TechKnowSurge
NIST NICE K1087 ISC2 CC 2.3 Cisco CCST Cybersecurity 1.2 NIST 800-53 AT-2 NIST NICE K0825 NIST 800-53 SI-8 NIST NICE K0994 NIST NICE K0684 NIST CSF PR.AT-01
VideoSecurityFree

Threats - Social Engineering Techniques

Social engineering is the manipulation of a person, rather than a system, to obtain information or provoke an action that serves the attacker. This coverage defines social engineering and walks through the methods of contact, the tactics, and the forms of false information a threat agent uses.

Complete this video to capture a CTF flag worth 1 point.

About this video

Social engineering is the manipulation or control of one person by another in order to obtain information or produce some other fraudulent outcome. What makes it work is not a technical weakness but a human one: the brain automates routine activity and extends trust to familiar people and roles, so a great deal of everyday behavior happens without conscious scrutiny. A threat agent who understands those built-in functions can leverage them for their own gain, which is why social engineering is best understood as an attack on a person rather than on a system. Every social engineering attack opens with a method of contact. Message-based contact is the most common, and phishing is its central form — an email or other message sent to extract credentials or other sensitive information. Phishing is named differently depending on who is targeted, how, and for what: spear phishing is a targeted attack against a specific individual or organization; whaling is spear phishing aimed at a senior figure such as a CEO; smishing arrives by text message, so named because texting runs on the Short Message Service protocol; vishing arrives by voice call; and instant messaging carries the same threat. A phishing email sent to an employee while impersonating someone else inside the same company is a business email compromise, or BEC. In-person contact covers shoulder surfing, in which an attacker watches a target enter credentials, and tailgating, in which an attacker follows an authorized person through a controlled entry point. There are also no-contact techniques, where the attacker never approaches the target directly: baiting leaves an enticing object such as an infected thumb drive for a victim to pick up and use, dumpster diving recovers sensitive material from discarded trash and recycling, and a watering hole attack compromises a third-party website the target organization is known to visit so that its users are infected there. On top of the method of contact sit the tactics that make the approach persuasive. Impersonation borrows credibility from a trusted person, an authority figure, or a trusted department such as IT. Quid pro quo offers something in exchange for information or access. Blackmail threatens the release of damaging information unless the target complies. And underneath most of these is the deliberate provocation of an emotion — curiosity, fear, or urgency — because a target who reacts quickly is a target who has stopped scrutinizing. Impersonation itself takes several specific forms, including business email compromise, brand impersonation, typosquatting — registering a look-alike domain that catches a common typo and sends the visitor to a fraudulent site — and pretexting, where the attacker builds a fabricated but compelling story to justify the request. The same manipulation scales to a mass audience as false information. Misinformation is inaccurate information spread by someone who believes it to be true. Disinformation is false information created and spread deliberately to deceive. A deep fake uses voice or video alteration to portray a real person saying or doing something they never said or did. Social engineering at this scale is a large and organized problem — entire businesses operate as cyber crime enterprises, and millions of people are targeted each year — which is why user education remains the primary defense: a person who can name the technique being used on them is far harder to manipulate.

What you'll learn

What's covered

Social Engineering Techniques

Aligned to

NIST NICE
K1087 Knowledge of social engineering tools and techniques
K0825 Knowledge of threat vector characteristics
K0994 Knowledge of denial and deception tools and techniques
K0684 Knowledge of cybersecurity threat characteristics
ISC2 CC
2.3 Understand security awareness
Cisco CCST Cybersecurity
1.2 Explain common threats and vulnerabilities
NIST 800-53
AT-2 Literacy Training and Awareness
SI-8 Spam Protection
NIST CSF
PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.

