Scenario library / Social engineering
Helpdesk Social Engineering Intrusion: a tabletop exercise scenario
A caller convinces the service desk to reset MFA for a senior engineer. Twenty minutes later that account is enumerating privileged systems.
60–75 min · Executive + IT operations + HR

What this is modelled on
Modelled on intrusions where an attacker calls the service desk posing as an employee, has an authentication factor reset, and then moves quickly into privileged systems using ordinary access.
Why it matters
The weakest link is a helpful process, not a missing product. This exercise puts the identity verification standard, and the pressure to bypass it, on the table.
Exercise objectives
- Test identity verification standards for resets and exceptions
- Rehearse rapid account containment with HR and IT together
- Assess privileged access blast radius from one standard account
- Review call recording and audit evidence quality
Decision points tested
- Disable the account and disrupt the engineer's team, or monitor
- How to handle a possible wrongful suspicion of an employee
- Immediate control changes at the service desk
- Law enforcement and insurer engagement
Sample inject timeline
- T+0
Reset request
The service desk logs a successful MFA reset for a named engineer who is on leave.
- T+15
Unusual access
The account accesses a privileged access management console for the first time.
- T+35
Data movement
A large archive is copied to a personal cloud storage domain.
- T+55
Attribution pressure
Leadership asks whether the named employee is responsible.
What the after-action report should capture
- Verification standard adherence and exceptions
- Detection latency for first privileged access
- HR and security coordination
- Control changes agreed with owners
Run this scenario with your team
Tailor it to your environment with AI, run the injects live, and export a web or PDF after-action report when the exercise ends.
