Skip to content
Cover of Social Engineering: The Science of Human Hacking by Christopher Hadnagy
Security & Cyber Recommended

Social Engineering: The Science of Human Hacking

by Christopher Hadnagy

The human layer is the real attack surface — this book makes you feel it.

4.0 my rating
3.98 public avg
Status
Read · August 2024
Bought
August 1, 2024
For
Security engineers and red-teamers · Anyone who runs phishing or awareness programs · Defenders who keep forgetting the human in the threat model

The one-paragraph verdict

Hadnagy structures the whole discipline — OSINT, pretexting, elicitation, influence, the close — into a repeatable attack framework, and the real strength is the field stories. He doesn’t only parade his wins; he walks through engagements that fell apart, which is rare and makes the lessons stick. The weaknesses are just as real: it pads with restated NLP-adjacent influence theory, leans on his own company and certifications more than I’d like, and occasionally mistakes a checklist for an insight. Read past that and you come away seeing every help-desk call and lobby badge reader as an exploit primitive.

Who should read it

Security engineers, red-teamers, and anyone running phishing or awareness programs will get the most out of it — it gives you vocabulary and a methodology, not just anecdotes. Defenders who model threats purely as CVEs should read it precisely because it pushes the human into scope. People wanting a rigorous academic treatment of persuasion psychology should look elsewhere.

Where it earned its place

It changed a habit more than a belief: I now reflexively ask “who would just be told this?” before reaching for a technical exploit. That framing — that the cheapest path in is usually a person, not a port — has quietly reshaped how I read my own systems and the access flows around them.

Skip it if…

Skip it if you already run social-engineering engagements for a living, or if self-promotional padding and repeated points make you put a book down — both are present here.

#security#social-engineering#red-team#phishing#human-factors