❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayBlack Hills Information Security

How to Design and Execute Effective Social Engineering Attacks by Phone

By: BHIS
18 June 2025 at 10:46

How to Design and Execute Effective Social Engineering Attacks by Phone

Social engineering is the manipulation of individuals into divulging confidential information, granting unauthorized access, or performing actions that benefit the attacker, all without the victim realizing they are being tricked.

The post How to Design and Execute Effective Social Engineering Attacks by Phone appeared first on Black Hills Information Security, Inc..

How to Perform and Combat Social Engineering

By: BHIS
22 August 2024 at 23:00

This article was originally published in the second edition of the InfoSec Survival Guide. Find it free online HERE or order your $1 physical copy on the Spearphish General Store. […]

The post How to Perform and Combat Social Engineering appeared first on Black Hills Information Security, Inc..

Wishing: Webhook Phishing in Teams

By: BHIS
14 March 2024 at 09:10

Quick Jump: In the constantly evolving landscape of cybersecurity, it is common to see features designed for convenience lead to negative cybersecurity consequences. Microsoft Teams, an essential tool for corporate […]

The post Wishing: Webhook Phishing in Teams appeared first on Black Hills Information Security, Inc..

Spamming Microsoft 365 Like It’s 1995Β 

14 December 2023 at 11:00

I previously blogged about spoofing Microsoft 365 using the direct send feature enabled by default when creating a business 365 Exchange Online instance (https://www.blackhillsinfosec.com/spoofing-microsoft-365-like-its-1995/). Using the direct send feature, it […]

The post Spamming Microsoft 365 Like It’s 1995Β  appeared first on Black Hills Information Security, Inc..

Dynamic Device Code PhishingΒ 

By: BHIS
16 May 2023 at 15:55

rvrsh3ll //Β  IntroductionΒ  This blog post is intended to give a light overview of device codes, access tokens, and refresh tokens. Here, I focus on the technical how-to for standing […]

The post Dynamic Device Code PhishingΒ  appeared first on Black Hills Information Security, Inc..

Phishing Made Easy(ish)

Hannah Cartier // Social engineering, especially phishing, is becoming increasingly prevalent in red team engagements as well as real-world attacks. As security awareness improves and systems become more locked down, […]

The post Phishing Made Easy(ish) appeared first on Black Hills Information Security, Inc..

How to Not Get Scammed on Discord

By: BHIS
8 November 2021 at 17:02

Max Boehner & Noah Heckman // Introduction As 2020 sent us all into our homes social distancing,Β the demand forΒ online messagingΒ saw a huge spike in an effort for people to stay […]

The post How to Not Get Scammed on Discord appeared first on Black Hills Information Security, Inc..

How to Phish for User Passwords with PowerShell

By: BHIS
27 July 2021 at 10:22

tokyoneon // Spoofing credential prompts is an effective privilege escalation and lateral movement technique. It’s not uncommon to experience seemingly random password prompts for Outlook, VPNs, and various other authentication […]

The post How to Phish for User Passwords with PowerShell appeared first on Black Hills Information Security, Inc..

❌
❌