Trustwave says its tool to search social networks by name and face can aid security penetration tests, but it might lead to privacy violations.
Cybersecurity firm Trustwave has released an open-source tool designed to search for individuals across multiple social networks simultaneously using name and facial recognition matching.
Known as Social Mapper, the software automates the process of identifying target profiles across platforms such as LinkedIn, Facebook, Instagram, VKontakte, and Weibo. While developed to streamline security assessments, the tool has sparked widespread industry debate around privacy rights, automated scraping policies, and potential misuse by malicious actors.
How Social Mapper Automates Social Engineering Tests
Traditional ethical hacking and penetration testing rely heavily on social engineering to test an organisation’s security awareness. By simulating spear-phishing attacks against employees, security teams help businesses identify technical vulnerabilities and train staff to spot credential-harvesting scams.
“Over the years we’ve discovered that a lot of the compromises and breaches that we get engaged in, in general the initial footprint, comes from a social engineering attack,” explains Karl Sigler, Threat Intelligence Manager at Trustwave.
Rather than relying on official application programming interfaces (APIs), Social Mapper operates by logging into user-provided accounts and using open-source facial recognition algorithms to match profile pictures with target names. This eliminates hours of manual research, enabling security consultants to efficiently map out organisational hierarchies and build targeted phishing simulations.
Strengthening Organisational Resilience & IT Capabilities
As social engineering and cyber threats grow increasingly sophisticated, organisations must continuously upscale their internal security controls and workforce capabilities. Building resilient infrastructure requires dedicated technical expertise—from ethical hackers and penetration testers to cloud architects and privacy compliance leads.
Partnering with a specialised tech recruitment agency ensures your organisation secures the exact skills needed to protect critical systems. You can connect with experienced cybersecurity professionals through our localised services:
-
IT recruitment – Finding elite technology leaders and cybersecurity consultants to oversee enterprise defence strategies.
-
IT recruitment in Melbourne – Sourcing experienced ethical hackers, security analysts, and systems engineers.
-
IT recruitment in Sydney – Connecting businesses with specialised threat intelligence analysts and cyber risk specialists.
-
IT recruitment in Adelaide – Accessing clearance-ready IT security experts and defence-sector software specialists.
Privacy Concerns and Platform Terms of Service
Despite its practical benefits for penetration testing, Social Mapper has raised significant privacy concerns among civil liberties advocates. Critics argue that automated profiling tools make public data far easier to exploit at scale.
Key Controversy Points
-
Privacy Violations: Civil rights advocates highlight that automated tools aggregate profile data in ways average users do not anticipate when creating social media accounts.
-
Platform Scraping Policies: Major networks explicitly prohibit automated scraping. A Facebook spokesperson confirmed the platform reaches out to developers of such software to enforce compliance with their terms of service.
-
The Defender’s Dilemma: Trustwave maintains that cybercriminals already employ automated scraping and image-matching tools behind closed doors. Providing similar capabilities to ethical testers helps organisations keep pace with real-world threat actors.
While social platforms continue to refine anti-scraping controls and restrict search functionality, tools like Social Mapper underscore the ongoing balance between defensive security research and digital privacy protection.