rate- Percentage of simulated (and real) phishing emails actively reported, not just ignored
- Time-to-report- Median time between delivery and the first user report; drives how fast blocklists can be updated
- Repeat clicker rate- Employees who click on multiple campaigns, indicating need for targeted coaching
- High-risk group performance- Break out results for finance, HR, and executives separately - they are BEC's primary targets
For high-value requests like wire transfers or password resets, establish a pre-agreed verbal 'safe phrase' with finance and IT teams — attackers using deepfake voice or video can mimic tone and appearance, but not a shared secret they were never told.