click below
click below
Normal Size Small Size show me how
Social Engineering
Explain common threat vectors and attack surfaces, security awareness practice
| Question | Answer |
|---|---|
| social engineering | Manipulative strategy that exploits human psychology to gain unauthorized access to systems, data, or physical spaces. authority, urgency, social proof, scarcity, likability, fear |
| likability | Associated with being nice, friendly, and socially accepted by others |
| fear | feeling afraid of someone or something. feat and authority. |
| impersonation | an attack where an adversary assumes the identity of another person to gain unauthorized access to resources or steal sensitive data. unauthorized access, disruption of services, complete system takeover |
| brand impersonation | an attacker pretends to represent a legitimate company or brand |
| typosquatting | form of cyber attack where an attacker registers a domain name that is similar to a popular website but contains some kind of common typographical errors |
| watering hole attacks | targeted form of cyber attack where attackers compromise a specific website or service that their target is known to use |
| Pretexting | |
| Phishing attacks | vishing, smishing, whaling, spear phishing, business email compromise |
| phishing | Fraudulent attack using deceptive emails from trusted sources to trick individuals into this closing personal information like passwords and credit card numbers |
| spear phishing | Used by cyber criminals, who are more tightly focused on a specific group of individuals or organizations |
| whaling | Form of spear fishing that targets high-profile individuals, like CEOs or CFO's |
| business email compromise (BEC) | Advanced phishing attack that leverages internal email accounts within a company to manipulate employees into carrying out malicious actions for the attacker |
| Vishing (voice phishing) | Phone-based attack in which the attacker diseases victims into divulging personal or financial information |
| smishing (SMS Phishing) | attack that uses text messages to deceive individuals into sharing their personal information |
| anti-phishing campaign | vital tool for educating individuals about phishing risks and how to recognize potential phishing attempts in user security awareness training |
| common characteristics of phishing email | generic greeting, spelling and grammar mistakes, spoofed email addresses |
| urgency | phishing email induce urgency by pushing recipients to take immediate action |
| unusual requests | approach emails requesting sensitive information with high suspicion and caution |
| mismatched URLs | in HTML-based emails, the visible text is the display text, while the underlying URL of a web link can be manipulated |
| phish insight | |
| Fraud | wrong or criminal deception intended to result in financial or personal gain |
| identity fraud | the use by one person of another person's personal information, without authorization, to commit a crime or to deceive or defraud that other person or a third person |
| identity theft | attacker tries to fully assume the identity of their victim |
| scam | fraudulent or deceptive act or operation |
| invoice scam | a person is tricked into paying for a fake invoice for a service or product that they did not order |
| misinformation | inaccurate information shared unintentionally |
| disinformation | intentional spread of false information to deceive or mislead |
| common social engineering tatic | diversion theft, hoaxes, shoulder surfing, dumpster diving, eavesdropping, baiting, piggybacking or tailgating |
| diversion theft | manipulating a situation or creating a distraction to steal valuable items or information |