Communication with the employees and end users is the very first phase to be conducted after we reach the client's site. This phase includes No tech Hacking, which can also be described as social engineering. The idea is to gain knowledge about the target systems from the end users' perspective. This phase also answers the question of whether an organization is protected from the leaking of information through end users. The following example should make things more transparent.
Last year, our team was working on a white box test, and we visited the client's site for on-site internal testing. As soon as we arrived, we started talking to the end users, asking if they faced any problems while using ...