Key terms

Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Spear Phishing
A targeted phishing attack directed at a specific individual or organization using personalized information.
Whaling
A type of spear phishing attack that targets high-level executives or senior leadership within an organization, such as CEOs or C-suite members.
Smishing
A social engineering attack delivered via SMS text messages that tricks recipients into clicking malicious links, calling fraudulent numbers, or revealing sensitive information such as account credentials or financial data.
Vishing
A voice-based social engineering attack in which an attacker uses phone calls or voice messages to manipulate targets into revealing sensitive information or taking a harmful action such as transferring funds or resetting credentials.
Business Email Compromise
BEC
An attack where a threat actor impersonates a trusted person within an organization via email to deceive employees, often by spoofing or compromising a legitimate email address.
Tailgating
A physical security breach where an unauthorized person follows an authorized individual through a secured entry point without presenting credentials.
Shoulder Surfing
An attack in which an adversary physically observes a victim entering credentials or access information by looking over their shoulder or from close proximity.
Baiting
A social engineering technique that uses an enticing offer or lure to trick a victim into taking an action that compromises their security.
Dumpster Diving
A physical reconnaissance technique where an attacker searches through an organization's discarded trash to find sensitive information that was not properly destroyed.
Watering Hole Attack
An attack where an adversary compromises a third-party website frequently visited by members of a target organization in order to infect those users and gain indirect access to the organization.
Impersonation
A social engineering tactic in which an adversary poses as a trusted individual or authority figure to gain a victim's confidence and compliance.
Quid Pro Quo
A social engineering attack technique involving an overt exchange of something for something, such as offering a benefit in return for access, credentials, or sensitive information.
Blackmail
An overt social engineering attack in which an adversary threatens to release damaging information about a victim unless the victim complies with demands such as payment, access credentials, or sensitive data.
Pretexting
A social engineering technique in which an attacker fabricates a convincing scenario — such as impersonating IT support, a vendor, or an authority figure — to manipulate a target into performing an action or disclosing sensitive information.
Typosquatting
A form of impersonation that registers misspelled or look-alike domain names to deceive users into visiting fraudulent websites.
Misinformation
False information that is spread unintentionally, where the person sharing it believes it to be true.
Disinformation
False information that is deliberately created and spread with the intent to deceive or mislead others.
Deep Fake
A form of disinformation that uses audio or video media to falsely portray a real person saying or doing something they never said or did.

Topics

Social Engineering Phishing Impersonation Physical Security Disinformation Security Awareness Cybersecurity

Transcript

No one really wants to be controlled or manipulated, but there are some threat agents out there that become masters at it. We call that social engineering. They're able to social engineer, or trick, people into getting what they want.

We'll start out by defining what social engineering is, then we're going to get into some methods of contact that a threat agent will use, to include phishing, in person, and no contact. Then we're going to get into some tactics that they'll use, and then we'll wrap things up by talking about false information.

What social engineering is

Your brain is really quite amazing. Have you noticed there's some activities that you can do without ever thinking about it, that you've done them enough that your brain has logged it as a routine and you don't have to consciously focus on it? A sort of autopilot that your brain has. Well, that resides as a function of your brain so you don't have to think about every single activity you do, and some of those functions you're actually born with and your brain just naturally does. But the problem is that there are some people out there that know how to leverage these functions for their own gain.

That's what social engineering is. Social engineering is when somebody manipulates or controls somebody else using these built-in functions, or using some form of manipulation, for their own purpose, for getting some sort of information from them, or other fraudulent purposes.

Methods of contact

A threat agent is going to start out by making a connection with somebody. Perhaps it's through messaging like email, maybe it's that they've given them a phone call, perhaps it's in person, or there are even methods where they don't even have to reach out to the person and they can actually leverage the person for their own gains.

Phishing

One of the ways that a threat agent will do this is through the use of phishing. Phishing is when a threat agent sends an email or other type of message with the intention of getting some sort of information out of you. Perhaps it's maybe like user credentials or some other sensitive piece of information.

Phishing can actually go by many different names depending on who's being targeted, how they're being targeted, and what kind of information is trying to be extracted. An example of this is spear phishing. Spear phishing is a targeted attack against an individual or an organization. Whaling is a type of spear phishing when it targets somebody big in the company, like a CEO, somebody that's higher up in the ranks.

If phishing is happening through email we call that phishing; if it's happening through text messages we call it smishing; if it's happening over a phone call we call it vishing; or there's also instant messaging, so there is a threat through instant messaging as well. And a term you might see out there is message-based, which just means it's happening through text, whether it's phishing, smishing, or instant messaging.

If a threat agent is sending a phishing email to somebody at a company pretending to be somebody else at the company, we call that a business email compromise, or BEC. As already mentioned, if there's phishing happening through text messages we call that smishing, and I wanted to point out the reason why there's an S at the beginning: because texting uses a protocol called short message service, so SMS. That's why smishing.

