Karka

Free course

Phishing and Social Engineering

Spot social engineering across email, phone, chat and in person, verify before acting, and report it the right way.

What this course does not do

Some jurisdictions and sector regulators require employers to provide security awareness training, and the required audience, content and frequency differ between them. This course is written to support such an obligation; it does not by itself satisfy any named legal requirement, and your compliance team confirms what applies to your location and sector. Any refresher interval mentioned here is company policy, not a universal legal minimum.

Required in some jurisdictionsCoreSOC 2
6 modules 35 lessons 3 enrolled ~1.5h of material

First three lessons free. Full access with Founding Annual Access, ₹3,999 for your first year.

Phishing and Social Engineering

By the end

What you'll build

  • Inspect a suspicious message and name the specific signals that make it suspicious
  • Verify an unexpected request for money, credentials or data through an independent channel before acting
  • Recognise social engineering delivered by phone, text, chat, calendar invite, QR code or in person
  • Report a suspected attempt through the internal route without deleting or forwarding the evidence
  • Take the correct first steps in the minutes after you have clicked, replied or entered credentials

Curriculum

What's inside

6 modules · 35 lessons

  1. 01

    How Social Engineering Works On People

    5 lessons
    • Authority, Urgency and Fear: The Levers Behind Almost Every Attack
    • Pretexting: The Story That Makes the Ask Sound Reasonable
    • Why Busy, Competent People Fall For It
    • Reconnaissance: What an Attacker Learns About You First
    • Levers, pretexts and conditions: match what you saw to what it wasmatch pairs
  2. 02

    Reading a Suspicious Message

    6 lessons
    • A Ten-Point Inspection You Can Run in Thirty Seconds
    • Sender Names, Display Names and Look-Alike Domains
    • Links: Hovering, Shorteners and Chained Redirects
    • Attachments and the File Types That Should Make You Pause
    • Requests That Quietly Bypass an Existing Process
    • + 1 more lesson
  3. 03

    Beyond the Inbox

    7 lessons
    • Voice, Text and Chat: Social Engineering Off Email
    • Phone Pretexting and Spoofed Caller Identity
    • Messaging App Lures and Fake Recruitment Approaches
    • Calendar Invites, File-Share Notices and Collaboration Requests
    • QR Codes, Posters and Dropped Media
    • + 2 more lessons
  4. 04

    Targeted and Financial Attacks

    6 lessons
    • When the Request Appears to Come From Your Own Side
    • Spear Phishing Assembled From Public Information
    • Invoice Fraud and Bank Detail Changes
    • Supplier and Partner Account Takeover
    • Out-of-Band Verification That Actually Works
    • + 1 more lesson
  5. 05

    Reporting and Recovery

    6 lessons
    • You Clicked: The First Ten Minutes
    • Reporting Without Forwarding the Attack Onward
    • What Not to Delete, and Why
    • Simulated Phishing Exercises: What They Are and Are Not For
    • Helping a Colleague Who Has Been Caught
    • + 1 more lesson
  6. 06

    Practice and check

    5 lessons
    • Tactic, Tell and Meaningmatch pairs
    • The First Ten Minutes After You Clicksequence order
    • Say It Preciselyfill blank
    • The Invoice That Changed Its Bank Detailsscenario
    • Course quizquiz

The shape of it

How this course works

Short lessons

35 lessons across 6 modules, each small enough to finish in one sitting.

Practice as you go

Every lesson ends with a small space for what you noticed — the doing is the learning.

Progress you can see

Your progress is saved lesson by lesson, ready whenever you come back.

Ready when you are.

Make an account and this course opens up — your progress is saved from the very first lesson.