Phishing, vishing, and everything in between
Social engineering is the opening move in a large share of the breaches that make the news. It bypasses the perimeter entirely, because it does not attack your technology — it asks one of your people for the keys, plausibly, at a moment when saying yes is the path of least resistance.
Brackish tests your organization against these attacks under controlled conditions, with agreed rules of engagement and a defined escalation path.
What we test
Phishing. Targeted email campaigns using pretexts built from what an attacker could actually learn about your organization, rather than a generic template.
Vishing. Voice-based pretexting against help desks, reception, and staff, to establish what an attacker can obtain or arrange over the phone.
Pretexting and in-person approaches. Where in scope, we test more than the inbox — a plausible visitor at reception, a call that sets up a drop. The building itself, as a dedicated target, is physical penetration testing. On a red team either thread is usually one part of a larger objective rather than a day of its own.
What we measure
The interesting numbers are not the ones that make a good slide. We report:
- How many people engaged with the pretext, and how many reported it
- How long it took from first interaction to first internal report
- Whether the reporting path worked as documented when someone used it
- What an attacker would have gained had the campaign been real
That last point matters most. A captured credential that hits multi-factor authentication and a monitored login alert is a very different outcome from one that opens a mailbox, and only one of them is worth acting on urgently.
What you receive
A campaign report covering the pretexts used, the aggregate response, the detection and escalation timeline, and specific recommendations for both technical controls and process. We do not name individuals unless you specifically require it.