<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=HDogan</id>
	<title>Elvis Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=HDogan"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php/Special:Contributions/HDogan"/>
	<updated>2026-09-10T06:23:14Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering&amp;diff=17704</id>
		<title>Social Engineering</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering&amp;diff=17704"/>
		<updated>2024-12-18T21:43:16Z</updated>

		<summary type="html">&lt;p&gt;HDogan: added OSINT comparison to SOCMINT&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
This documentation contains information of what Social Engineering is, how it is getting used and how to prevent or mitigate some of those attacks. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
In order to execute a social engineering attack you need to understand the basis of social engineering described below. There are also tools to understand and execute these attacks on a practical level. There are many pre-defined attacks which show how easy it is to perform such attacks. You can read more about that in [[Social Engineering Toolkit]]&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
Social engineering is a technique that involves using human interaction to gather information or influence a person to act in a certain way. It can involve spying on someone&#039;s personal life in order to achieve a specific goal, such as manipulating elections, obtaining information, or stealing money. The goal of social engineering is to guide a person towards a particular outcome, often by manipulating their thoughts or actions.&lt;br /&gt;
&lt;br /&gt;
=== Phases ===&lt;br /&gt;
In Social Engineering there are a few necessary steps to complete an attack and gain the information you are after. Kevin Mitnick has divided the process into 4 steps with are mainly: &#039;&#039;&#039;Information Gathering&#039;&#039;&#039;, &#039;&#039;&#039;Hook Relationship&#039;&#039;&#039;, &#039;&#039;&#039;Exploitation and Execution&#039;&#039;&#039; and &#039;&#039;&#039;End without leaving a trace&#039;&#039;&#039;. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:01_mitnicks_attack_circle.png|thumb|none|300px|Source: Mouton, Social&lt;br /&gt;
engineering attack framework]]&lt;br /&gt;
&lt;br /&gt;
==== Information Gathering ====&lt;br /&gt;
Information gathering involves collecting as much information as possible about a potential victim in order to identify possible attack vectors. This may include identifying personal details, interests, or vulnerabilities that can be exploited. This information can be gathered through various means, such as social media, public records, or by directly interacting with the victim.&lt;br /&gt;
&lt;br /&gt;
==== Hook Relationship ====&lt;br /&gt;
In order to build a &amp;quot;hook relationship&amp;quot; with the victim, the attacker will often try to present themselves as trustworthy in order to gain the victim&#039;s confidence and cooperation. This may involve pretending to be someone the victim knows, such as a colleague or friend, or posing as an authority figure in order to gain the victim&#039;s trust.&lt;br /&gt;
&lt;br /&gt;
==== Exploitation and Execution ====&lt;br /&gt;
The exploitation and execution phase involves manipulating the victim in order to persuade them to take certain actions or disclose information that the attacker is seeking. This may involve using psychological manipulation or other tactics to influence the victim&#039;s behavior. The attacker may use a variety of tactics, such as flattery, fear, or pressure, in order to persuade the victim to comply with their requests.&lt;br /&gt;
&lt;br /&gt;
==== End without leaving a trace ====&lt;br /&gt;
Once the attacker has achieved their goal, they will often try to cover their tracks and end the attack without leaving any evidence behind. This may involve deleting any records of the attack or disguising their involvement in order to avoid detection. In order to avoid being caught, the attacker may also take steps to destroy any evidence of the attack, such as wiping clean any devices or servers that were used in the attack.&lt;br /&gt;
&lt;br /&gt;
== Attacks ==&lt;br /&gt;
This part contains the most common and basic attacks used today. Nearly everyone should have seen such an attack in practice, either by e.g. receiving a pishing email or getting a warning that pishing emails are circulating with an example. If you have not, just check you Spam or Junk folder in you mailbox you will probably find one in there. &lt;br /&gt;
&lt;br /&gt;
=== Phishing ===&lt;br /&gt;
Phishing Attacks are one of the most common attacks. They are pretty simple and based on for example a real E-Mail that is being copied and used to get user data with links redirecting to a wrong website. This website looks than pretty similar to the original and if you do not look close enough you sometimes do not even realize that it is fake. The goal of this attack is in general to steal password from accounts and then try to steal money in any way possible. There are different types of phishing:&lt;br /&gt;
* Spear phishing: Are attacks on specific people or groups, for this you need to know about the person/company beforehand. Since it is very personal, it is also often very successful in contrast to other Social Engineering approaches. &lt;br /&gt;
