- 2.2 - Explain common threat vectors and attack surfaces
- Understand common social engineering methods
- Identify signs of manipulation, impersonation, and phishing
- Social Engineering
- Phishing
- Common Social Engineering Techniques
- Impersonation
- Physical Social Engineering
- Prevention and Awareness
- Key Takeaways
- Social Engineering: Manipulating people into giving access, information, money, or performing an action.
- Social engineering targets human trust, urgency, fear, curiosity, or authority.
Examples:
- Fake IT support call asking for a password
- Email pretending to be a bank
- Text message with malicious link
- Attacker tailgating into a building
- Phishing: Using email or messages to trick users into revealing information or clicking malicious links.
Types of phishing:
- Spear Phishing: Targeted phishing against a specific person or group.
- Whaling: Phishing targeting executives or senior leaders.
- Vishing: Voice phishing over phone calls.
- Smishing: Phishing through SMS text messages.
- Business Email Compromise: Attacker impersonates a trusted business contact or executive.
- Pretexting: Creating a fake story to gain trust.
- Baiting: Offering something tempting, such as a USB drive.
- Quid Pro Quo: Offering a service in exchange for information.
- Urgency: Pressuring the victim to act quickly.
- Authority: Pretending to be someone with power.
- Familiarity: Pretending to know the victim or organization.
- Impersonation: Pretending to be another person or trusted organization.
Examples:
- Fake help desk employee
- Fake vendor
- Fake manager
- Fake delivery person
- Fake law enforcement or government official
- Tailgating: Following an authorized person into a secure area.
- Piggybacking: Entering with permission from an authorized person, often by exploiting politeness.
- Shoulder Surfing: Watching someone enter sensitive information.
- Dumpster Diving: Searching trash for sensitive information.
- USB Baiting: Leaving infected removable media for someone to use.
Good practices:
- Verify unexpected requests
- Report suspicious emails
- Do not share passwords or MFA codes
- Inspect links and sender addresses
- Lock screens
- Challenge unknown visitors according to policy
- Dispose of sensitive documents securely
- Social engineering attacks people, not only technology.
- Awareness, verification, and reporting reduce social engineering risk.