Social engineering overview
Social engineering, by definition, is the psychological manipulation of a person to get useful and sensitive information from them, which can later be used to compromise a system. In other words, criminals use social engineering to gain confidential information from people, by taking advantage of human behavior.
Social Engineering Engagement Framework
The Social Engineering Engagement Framework (SEEF) is a framework developed by Dominique C. Brack and Alexander Bahmram. It summarizes years of experience in information security and defending against social engineering. The stakeholders of the framework are organizations, governments, and individuals (personals). Social engineering engagement management goes through three steps:
- Pre-engagement process: Preparing the social engineering operation
- During-engagement process: The engagement occurs
- Post-engagement process: Delivering a report
There are many social engineering techniques used by criminals:
- Baiting: Convincing...