* Whaling: Similar to spear-phishing, except that high-profile individuals are targeted.&lt;br /&gt;
* Vishing: These phishing attacks are carried out over the phone.&lt;br /&gt;
* Smishing: The attacks are carried out over text messages.&lt;br /&gt;
* Interactive voice-response phishing: Interactive voice response system is used. &lt;br /&gt;
* Business email compromise phishing: : It is similar to whaling, the attacker wants access to business mails and then sends legitimate looking business mails to get ”normal” employees to click some link or something.&lt;br /&gt;
* Scareware: Scareware exploits the tendency to act rashly when someone feels threatened. By staging a threat and offering a solution to unsuspecting victims. This can be done in the form of emails, pop-ups, or SMS that lead to malware or fake websites collecting sensitive information.&lt;br /&gt;
&lt;br /&gt;
=== Pharming ===&lt;br /&gt;
This approach is similar to the goal of Phishing but is done quite differently. The task is to lure the victim on to a similar looking website e.g. bank, insurance, ... but it is not done with sending you fake links but rather hacking the DNS Server and redirecting you instantly without you even knowing. The domain of the website is completely legit. If the website is done very well your data is being saved and afterwards you are getting redirect onto your real bank account on the real website without you ever knowing.&lt;br /&gt;
&lt;br /&gt;
=== Pretexting ===&lt;br /&gt;
This attack is similar to Phishing but the goal of this attack is to make you believe that you are being contacted by someone close or authoritative. These messages could lead you to send personal information to the attacker. If done right and other conversation were being captured before and the phone number or E-Mail got spoofed you sometimes would not even realize that it is a fake.  &lt;br /&gt;
&lt;br /&gt;
=== Tailgaiting ===&lt;br /&gt;
Tailgaiting is an attack that requires physical access to a secure building. This is achieved by following people through doors or opening you the door by thinking you lost your access card. When done right you get access to a certain level where you could install malware on others PCs. Another ways would be to ask someone for their phone to make a call and then install malware when they are not watching. &lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
[[Ransomware]] is a type of malicious software that encrypts a victim&#039;s personal data and demands a ransom from the victim to restore access to the data. These attacks have been increasing in popularity and are becoming more and more difficult to stop. Some well-known examples of [[Ransomware]] include WannaCry (2017) and Locky (2016). One of the dangers of ransomware is that even if the victim pays the ransom, there is no guarantee that they will actually get their data back.&lt;br /&gt;
&lt;br /&gt;
=== Shoulder Surfing ===&lt;br /&gt;
Secretly observing confidential information, such as passwords or PINs, by watching individuals operate devices.&lt;br /&gt;
&lt;br /&gt;
=== Dumpster Diving ===&lt;br /&gt;
This technique is as the name already tells used to get information out of the trash of others. A letter with sensitive infomation e.g. bank, creditcard or hard drives can contain a lot of data that can be used against you if not disposed properly. A good tip would be throw away pieces of information in different trash cans for example when on the way to work. &lt;br /&gt;
&lt;br /&gt;
=== Pop-Up Window ===&lt;br /&gt;
Pop-Up Windows are often used to scare non enlightened people to get tricked by a simple window mostly in a browser. This scam either wants you to redeem the jackpot you just won or tell you that you computer is infected and you should call the attacker to infect you with malware. Most of the times these windows are hard to close and are pretty loud to intimiated the victim. &lt;br /&gt;
&lt;br /&gt;
=== Baiting/USB Drop ===&lt;br /&gt;
Another bait attack involves the use of dropped USB drives. The attacker will leave a USB drive in a public place, such as a parking lot or lobby, with a label or message that suggests it contains something interesting or valuable. When someone picks up the drive and plugs it into their computer, they may be exposing their system to malware or ransomware.&lt;br /&gt;
&lt;br /&gt;
=== Eavesdropping ===&lt;br /&gt;
Eavesdropping is the act of secretly listening to the private conversations of others without their knowledge. It can be done in a variety of ways, such as through the use of hidden microphones, wiretapping, or simply by listening in on a conversation that is happening nearby. Eavesdropping can be a serious invasion of privacy and is often illegal, particularly if it is done for malicious purposes such as to gather personal or sensitive information. In the digital age, eavesdropping can also be done remotely through the use of malware or other cyber threats that allow an attacker to access and monitor the conversations of their victims.&lt;br /&gt;
&lt;br /&gt;
=== Reverse Social Engineering ===&lt;br /&gt;
