O Engenheiro Social
Security consulting, behavioral training, and tools built on a single conviction: most breaches start with a person, not a packet. I work at that intersection.
About
I'm Luiz: a security practitioner specialized in the human side of attacks. I design phishing simulations with behavioral precision, analyze results through a proprietary methodology operationalized in S.E.A.map, and build training that actually changes how people think under pressure.
Services
I design and execute social engineering simulations (phishing, vishing, pretexting, physical) and deliver post-campaign analyses that go beyond click rates with Sea.map: a proprietary framework that covers HFACS, Bow-Tie and MITRE ATT&CK analysis. I can also help identify the organizational, behavioral, and technical conditions that make people vulnerable from DevSecOps to Human Factor, and surface actionable insights without being prescriptive.
Discuss a project →Let's make security awareness training that doesn't put people to sleep. I develop SCORM-compatible interactive modules with gamified mechanics, realistic scenarios, and didactic design focused on behavioral change, not checkbox compliance. Built for corporate audiences who've seen every slide deck already.
Discuss a project →Product
Social Engineering Attack map. A structured analysis tool that takes a phishing simulation (its pretext, visual elements, statistical results, and campaign history) and maps the full attack surface across behavioral, organizational, and technical dimensions.
Built on a proprietary HFACS-adapted methodology. Currently in private beta. The output is a layered intelligence map, not a dashboard — it surfaces why people clicked, not just how many.
Know more →Public Resource
A public taxonomy of the human layer of social engineering: the psychological principles, emotional triggers, behavioral techniques, and situational contexts that make attacks work, regardless of the delivery vector.
Each entry in SEA.db goes beyond classification. Principles include cognitive system mapping and real-world attack examples. Emotions are documented with susceptibility benchmarks drawn from 800+ live campaigns. Techniques cross-reference MITRE ATT&CK and include detection signals your team can actually act on. Every entity is planned to have a training module (SCORM-ready, for deployment in your LMS), so awareness follows structure, not guesswork.
Built from operational data, not theory. Free to use, cite, and build on.
Training Experience
You're a veteran federal agent leading a Globalpol task force hunting a social engineering gang. Over 7 investigation rounds and 40+ hours of gameplay, you learn every major technique from phishing, vishing, social media and physical attacks by investigating them.
Decisions matter. Every choice shapes the evidence you collect and the investigator you become. Four distinct endings await.
Follow development →Contact
Whether it's a simulation, a training program, early access to S.E.A.map, or just a conversation — reach out directly.