Skip to content

Latest commit

 

History

History
82 lines (62 loc) · 2.84 KB

File metadata and controls

82 lines (62 loc) · 2.84 KB

Social Engineering

Objectives

  • 2.2 - Explain common threat vectors and attack surfaces
  • Understand common social engineering methods
  • Identify signs of manipulation, impersonation, and phishing

Table of Contents

  1. Social Engineering
  2. Phishing
  3. Common Social Engineering Techniques
  4. Impersonation
  5. Physical Social Engineering
  6. Prevention and Awareness
  7. Key Takeaways

Social Engineering

  • Social Engineering: Manipulating people into giving access, information, money, or performing an action.
  • Social engineering targets human trust, urgency, fear, curiosity, or authority.

Examples:

  • Fake IT support call asking for a password
  • Email pretending to be a bank
  • Text message with malicious link
  • Attacker tailgating into a building

Phishing

  • Phishing: Using email or messages to trick users into revealing information or clicking malicious links.

Types of phishing:

  • Spear Phishing: Targeted phishing against a specific person or group.
  • Whaling: Phishing targeting executives or senior leaders.
  • Vishing: Voice phishing over phone calls.
  • Smishing: Phishing through SMS text messages.
  • Business Email Compromise: Attacker impersonates a trusted business contact or executive.

Common Social Engineering Techniques

  • Pretexting: Creating a fake story to gain trust.
  • Baiting: Offering something tempting, such as a USB drive.
  • Quid Pro Quo: Offering a service in exchange for information.
  • Urgency: Pressuring the victim to act quickly.
  • Authority: Pretending to be someone with power.
  • Familiarity: Pretending to know the victim or organization.

Impersonation

  • Impersonation: Pretending to be another person or trusted organization.

Examples:

  • Fake help desk employee
  • Fake vendor
  • Fake manager
  • Fake delivery person
  • Fake law enforcement or government official

Physical Social Engineering

  • Tailgating: Following an authorized person into a secure area.
  • Piggybacking: Entering with permission from an authorized person, often by exploiting politeness.
  • Shoulder Surfing: Watching someone enter sensitive information.
  • Dumpster Diving: Searching trash for sensitive information.
  • USB Baiting: Leaving infected removable media for someone to use.

Prevention and Awareness

Good practices:

  • Verify unexpected requests
  • Report suspicious emails
  • Do not share passwords or MFA codes
  • Inspect links and sender addresses
  • Lock screens
  • Challenge unknown visitors according to policy
  • Dispose of sensitive documents securely

Key Takeaways

  • Social engineering attacks people, not only technology.
  • Awareness, verification, and reporting reduce social engineering risk.