One common technique used in reverse social engineering attacks is for the attacker to pretend to be a good guy or authority figure in order to gain the victim&#039;s trust. For example, the attacker might pretend to be a technical support representative and ask the victim for their login credentials in order to &amp;quot;fix&amp;quot; a problem with their computer. Or, the attacker might pose as a law enforcement officer and request that the victim provide sensitive information in order to &amp;quot;assist with an investigation.&amp;quot; In these cases, the victim may feel pressure to comply with the request, believing that they are helping to solve a problem or protect against a threat.&lt;br /&gt;
&lt;br /&gt;
=== Impersonating ===&lt;br /&gt;
Impersonating is the act of pretending to be someone else, either in person or online, in order to deceive others. This can be done for a variety of reasons, such as to gain access to sensitive information or resources, to evade detection or consequences, or to commit a crime. In the digital world, impersonation is often done through the use of fake profiles or websites that mimic legitimate ones in order to trick people into divulging personal information or money. In person, impersonation can be more complex and may involve the use of props, costumes, and other means of disguising one&#039;s true identity.&lt;br /&gt;
&lt;br /&gt;
===Psychological Attacks===&lt;br /&gt;
;Reciprocity:&lt;br /&gt;
: Offering favors to create a sense of obligation to reciprocate.&lt;br /&gt;
;Obligation:&lt;br /&gt;
: Evoking a feeling of duty or cooperation to comply with requests.&lt;br /&gt;
;Free Information:&lt;br /&gt;
: Extracting seemingly harmless information through casual conversation.&lt;br /&gt;
;Authority:&lt;br /&gt;
: Exploiting the perceived authority of figures to compel compliance.&lt;br /&gt;
;Desire to Help:&lt;br /&gt;
: Faking distress to evoke sympathy and manipulate individuals into offering assistance.&lt;br /&gt;
&lt;br /&gt;
== Prevention ==&lt;br /&gt;
As attacks increase and improve it is very hard to defend against those if you do not know how they work and what they do. To prevent or mitigate such attacks you need 3 important informations.&lt;br /&gt;
&lt;br /&gt;
=== Clarify Attacks ===&lt;br /&gt;
The first part help you to understand how and what these attacks are trying to do. If you know what a Pop-Up Window is and you now know that these messages are spam and trying to lure you into a trap you will not fall for it anymore. The best way is know examples of the most common attacks to obtainer awareness againts those social engineering attacks. Since these attacks improve over time you should be up-to-date and you should ask people you trust for help if you do not know how to proceed. &lt;br /&gt;
&lt;br /&gt;
=== Education and Training ===&lt;br /&gt;
To ensure the safety and security of your employees, it is important to provide regular training sessions to keep them informed on best practices and current threats. They should be cautious when receiving phone calls or emails from unknown sources, and verify the identity of the sender before disclosing any confidential information. They should also be wary of suspicious links or attachments, and avoid downloading unknown files. To further protect against potential threats, it is advisable to implement multifactor authentication and regularly update antivirus and antimalware programs. Additionally, it is important to carefully examine the references of any offers or requests for sensitive data.&lt;br /&gt;
&lt;br /&gt;
=== Set Security Standards ===&lt;br /&gt;
You should start setting yourself a certain security standard. This goes from checking certain programs or files you do not know to check links before you click them. If you have a new contact in your mailbox you should double check the sender to know for you sure you are not dealing with a scam artist. You should also never share you PC with other or plug-in strange devices you do not know. An increased awareness about pishing emails from providers would be appreciative to check bills if they are not infected with malware. &lt;br /&gt;
&lt;br /&gt;
=== Implement Security Tools ===&lt;br /&gt;
Since detecting malware is getting more difficult everytime you should start using certain tools to help you secure you environment. To protect against more advanced attacks, it is recommended that companies use Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS), which can detect and respond to attacks in real-time. In addition to a firewall, companies can also use Virtual Private Networks (VPNs) to secure their internet connection. Anti-phishing tools can help to block and blacklist phishing websites, and companies can also consider using honeypot emails as a way to lure and track attackers. It is also important to implement physical security measures, such as properly securing hardware and following guidelines for physical access to facilities. These tools will help you to detect unwanted programs and helps you safeing your data externally. &lt;br /&gt;
&lt;br /&gt;
* Anti Virus Software: [https://www.malwarebytes.com/ Malwarebytes]&lt;br /&gt;
* Browser Anti-Ad/Spam Plugin: [https://ublockorigin.com/ uBlock Origin]&lt;br /&gt;
* Check E-Mail periodically: [https://haveibeenpwned.com/ HaveIBeenPwned]&lt;br /&gt;
* Safe File externally: [https://nextcloud.com/ Nextcloud]&lt;br /&gt;
* Check Programs: [https://www.virustotal.com/ Virustotal]&lt;br /&gt;
* Password Manager: [https://keepassxc.org/ KeepassXC]&lt;br /&gt;
&lt;br /&gt;
== Social Media Intelligence ==&lt;br /&gt;
&lt;br /&gt;
