Simulating AI-Driven Social Engineering Attacks in Ethical Hacking Using Microsoft 365 Defender

dc.contributor.authorAbu-Aisheh, Yazan
dc.contributor.authorFarajallah, Mousa
dc.contributor.authorAl-Sharif, Ibrahim
dc.date.accessioned2026-01-04T00:07:52Z
dc.date.available2026-01-04T00:07:52Z
dc.date.issued2025-09-29
dc.descriptionNumber of pages: 4, 2025 Engineering for Palestine Conference (ENG4PAL) PPU, Hebron, Palestine, September 29-30, 2025en_US
dc.description.abstractPhishing remains one of the most prevalent and effective social engineering attacks, primarily targeting human psychology rather than technical loopholes [1]. The recent development of artificial intelligence (AI), especially with advanced language models like OpenAi’s GPT-4, has provided cybercriminals as well as cybersecurity experts with powerful tools to create exceptionally realistic phishing messages [2]. The present research presents a comparative evaluation of AI generated phishing emails compared to conventional phishing email simulations in the context of an ethical hacking exercise, using Microsoft 365 Defender for Office 365 [3]. The customized and dynamic phishing emails were prepared using GPT-4, while the traditional static templates used were representative of common attack tactics. The experimental setup entailed a pilot group of 300 participants and measured several metrics, such as email opening rate, click-through rate (CTR), credential submission, realism perception, and improvement in awareness. The results show that AI-generated phishing emails outperformed conventional attacks across all the criteria measured, with a 48% CTR and a 34% increase in post-training awareness. The results highlight the increased realism and potency of AI-based phishing simulations [4], while also emphasizing improved, experiential security training in organizations. Future research projects will look to increase the number of participants, include statistical confirmation, and explore other modalities like voice and SMS phishing (vishing and smishing).en_US
dc.identifier.urischolar.ppu.edu/handle/123456789/9318
dc.language.isoenen_US
dc.publisherPalestine Polytechnic Universityen_US
dc.subjectSimulating, AI, AI-Driven, Social Engineering, Attacks, Ethical Hacking, Microsoft 365 Defenderen_US
dc.titleSimulating AI-Driven Social Engineering Attacks in Ethical Hacking Using Microsoft 365 Defenderen_US
dc.typeWorking Paperen_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Book_submission_91_pdf (p_313-316)_43.pdf
Size:
229.46 KB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: