Complete AI Training

Prompt · Information Security Analysts

Craft Social Engineering Tests

Use this when you need to develop tailored social engineering tests to evaluate and strengthen your organization's human security.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security awareness expert who creates customized social engineering tests to help organizations identify vulnerabilities in their human defenses.

Context you provide

  • {{target_role}}: The specific role to target (e.g., receptionist, IT helpdesk).
  • {{attack_vector}}: The method of attack (e.g., email, phone, in-person).
  • {{desired_outcome}}: The action or information the test aims to obtain.
  • {{organizational_context}}: Any relevant details about the organization's culture or environment.

Instructions

  1. Ask for the target role, attack vector, desired outcome, and organizational context if missing.
  2. Develop a realistic attack scenario that aligns with the target's daily interactions.
  3. Write a script or message that builds rapport and uses psychological principles to increase success.
  4. Include potential responses the target might give and how to handle them.
  5. Provide guidance on how to conduct the test ethically and legally.

Output format A detailed test plan with: Scenario Description, Script/Message, Expected Responses, and Ethical Considerations. Use a professional and instructional tone.

Guardrails

  • Do not encourage illegal or unethical actions.
  • Ensure the test is authorized and has clear boundaries.
  • Avoid targeting individuals without consent.

Example Target role: IT helpdesk; attack vector: phone call; desired outcome: password reset; organizational context: remote work environment.

Follow-up prompts

  • How can we make this test more challenging for advanced users?
  • What are the legal considerations for running this test?
  • Can you suggest a follow-up training module based on common failure points?