Social engineering
Social engineering is attacking the human element of security — manipulating people into revealing information or taking actions, rather than exploiting software. It is the discipline the awesome-social-engineering corpus maps, and it sits beside OSINT in this spoke because the two are one chain: OSINT is the reconnaissance, social engineering is the act.
The pieces
- Persuasion psychology — the influence/manipulation principles (Cialdini, Hadnagy, Mitnick) the field is built on; the “why it works.”
- Pretexting & phishing — the delivery: a credible false context, often by email/web (Gophish, Evilginx2, and other tooling in awesome-social-engineering).
- Reconnaissance — OSINT supplies the target’s habits, contacts, and context that make a pretext believable. A profile from llm-osint or kallisto-osinter is, in this frame, pre-attack intelligence.
Why OSINT and social engineering belong together
A pretext is only as good as what you know about the target, so better recon → better social engineering. That is precisely why automating OSINT matters for this discipline: AI-OSINT makes the reconnaissance phase cheap and scalable, which raises the stakes of the human-element attack — and of the defenses against it.
Defense
The same body of knowledge is defensive: awareness training, recognizing pretexts, and the Social-Engineer community/Layer 8 resources in awesome-social-engineering. The spoke documents the field to understand and defend against it, scoped (per the source’s own disclaimer) to professionals and controlled-environment education.
Related
osint · ai-osint · awesome-social-engineering · llm-osint · synthesis