Social Engineering Flashcards
Pretexting
Pretexting is a method of inventing a scenario to convince victims to divulge information they should not divulge.
Insider Threat
A person who works with your organisation but has ulterior motives. -E.g.: Employees who steal information are insider threats.
Phishing
An attempt to fraudulently obtain information from a user (usually by email).
Spear Phishing
An attempt to fraudulently obtain information from a user (usually by email). Spear Phishing targets a specific individual.
Whaling
A form of spear phishing that directly targets the CEO, CFO, CIO, CSO or other high-value target in an organisation.
Smishing
Phising conducted over SMS.
Vishing
Phising that occurs over voice calls.
Pharming
Phising attempt to trick a user to access a different website.
What are the 6 Motivation Factors in Social Engineering
- Authority
- Urgency
- Social Proof
- Scarcity
- Likeability
- Fear
Diversion Theft
When a thief trys to divert a shipment to another location.
Hoax
Deceiving people into believing something is false when it’s true (or vice versa)
Shoulder Surfacing
Someone watches your activities in person to obtain authentication information.
Eavesdropping
When a person uses direct observation to “listen” in to a conversation
Dumpster Diving
When a person scavenges for information in garbage containers.
Baiting
When a malicious individual leaves malware-infected removable media such as a USB drive or optical disk in plain view for a victim.