ALL PASS, NO FAIL!

CEH v13 Module 9: Social Engineering

Social engineering is the art of human manipulation. This module covers various social engineering attack vectors including phishing, spear phishing, whaling, vishing, smishing, pretexting, baiting, tailgating, and quid pro quo. Understanding psychological principles of influence is key to both launching and defending against these attacks.

The CEHStudy app carries 16 flashcards for Module 9 across 3 sections — the overview section defines the core techniques; use the psychological-principles cards to learn why each one works.

Key Topics Covered

Important Terms & Concepts

Phishing: Bulk fraudulent emails designed to trick recipients into revealing sensitive information (credentials, financial data) or clicking malicious links.
Spear Phishing: Targeted phishing attack directed at a specific person or organization. Uses researched information about the target for higher success rate.
Whaling: A subset of spear phishing that specifically targets senior executives and high-profile individuals who have access to sensitive corporate data.
Vishing (Voice Phishing): Social engineering via phone calls. Attackers use caller ID spoofing, IVR systems, and urgency to manipulate victims into disclosing information.
Smishing: SMS-based phishing. Uses text messages with malicious links or requests for personal information. Growing rapidly with mobile device usage.
Pretexting: Creating an entirely fabricated scenario (e.g., fake IT support call) to persuade the victim to release information. The attacker builds a believable story over time.
Baiting: Offering something enticing to trick the victim into installing malware or revealing credentials. Example: leaving infected USB drives in parking lots labeled "Confidential Payroll."
Tailgating: Physically following an authorized person into a restricted area without using credentials. Countermeasure: challenge unrecognized individuals and use mantraps.

Psychological Principles of Influence

How to Study This Module

Frequently Asked Questions

What is the most common social engineering attack?
Phishing remains the most widely used social engineering attack, accounting for the majority of security breaches. Spear phishing is the most effective due to its targeted nature.

How do you protect against social engineering?
Security awareness training, multi-factor authentication, verification procedures (never share info on unsolicited calls), and establishing clear security policies.

Related Modules

What is Social Engineering in Ethical Hacking?

Social Engineering is a core domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. It covers human-manipulation techniques that bypass technical controls — bulk phishing, targeted spear phishing and executive whaling. No amount of technical security stops a manipulated willing participant; the human is the weakest link in the security chain. Module 9 accounts for approximately 10% of CEH v13 exam questions.

Key Concepts in Social Engineering

Common Exam Mistakes in Module 9

Scrambling the delivery-channel variants: the exam names channels, not just "phishing." Vishing = voice, smishing = SMS, quishing = QR codes (email filters cannot scan them, hiding the destination until the victim scans — parking tickets, event passes and Wi-Fi signs are the usual lures); whaling targets C-suite executives, not a channel.
Blending baiting, pretexting, and tailgating: baiting leaves something tempting behind — the classic is an infected USB drive in a parking lot. Pretexting builds a fabricated scenario, usually a cover identity like IT support. Tailgating (piggybacking) is following through a secured door; dumpster diving searches trash for documents. Four distinct techniques, four distinct answers.
Picking technology as the "most important" defense: when the question asks for the single most important control against social engineering, the answer is ongoing employee training and security awareness — people who verify requests and run regular simulations. MFA limits the damage of a successful credential grab but does not stop the willing click.

Tools Used in Social Engineering

The tools the CEH exam references for this domain — several serve both offense and authorized awareness testing:

Worked Example: Building a Spear-Phish for the Finance Team

Researching acme-corp, the attacker finds on LinkedIn that the new controller, "Dana R.", just joined from a rival firm — a perfect urgency hook. Using TheHarvester and SpiderFoot, they pull valid email addresses and the company's real invoice vendor name, then register a look-alike domain (one missing letter) that renders identically at a glance.

The delivery: a spear-phished "urgent: payment failed" email lands in Dana's inbox during quarter close and links to a fake Microsoft login on the spoofed domain — the victim types real credentials into what looks like their own portal. The exam follow-up asks for countermeasures: verification procedures for wire requests, DMARC/DKIM/SPF on outbound mail, and awareness training that makes "urgent executive" the phrase to treat with suspicion.

How to Study Social Engineering for the CEH v13 Exam

To study Module 9:

  1. Create a comparison table of all SE attack types: delivery channel (email/phone/SMS/physical/website), targeting level (bulk/individual/executive), and primary goal (credentials/malware/access) — the exam's staple 'identify the attack type' question
  2. Memorize the six psychological principles with real-world examples — expect a question mapping a specific tactic to its trigger
  3. Hands-on: set up Gophish locally (Docker container), build a fake company password-reset template, run it against yourself in a test environment, and analyze the campaign statistics (click rate, credential submissions) — the metrics organizations track in awareness programs
  4. Review related modules: Module 14 (Web Application Hacking) for building phishing delivery vehicles, and Module 2 (Footprinting & Reconnaissance) for the OSINT research behind targeted spear phishing

Frequently Asked Questions About Social Engineering

Why is social engineering considered the most effective attack vector in real-world breaches?

According to Verizon's Data Breach Investigations Report (DBIR), social engineering is involved in approximately 74% of all data breaches. Humans are the least secure component of any system: one manipulated employee who clicks a link or shares a password bypasses every encryption, firewall rule and access control. Security awareness training cuts successful phishing rates by up to 70%, but no training eliminates the risk; defense in depth must combine human and technical controls.

What is Business Email Compromise (BEC) and how does it relate to the CEH exam?

Business Email Compromise impersonates an executive (CEO fraud), vendor or business partner to redirect financial transactions. The FBI's IC3 reports BEC as the single most costly cybercrime — losses exceeding $2.9 billion in 2023 alone. Unlike standard phishing, the goal is financial fraud (wire transfer redirection), not credential theft; on the CEH exam it falls under whaling/CEO fraud categories. Indicators: urgent payment requests, unfamiliar recipients, slight domain variations (ceo-company.com vs ceo.company.com), requests to bypass normal approval. Primary defense: multi-level approval for financial transactions and out-of-band verification for unusual requests.

Related CEH v13 Modules

Related Glossary Terms