People are the most targeted part of any system. Social engineering manipulates human trust to bypass technical controls.
Social Engineering
Attacking the human, not the machine.
Tap or hover a part to learn more.
Mass deceptive email.
Fraudulent emails/messages sent widely to trick people into revealing credentials or running malware. Spear phishing targets an individual; whaling targets executives.
Check your understanding
1. What distinguishes spear phishing from phishing?
2. Which single control most reduces the impact of stolen credentials?
The techniques
- Phishing (mass), spear phishing (targeted) and whaling (executives) — deceptive emails/messages.
- Pretexting (a fabricated scenario), baiting (a lure like a USB drive) and vishing (voice/phone).
- Attacks exploit urgency, authority and fear — recognising these cues is the best defence.
Many intrusions start here, then follow the cyber kill chain:
The Cyber Kill Chain
The seven stages of an intrusion — and where you can break it.
Tap or hover a part to learn more.
Research the target.
The attacker gathers information — emails, technologies, employees, exposed services — via OSINT and scanning. Defence: minimise public exposure, monitor for scanning.
Check your understanding
1. Blocking a malicious email attachment disrupts which stage?
2. Egress filtering and DNS monitoring most directly disrupt which stage?
Defences: awareness training, MFA (so stolen passwords aren't enough), email filtering and a strong reporting culture. This connects to IAM and Security+.