Social media intelligence (SOCMINT) is a process that involves gathering and analyzing data from social media platforms in order to inform business decisions. This type of intelligence can be used to track brand mentions and sentiment, monitor competitors, and identify emerging trends or opportunities for engagement.&lt;br /&gt;
&lt;br /&gt;
By collecting and analyzing social media data, companies can gain valuable insights into the perceptions and behaviors of their customers and target audience. This can inform marketing strategies, customer service efforts, and product development. For example, a company might use social media intelligence to identify common customer pain points and develop solutions to address them, or to identify influencers to partner with in order to promote their brand.&lt;br /&gt;
&lt;br /&gt;
OSINT (Open-Source Intelligence) on the contrary focuses on collecting information that is freely available from public sources, such as news articles, research papers and online databases.&lt;br /&gt;
&lt;br /&gt;
There are a number of tools and platforms available to help companies automate the process of gathering and analyzing social media data. These tools often include features such as keyword tracking, sentiment analysis, and competitor analysis. Examples would be Facebook Search Engine and Twitter Advanced Search. Some OSINT tools can also be used for social media. (Maltego, Sherlock, Social-Searcher,...)&lt;br /&gt;
&lt;br /&gt;
Overall, social media intelligence can be an important part of a company&#039;s market research and customer insights efforts, helping them to better understand and connect with their audience on social media. It can also be a useful way for companies to stay up-to-date on industry developments and emerging trends, and to identify opportunities for growth and innovation.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.sciencedirect.com/science/article/abs/pii/S2214212614001343?via%3Dihub&lt;br /&gt;
* https://link.springer.com/chapter/10.1007/978-3-642-22424-9_4&lt;br /&gt;
* https://www.mdpi.com/1999-5903/11/4/89&lt;br /&gt;
* https://www.researchgate.net/profile/Hugo-Barbosa/publication/315351300_SOCIAL_ENGINEERING_AND_CYBER_SECURITY/links/599c43430f7e9b892bafc0df/SOCIAL-ENGINEERING-AND-CYBER-SECURITY.pdf&lt;br /&gt;
* https://cybernews.com/cyber-war/influencing-anonymous-experiment/&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>HDogan</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering&amp;diff=17559</id>
		<title>Social Engineering</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering&amp;diff=17559"/>
		<updated>2024-12-18T17:41:56Z</updated>

		<summary type="html">&lt;p&gt;HDogan: Merged missing info from &amp;quot;Social Engineering &amp;amp; Phishing Platform&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
This documentation contains information of what Social Engineering is, how it is getting used and how to prevent or mitigate some of those attacks. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
In order to execute a social engineering attack you need to understand the basis of social engineering described below. There are also tools to understand and execute these attacks on a practical level. There are many pre-defined attacks which show how easy it is to perform such attacks. You can read more about that in [[Social Engineering Toolkit]]&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
Social engineering is a technique that involves using human interaction to gather information or influence a person to act in a certain way. It can involve spying on someone&#039;s personal life in order to achieve a specific goal, such as manipulating elections, obtaining information, or stealing money. The goal of social engineering is to guide a person towards a particular outcome, often by manipulating their thoughts or actions.&lt;br /&gt;
&lt;br /&gt;
=== Phases ===&lt;br /&gt;
In Social Engineering there are a few necessary steps to complete an attack and gain the information you are after. Kevin Mitnick has divided the process into 4 steps with are mainly: &#039;&#039;&#039;Information Gathering&#039;&#039;&#039;, &#039;&#039;&#039;Hook Relationship&#039;&#039;&#039;, &#039;&#039;&#039;Exploitation and Execution&#039;&#039;&#039; and &#039;&#039;&#039;End without leaving a trace&#039;&#039;&#039;. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:01_mitnicks_attack_circle.png|thumb|none|300px|Source: Mouton, Social&lt;br /&gt;
engineering attack framework]]&lt;br /&gt;
&lt;br /&gt;
==== Information Gathering ====&lt;br /&gt;
Information gathering involves collecting as much information as possible about a potential victim in order to identify possible attack vectors. This may include identifying personal details, interests, or vulnerabilities that can be exploited. This information can be gathered through various means, such as social media, public records, or by directly interacting with the victim.&lt;br /&gt;
&lt;br /&gt;
==== Hook Relationship ====&lt;br /&gt;
In order to build a &amp;quot;hook relationship&amp;quot; with the victim, the attacker will often try to present themselves as trustworthy in order to gain the victim&#039;s confidence and cooperation. This may involve pretending to be someone the victim knows, such as a colleague or friend, or posing as an authority figure in order to gain the victim&#039;s trust.&lt;br /&gt;
&lt;br /&gt;
==== Exploitation and Execution ====&lt;br /&gt;
