SAINTCON 2016 - Brent White & Tim Roberts - Forging Your Identity : Credibility Beyond Words

Experts Brent White and Tim Roberts share real-world social engineering tactics for infiltrating companies, showcasing the skills and knowledge needed to build a convincing fake identity.

Key takeaways
  • Forge an identity by learning about the company and creating a back story.
  • Use fake letters of authorization to gain access to clients’ facilities.
  • Employ social engineering techniques, such as acting as a contractor or a vendor, to gain access to secure areas.
  • Use recon to gather information about a company’s security protocols and exploit vulnerabilities.
  • Create a convincing disguise by using a clipboard, a hat, and a fake badge.
  • Act as a “listening post” by sitting in a public area and gathering information from others.
  • Use a fake phone call to gain access to a secure area.
  • Practice persuasion skills and learn to adapt to situations.
  • Use open-source intelligence to gather information about a company’s security policies and procedures.
  • Employ “redirection” tactics to test security protocols and gain access to secure areas.
  • Use a fake ID and backstory to gain access to a company’s facilities.
  • Learn to recognize warning signs and indicators of suspicious activity.
  • Use a fake letter of authorization to gain access to a company’s data center.
  • Employ “cold calling” tactics, such as knocking on doors and introducing yourself as a vendor or contractor.