The social engineering life cycle
The social engineering life cycle is a systematic approach that describes the stages involved in a social engineering attack. It provides a comprehensive framework for understanding and mitigating the tactics employed by attackers who manipulate human behavior to gain unauthorized access, extract information, or exploit individuals or organizations for personal gain.
The social engineering life cycle involves several stages, as listed here and also demonstrated in Figure 9.1:
- Reconnaissance: Gathering information about the target
- Target selection: Carefully choosing individuals or groups to exploit
- Pretext development: Creating a believable and trustworthy persona
- Engagement: The attacker works on building a relationship and gaining the target’s trust
- Exploitation or elicitation:
- Exploitation: Manipulating the victim to perform a plurality of actions desired by the attacker
- Elicitation: The discrete gathering of information...