The exploitation and execution phase involves manipulating the victim in order to persuade them to take certain actions or disclose information that the attacker is seeking. This may involve using psychological manipulation or other tactics to influence the victim&#039;s behavior. The attacker may use a variety of tactics, such as flattery, fear, or pressure, in order to persuade the victim to comply with their requests.&lt;br /&gt;
&lt;br /&gt;
==== End without leaving a trace ====&lt;br /&gt;
Once the attacker has achieved their goal, they will often try to cover their tracks and end the attack without leaving any evidence behind. This may involve deleting any records of the attack or disguising their involvement in order to avoid detection. In order to avoid being caught, the attacker may also take steps to destroy any evidence of the attack, such as wiping clean any devices or servers that were used in the attack.&lt;br /&gt;
&lt;br /&gt;
== Attacks ==&lt;br /&gt;
This part contains the most common and basic attacks used today. Nearly everyone should have seen such an attack in practice, either by e.g. receiving a pishing email or getting a warning that pishing emails are circulating with an example. If you have not, just check you Spam or Junk folder in you mailbox you will probably find one in there. &lt;br /&gt;
&lt;br /&gt;
=== Phishing ===&lt;br /&gt;
Phishing Attacks are one of the most common attacks. They are pretty simple and based on for example a real E-Mail that is being copied and used to get user data with links redirecting to a wrong website. This website looks than pretty similar to the original and if you do not look close enough you sometimes do not even realize that it is fake. The goal of this attack is in general to steal password from accounts and then try to steal money in any way possible. There are different types of phishing:&lt;br /&gt;
* Spear phishing: Are attacks on specific people or groups, for this you need to know about the person/company beforehand. Since it is very personal, it is also often very successful in contrast to other Social Engineering approaches. &lt;br /&gt;
* Whaling: Similar to spear-phishing, except that high-profile individuals are targeted.&lt;br /&gt;
* Vishing: These phishing attacks are carried out over the phone.&lt;br /&gt;
* Smishing: The attacks are carried out over text messages.&lt;br /&gt;
* Interactive voice-response phishing: Interactive voice response system is used. &lt;br /&gt;
* Business email compromise phishing: : It is similar to whaling, the attacker wants access to business mails and then sends legitimate looking business mails to get ”normal” employees to click some link or something.&lt;br /&gt;
* Scareware: Scareware exploits the tendency to act rashly when someone feels threatened. By staging a threat and offering a solution to unsuspecting victims. This can be done in the form of emails, pop-ups, or SMS that lead to malware or fake websites collecting sensitive information.&lt;br /&gt;
&lt;br /&gt;
=== Pharming ===&lt;br /&gt;
This approach is similar to the goal of Phishing but is done quite differently. The task is to lure the victim on to a similar looking website e.g. bank, insurance, ... but it is not done with sending you fake links but rather hacking the DNS Server and redirecting you instantly without you even knowing. The domain of the website is completely legit. If the website is done very well your data is being saved and afterwards you are getting redirect onto your real bank account on the real website without you ever knowing.&lt;br /&gt;
&lt;br /&gt;
=== Pretexting ===&lt;br /&gt;
This attack is similar to Phishing but the goal of this attack is to make you believe that you are being contacted by someone close or authoritative. These messages could lead you to send personal information to the attacker. If done right and other conversation were being captured before and the phone number or E-Mail got spoofed you sometimes would not even realize that it is a fake.  &lt;br /&gt;
&lt;br /&gt;
=== Tailgaiting ===&lt;br /&gt;
Tailgaiting is an attack that requires physical access to a secure building. This is achieved by following people through doors or opening you the door by thinking you lost your access card. When done right you get access to a certain level where you could install malware on others PCs. Another ways would be to ask someone for their phone to make a call and then install malware when they are not watching. &lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
[[Ransomware]] is a type of malicious software that encrypts a victim&#039;s personal data and demands a ransom from the victim to restore access to the data. These attacks have been increasing in popularity and are becoming more and more difficult to stop. Some well-known examples of [[Ransomware]] include WannaCry (2017) and Locky (2016). One of the dangers of ransomware is that even if the victim pays the ransom, there is no guarantee that they will actually get their data back.&lt;br /&gt;
&lt;br /&gt;
=== Shoulder Surfing ===&lt;br /&gt;
Secretly observing confidential information, such as passwords or PINs, by watching individuals operate devices.&lt;br /&gt;
&lt;br /&gt;
=== Dumpster Diving ===&lt;br /&gt;
This technique is as the name already tells used to get information out of the trash of others. A letter with sensitive infomation e.g. bank, creditcard or hard drives can contain a lot of data that can be used against you if not disposed properly. A good tip would be throw away pieces of information in different trash cans for example when on the way to work. &lt;br /&gt;
&lt;br /&gt;
=== Pop-Up Window ===&lt;br /&gt;
Pop-Up Windows are often used to scare non enlightened people to get tricked by a simple window mostly in a browser. This scam either wants you to redeem the jackpot you just won or tell you that you computer is infected and you should call the attacker to infect you with malware. Most of the times these windows are hard to close and are pretty loud to intimiated the victim. &lt;br /&gt;
&lt;br /&gt;
=== Baiting/USB Drop ===&lt;br /&gt;
Another bait attack involves the use of dropped USB drives. The attacker will leave a USB drive in a public place, such as a parking lot or lobby, with a label or message that suggests it contains something interesting or valuable. When someone picks up the drive and plugs it into their computer, they may be exposing their system to malware or ransomware.&lt;br /&gt;
&lt;br /&gt;
=== Eavesdropping ===&lt;br /&gt;
Eavesdropping is the act of secretly listening to the private conversations of others without their knowledge. It can be done in a variety of ways, such as through the use of hidden microphones, wiretapping, or simply by listening in on a conversation that is happening nearby. Eavesdropping can be a serious invasion of privacy and is often illegal, particularly if it is done for malicious purposes such as to gather personal or sensitive information. In the digital age, eavesdropping can also be done remotely through the use of malware or other cyber threats that allow an attacker to access and monitor the conversations of their victims.&lt;br /&gt;
&lt;br /&gt;
=== Reverse Social Engineering ===&lt;br /&gt;
One common technique used in reverse social engineering attacks is for the attacker to pretend to be a good guy or authority figure in order to gain the victim&#039;s trust. For example, the attacker might pretend to be a technical support representative and ask the victim for their login credentials in order to &amp;quot;fix&amp;quot; a problem with their computer. Or, the attacker might pose as a law enforcement officer and request that the victim provide sensitive information in order to &amp;quot;assist with an investigation.&amp;quot; In these cases, the victim may feel pressure to comply with the request, believing that they are helping to solve a problem or protect against a threat.&lt;br /&gt;
&lt;br /&gt;
=== Impersonating ===&lt;br /&gt;
Impersonating is the act of pretending to be someone else, either in person or online, in order to deceive others. This can be done for a variety of reasons, such as to gain access to sensitive information or resources, to evade detection or consequences, or to commit a crime. In the digital world, impersonation is often done through the use of fake profiles or websites that mimic legitimate ones in order to trick people into divulging personal information or money. In person, impersonation can be more complex and may involve the use of props, costumes, and other means of disguising one&#039;s true identity.&lt;br /&gt;
&lt;br /&gt;
===Psychological Attacks===&lt;br /&gt;
;Reciprocity:&lt;br /&gt;
: Offering favors to create a sense of obligation to reciprocate.&lt;br /&gt;
;Obligation:&lt;br /&gt;
: Evoking a feeling of duty or cooperation to comply with requests.&lt;br /&gt;
;Free Information:&lt;br /&gt;
: Extracting seemingly harmless information through casual conversation.&lt;br /&gt;
;Authority:&lt;br /&gt;
: Exploiting the perceived authority of figures to compel compliance.&lt;br /&gt;
;Desire to Help:&lt;br /&gt;
: Faking distress to evoke sympathy and manipulate individuals into offering assistance.&lt;br /&gt;
&lt;br /&gt;
== Prevention ==&lt;br /&gt;
As attacks increase and improve it is very hard to defend against those if you do not know how they work and what they do. To prevent or mitigate such attacks you need 3 important informations.&lt;br /&gt;
&lt;br /&gt;
=== Clarify Attacks ===&lt;br /&gt;
The first part help you to understand how and what these attacks are trying to do. If you know what a Pop-Up Window is and you now know that these messages are spam and trying to lure you into a trap you will not fall for it anymore. The best way is know examples of the most common attacks to obtainer awareness againts those social engineering attacks. Since these attacks improve over time you should be up-to-date and you should ask people you trust for help if you do not know how to proceed. &lt;br /&gt;
&lt;br /&gt;
=== Education and Training ===&lt;br /&gt;
To ensure the safety and security of your employees, it is important to provide regular training sessions to keep them informed on best practices and current threats. They should be cautious when receiving phone calls or emails from unknown sources, and verify the identity of the sender before disclosing any confidential information. They should also be wary of suspicious links or attachments, and avoid downloading unknown files. To further protect against potential threats, it is advisable to implement multifactor authentication and regularly update antivirus and antimalware programs. Additionally, it is important to carefully examine the references of any offers or requests for sensitive data.&lt;br /&gt;
&lt;br /&gt;
=== Set Security Standards ===&lt;br /&gt;
You should start setting yourself a certain security standard. This goes from checking certain programs or files you do not know to check links before you click them. If you have a new contact in your mailbox you should double check the sender to know for you sure you are not dealing with a scam artist. You should also never share you PC with other or plug-in strange devices you do not know. An increased awareness about pishing emails from providers would be appreciative to check bills if they are not infected with malware. &lt;br /&gt;
&lt;br /&gt;
=== Implement Security Tools ===&lt;br /&gt;
Since detecting malware is getting more difficult everytime you should start using certain tools to help you secure you environment. To protect against more advanced attacks, it is recommended that companies use Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS), which can detect and respond to attacks in real-time. In addition to a firewall, companies can also use Virtual Private Networks (VPNs) to secure their internet connection. Anti-phishing tools can help to block and blacklist phishing websites, and companies can also consider using honeypot emails as a way to lure and track attackers. It is also important to implement physical security measures, such as properly securing hardware and following guidelines for physical access to facilities. These tools will help you to detect unwanted programs and helps you safeing your data externally. &lt;br /&gt;
&lt;br /&gt;
* Anti Virus Software: [https://www.malwarebytes.com/ Malwarebytes]&lt;br /&gt;
* Browser Anti-Ad/Spam Plugin: [https://ublockorigin.com/ uBlock Origin]&lt;br /&gt;
* Check E-Mail periodically: [https://haveibeenpwned.com/ HaveIBeenPwned]&lt;br /&gt;
* Safe File externally: [https://nextcloud.com/ Nextcloud]&lt;br /&gt;
* Check Programs: [https://www.virustotal.com/ Virustotal]&lt;br /&gt;
* Password Manager: [https://keepassxc.org/ KeepassXC]&lt;br /&gt;
&lt;br /&gt;
== Social Media Intelligence ==&lt;br /&gt;
&lt;br /&gt;
Social media intelligence (SOCMINT) is a process that involves gathering and analyzing data from social media platforms in order to inform business decisions. This type of intelligence can be used to track brand mentions and sentiment, monitor competitors, and identify emerging trends or opportunities for engagement.&lt;br /&gt;
&lt;br /&gt;
By collecting and analyzing social media data, companies can gain valuable insights into the perceptions and behaviors of their customers and target audience. This can inform marketing strategies, customer service efforts, and product development. For example, a company might use social media intelligence to identify common customer pain points and develop solutions to address them, or to identify influencers to partner with in order to promote their brand.&lt;br /&gt;
&lt;br /&gt;
There are a number of tools and platforms available to help companies automate the process of gathering and analyzing social media data. These tools often include features such as keyword tracking, sentiment analysis, and competitor analysis.&lt;br /&gt;
&lt;br /&gt;
Overall, social media intelligence can be an important part of a company&#039;s market research and customer insights efforts, helping them to better understand and connect with their audience on social media. It can also be a useful way for companies to stay up-to-date on industry developments and emerging trends, and to identify opportunities for growth and innovation.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.sciencedirect.com/science/article/abs/pii/S2214212614001343?via%3Dihub&lt;br /&gt;
* https://link.springer.com/chapter/10.1007/978-3-642-22424-9_4&lt;br /&gt;
* https://www.mdpi.com/1999-5903/11/4/89&lt;br /&gt;
* https://www.researchgate.net/profile/Hugo-Barbosa/publication/315351300_SOCIAL_ENGINEERING_AND_CYBER_SECURITY/links/599c43430f7e9b892bafc0df/SOCIAL-ENGINEERING-AND-CYBER-SECURITY.pdf&lt;br /&gt;
* https://cybernews.com/cyber-war/influencing-anonymous-experiment/&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>HDogan</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering_%26_Phishing_Platform&amp;diff=17556</id>
		<title>Social Engineering &amp; Phishing Platform</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering_%26_Phishing_Platform&amp;diff=17556"/>
		<updated>2024-12-18T17:41:00Z</updated>

		<summary type="html">&lt;p&gt;HDogan: was duplicate to &amp;quot;Social Engineering&amp;quot;. Merged both together and left the Phishing Exercises&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Social Engineering ==&lt;br /&gt;
&lt;br /&gt;
[[Social Engineering]] is a kind of cyber attack that influences a person to take an action that may or may not be in their best interests, according to Hadnagy. It relies on psychological manipulation with the goal of making individuals perform actions or share confidential information.&lt;br /&gt;
&lt;br /&gt;
==Mail Phishing Exercise==&lt;br /&gt;
The exercise &amp;quot;Mail Phishing&amp;quot; is designed to educate users about the risks associated with freely available personal information. The exercise serves as a demonstration of how social engineers can exploit personal details to execute phishing attacks, thus highlighting the necessity for cautious communication in work environments.&lt;br /&gt;
&lt;br /&gt;
[[File:Mail.PNG]]&lt;br /&gt;
===Purpose===&lt;br /&gt;
&lt;br /&gt;
;Raise Awareness:&lt;br /&gt;
: By simulating a phishing scenario using social media information, the exercise aims to raise awareness about the potential threats of sharing personal details online.&lt;br /&gt;
;Educate about Phishing:&lt;br /&gt;
: Through experiencing the attacker&#039;s perspective, participants learn about the tactics used by cybercriminals.&lt;br /&gt;
;Promote Alertness:&lt;br /&gt;
: The exercise highlights the importance of exercising caution when sharing online.&lt;br /&gt;
&lt;br /&gt;
===Scenario===&lt;br /&gt;
The exercise aims to personalize an email to an employee, faking familiarity. It begins with users being prompted to access publicly available social media data to gather information about the fictional individual.&lt;br /&gt;
Upon gathering the necessary information, participants are instructed to complete an email addressed to Cameron, impersonating a colleague named Sarah from the accounting department. The email requests Cameron&#039;s employee ID and department. The email seems urgent thanks to faking a system failure, exploiting the familiarity implied by the shared personal details.&lt;br /&gt;
If participants successfully fill in Cameron&#039;s employee ID, they &amp;quot;win&amp;quot; the exercise. In the case of a successful spoof, the user receives a short text explaining the tactics behind this attack, highlighting the potential risks associated with sharing personal information online and the importance of verifying requests for sensitive data in professional contexts.&lt;br /&gt;
&lt;br /&gt;
===Lessons===&lt;br /&gt;
#Recognizing the risks associated with freely available personal information on social media.&lt;br /&gt;
#Understanding the tactics employed in phishing attacks and how they exploit human psychology.&lt;br /&gt;
#Developing critical thinking skills to discern legitimate communication from potential phishing attempts.&lt;br /&gt;
#Implementing best practices for safeguarding sensitive information in online interactions.&lt;br /&gt;
== Shoulder Surfing Exercise ==&lt;br /&gt;
The exercise &amp;quot;Shoulder Surfing&amp;quot; is designed to educate on the potential risks associated with unauthorized access to sensitive information. Furthermore, it should highlight the importance of good password hygiene. Participants engage in a simulated scenario where they attempt to uncover a coworker&#039;s password and user.&lt;br /&gt;
&lt;br /&gt;
[[File:Shoulder.PNG]]&lt;br /&gt;
=== Purpose ===&lt;br /&gt;
; Highlighting the Simplicity of Shoulder Surfing:&lt;br /&gt;
: By simulating a scenario where participants attempt to obtain a coworker&#039;s password through observation, the exercise underscores the risks associated with shoulder surfing and unauthorized access to sensitive information.&lt;br /&gt;
; Promoting Good Password Hygiene:&lt;br /&gt;
: Participants learn about the importance of using strong, unique passwords and avoiding the use of easily guessable information, such as details found in one&#039;s surroundings.&lt;br /&gt;
; Raising Awareness about Password Complexity:&lt;br /&gt;
: The exercise encourages participants to consider their password choices.&lt;br /&gt;
&lt;br /&gt;
=== Scenario ===&lt;br /&gt;
The exercise aims to figure out the identity of a coworker by &amp;quot;hacking&amp;quot; a web page. It begins with participants suspecting a coworker of stealing a project and needing evidence to confirm their suspicions. Participants are tasked with extracting information based on the work environment and a shoulder surfing snapshot. Using the observed information, participants attempt to access the coworker&#039;s given data on the site. Once participants successfully &amp;quot;hack&amp;quot; the profile, they uncover personal information about the coworker, effectively confirming their identity and involvement in the scenario.&lt;br /&gt;
&lt;br /&gt;
===Learning Objectives===&lt;br /&gt;
#Understanding the risks associated with shoulder surfing and unauthorized access to sensitive information.&lt;br /&gt;
#The importance of using strong, unique passwords to protect personal and professional accounts.&lt;br /&gt;
#Developing critical thinking skills to identify potential security vulnerabilities in password practices.&lt;br /&gt;
#Promoting a culture of security awareness and personal responsibility in safeguarding sensitive data.&lt;br /&gt;
&lt;br /&gt;
==The Project==&lt;br /&gt;
[https://git.fh-campuswien.ac.at/c2010475112/Phishing-Platform ProjectGit]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* C. Hadnagy, Social Engineering: The Science of Human Hacking. Wiley, 2010.&lt;br /&gt;
* K. D. Mitnick, The Art of Deception. Wiley, 2002. &lt;br /&gt;
* N. Y. Conteh and P. J. Schmick, “Cybersecurity:risks, vulnerabilities and countermeasures to prevent social engineering attacks,” 2016. [Online]. Available: https://api.semanticscholar.org/CorpusID:70178926&lt;br /&gt;
* R. B. Cialdini, Influence: The Psychology of Persuasion. HarperBusiness, 2006.&lt;br /&gt;
* R. Salama, F. Al-Turjman, S. Bhatla, and S. P. Yadav, “Social engineering attack types and prevention techniques- a survey,” in 2023 International Conference on Computational Intelligence, Communication Technology and Networking CICTN), 2023, pp.817–820.&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>HDogan</name></author>
	</entry>
</feed>