AI-Powered Social Engineering and Deepfake Exploitation Training Course
Build the attack under authorisation, then build the control that survives it
An intensive 3-day programme across the full AI-enabled attack chain — automated reconnaissance, synthetic video, cloned voice and machine-generated text. Participants build each stage in an isolated lab under authorisation, then break what they built: detection taught honestly, and verification controls designed to hold when detection fails.
About the Course
Synthetic media has stopped being a demonstration and become an operating cost. Gartner research published in May 2026 puts around 62% of surveyed organisations at a deepfake incident within a single year — 41% combined with social engineering on an audio call, 35% on a video call — while CrowdStrike’s 2026 Threat Hunting Report recorded vishing doubling across the first half of the year. Attackers now clone a voice from seconds of reference audio, sustain a fluent multi-turn conversation at campaign scale, and place a synthetic participant on a live video call. Arup lost around US$25 million to exactly that.
This 3-day programme trains security professionals to build those attacks under authorisation in an isolated lab, so they calibrate against real capability rather than a two-year-old example, and then to design the defence. Detection is taught honestly — including where detectors stop generalising to generators, codecs and compression they were never trained on — and the weight falls on controls that hold whether or not the fake is spotted: out-of-band verification, payment authority separation, provenance signalling, and identity assurance that resists an injected video stream. The legal frame travels with every technique, including the EU AI Act transparency obligations that became applicable on 2 August 2026.
-
Offensive Simulation for Red Teams
- Simulate multi-stage AI-enhanced social engineering campaigns end to end
- Build synthetic video, cloned voice and machine-generated text in a consented, isolated lab
- Attack your own detector, then design the verification controls that hold without it
-
Intensive 3-Day Format
- Accelerated learning through immersive, hands-on training
- Optimized curriculum covering essential AI security concepts
-
Cutting-Edge AI Threat Focus
- Latest AI-powered social engineering trends and attack vectors
- Advanced deepfake technology and synthetic media creation
- Machine learning-enhanced OSINT and automated target profiling
Course Content & Learning Experience
This accelerated 3-day curriculum represents a comprehensive exploration of artificial intelligence applications in social engineering contexts, from foundational machine learning concepts to sophisticated deepfake creation and detection.
Day 1: AI-Enhanced OSINT & Automated Target Profiling
Turn public exposure into a target profile the way an attacker now does it. Automated collection and aggregation at scale, language models reading a public writing sample for behavioural and communication-style signal, and computer vision pulling faces, locations and metadata out of an image set — with the legal line that runs through collection drawn as you go.
Lab Experience: Run an automated OSINT pipeline against a consented fictional persona set, then assemble a target profile you could defend in a report: what was collected, from where, under what authority, and what it actually supports.
Key Learning Areas:
- How AI changed the economics of reconnaissance — speed, cost and scale, not just quality
- Automated collection, aggregation and correlation across public and alternative sources
- Natural language processing for behavioural and communication-style profiling
- Computer vision for facial analysis, location inference and metadata extraction
- Where collection crosses a legal or authorisation boundary, and how to evidence that it did not
Day 2: Deepfake Creation & Synthetic Media Creation
Build the attack. Synthetic video has moved past GAN face-swaps and long training runs to diffusion and few-shot synthesis; voice cloning now needs seconds of reference audio; language models write pretexts that read clean and hold a conversation. The day closes on real-time work — live avatars, virtual-camera injection, and attacks against remote identity verification.
Technical Mastery: Produce synthetic video, a cloned voice and a personalised campaign to a stated quality standard from consented reference material, then run a live pipeline inside a controlled call and record what it achieved and what it cost to build.
Key Learning Areas:
- From GANs to diffusion and one-shot synthesis: what genuinely changed, and what did not
- Few-shot facial synthesis, reenactment, and the honest quality ceiling of each pipeline
- Voice cloning, real-time conversion and the full vishing kill chain
- LLM pretexting, multi-turn conversation and campaign-scale personalisation
- Live avatars, virtual-camera injection and attacks on remote identity verification
Day 3: AI Defense & Deepfake Detection Systems
Break what you built. Artefact, forensic and behavioural triage, then machine-learning detection deployed and measured against generators it has never seen — because benchmark scores hold steady while field performance quietly declines. The day ends on organisational defence, technical controls, threat intelligence, and a full-scale authorised engagement from scoping through to a report people act on.
Professional Applications: Attack your own detector and record where it fails, then design the out-of-band verification, payment-authority and incident-response controls that work without it — and run the final multi-vector simulation end to end.
Key Learning Areas:
- Artefact, forensic and behavioural detection, and precisely where each one stops working
- Deploying and evaluating ML detectors against unseen generators, codecs and compression
- Adversarial evasion, and how to read a detection vendor’s benchmark sceptically
- Provenance and content credentials, mail and call controls, injection-resistant identity assurance
- Threat intelligence, attribution, and scoping, authorising and reporting an AI-enhanced engagement
Professional Capabilities
Participants leave the intensive 3-day programme able to build the current attack under authorisation, measure what detection can and cannot do, and specify the controls an organisation should rely on instead.
AI-Enhanced Attack Development
Plan and run multi-stage social engineering campaigns that use machine learning for target analysis and personalisation, inside a defined authorisation boundary.
Deepfake Creation Mastery
Produce synthetic video, audio and imagery to a stated quality standard from consented material, for authorised security testing and awareness work.
Advanced Detection Systems
Deploy and evaluate detection for synthetic media and automated campaigns, including honest measurement against generators the model has never seen.
Organizational AI Resilience
Design the verification, payment-authority and incident-response controls that hold when detection fails, and calibrate awareness training to current attack quality.