Dark Mode

Settings

Capec-416 Detail

Manipulate Human Behavior

Meta Social Engineering Likelihood: Medium Typical Severity: Medium

Children: 407 417 425 426 427

Description

An adversary exploits inherent human psychological predisposition to influence a targeted individual or group to solicit information or manipulate the target into performing an action that serves the adversary's interests. Many interpersonal social engineering techniques do not involve outright deception, although they can; many are subtle ways of manipulating a target to remove barriers, make the target feel comfortable, and produce an exchange in which the target is either more likely to share information directly, or let key information slip out unintentionally. A skilled adversary uses these techniques when appropriate to produce the desired outcome. Manipulation techniques vary from the overt, such as pretending to be a supervisor to a help desk, to the subtle, such as making the target feel comfortable with the adversary's speech and thought patterns.

Not present

External ID Source Link Description
CAPEC-416 capec https://capec.mitre.org/data/definitions/416.html
REF-348 reference_from_CAPEC http://www.social-engineer.org The Official Social Engineering Portal, Social-Engineer.org, Tick Tock Computers, LLC

Not present

  1. The adversary must have the means and knowledge of how to communicate with the target in some manner.

Not present

Not present

Integrity Availability Confidentiality
Other (Attack patterns that manipulate human behavior can result in a wide variety of consequences and potentially affect the confidentiality, availability, and/or integrity of an application or system.) Other (Attack patterns that manipulate human behavior can result in a wide variety of consequences and potentially affect the confidentiality, availability, and/or integrity of an application or system.) Other (Attack patterns that manipulate human behavior can result in a wide variety of consequences and potentially affect the confidentiality, availability, and/or integrity of an application or system.)

Not present