In-person tactics

Phishing is not the only social engineering technique out there, though. For instance, you've got several in-person tactics that they'll use as well. A couple of examples of in-person would be tailgating and shoulder surfing.

Shoulder surfing is when somebody's looking over your shoulder to gather information. Perhaps it's when you're typing in your credentials and they see what your password is. So that's an example of shoulder surfing.

Tailgating is when somebody walks in behind you, like into a building or a closed-off area. A good example of this: I worked on the second floor of a building one time, and there was somebody, one of the employees, who was in the elevator with somebody else. When the employee got off, they turned the corner, and as the doors were shutting the other person stuck their hand out, the doors opened back up, and now he had access to the second floor and stole some equipment. So that's an example of tailgating.

No-contact methods

There are no-contact methods of social engineering as well. Baiting is an example of that. Baiting happens when you entice somebody to take some sort of bait. A good example of this is, let's say I want to trick people into installing a virus on their computer. I could put a virus on a thumb drive, put it around the office, and somebody would come along and say, oh, I wonder what that's for, or who that's for, what am I going to do with this? Well, I'll plug it into my machine to see what's on it, to see if I can give it to the proper person or throw it away. They plug it into their machine and then the virus gets installed on that machine.

Another example is dumpster diving. There are a lot of threat agents that will go through trash, go through the dumpster, go through the recycle bin to see if they can find sensitive information. It's a great source to get the initial information to leverage a network and get into a network.

There's also the watering hole. If I wanted to target a specific business, what I could do is see where that business went and browsed on the web, what pages they would go to, what sites they would go to, and then whatever site they would go to I would go and infect that site, hoping that somebody from that company would then go to that site, get the virus, and then I would have access to inside that network.

Other tactics

There are other tactics that threat agents will use as well. One of them is impersonation. You automatically trust certain people, certain people that you've already interacted with. Maybe it's a person of authority, maybe it's some sort of department that you trust like the IT department, and so you already have this trust built up. Well, somebody might impersonate one of those people to leverage that position to get you to do something. That's impersonation.

Quid pro quo is something for something. The idea is, I'll give you this if you give me that. I'll give you some money if you give me some information.

Then there's blackmail. That's, I have a piece of information that's against you, I'm going to release it unless you tell me some sort of information that I'm trying to gather. So that would be blackmail.

And then a lot of what they try to do is evoke some sort of emotion, like maybe it's curiosity, or maybe they're trying to create some sort of fear, or create some sort of urgency for you to do something quickly. So they'll try to evoke some sort of emotion to get you to react and fall for their social engineering tactics.

Types of impersonation

There are several different types of impersonation. We already mentioned the business email compromise. There's brand impersonation. That's where they pretend to be somebody from a name brand or a brand that you know, so they're just imitating some sort of brand that's out there.

There's also this thing called typo squatting. Typo squatting is the idea that they see some big website out there and they go and buy a domain that's very similar but just maybe has something that would be a common typo in it, and then you would type in that URL and be taken to the wrong site. I know somebody close to me that actually fell for one of those sites. They thought they were going to a Microsoft site but ended up going to a different site. So that would be an example of typo squatting.

Pretexting is when a threat agent will use some sort of fabricated story to extract information or get what they want out of you. The idea behind pretexting is they're probably going to try to evoke some sort of emotion out of you, or something that's compelling from their story, to get you to act and do what they want you to do.

False information

Then there's a lot of false information out there on the internet. Some of it's just misinformation, which means that it's wrong information but whoever created the information didn't intend it to be wrong, they were just inaccurate in the way they reported things.

Then there's disinformation. Disinformation is where somebody has actively put out false information on purpose.

And then deep fake is when there is some sort of voice or video alteration so it looks like one person, maybe a famous person, is saying something that they never said. They're using some voice modulation and some software to be able to trick other people into thinking that this person said stuff or did stuff that they didn't really do.

Social engineering is a huge problem out there, and there are companies out there that have mastered this. That's right, companies. There are businesses that are conducting cyber crime that are scamming people out of their life savings. There are millions of people that get hit every single year with this. It's a huge problem, but we're overcoming it because we're educating people, and so that's really what we want to do: educate our users on what are the tactics that a threat agent would use out there to scam them out of money or to take something away from the business.

So we talked about methods of contact, whether it's phishing, in person, or those no-contact methods; we talked about some of the tactics that they would use; and then what false information is out there.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →