social engineering

term

securityhacking

Manipulating people, rather than technology, to gain access or information.

It is the technique that no patch closes, because the vulnerability is a human decision rather than a line of code. In threat-intel terms it is the classic attack vector and one of the most common techniques in any actor's TTPs: pretexting (inventing a believable role), phishing and its targeted cousins, baiting, and tailgating are all procedures under it. The defense is correspondingly human, awareness training, verification habits, and processes that do not depend on any one person choosing correctly under pressure, which is why security-is-a-process rather than a product.

Also known as: social-engineering, pretexting

All glossary entries