Glossary

Cybercriminals are constantly evolving their tactics, exploiting human vulnerabilities to bypass traditional security measures.

"The Ultimate Social Engineering Glossary" provides a comprehensive list of terms and definitions to help you understand the techniques, tactics, and concepts behind social engineering attacks. Use this resource to stay informed and strengthen your defenses against phishing, vishing, smishing, and other human-targeted threats.

a

  • AI-Driven Phishing

    Phishing attacks enhanced by artificial intelligence to generate realistic and personalized messages or scenarios.

  • AI-Forged Evidence

    Creating fake evidence, such as contracts or emails, using AI to manipulate targets.

  • API Exploitation

    Misusing open APIs to extract sensitive organizational data.

  • Account Takeover

    When attackers gain control of a victim's online accounts through credential compromise.

  • Active Directory

    A critical component developed by Microsoft for managing network resources and user permissions.

  • Ad Fraud

    Manipulating online advertising systems to generate illegitimate revenue or redirect users.

  • Adversarial AI

    The use of artificial intelligence by attackers to bypass traditional security measures or create advanced threats.

  • Angler Phishing

    Using fake customer service accounts on social media to lure victims into sharing sensitive information.

  • Attack Surface Management

    Identifying and minimizing the points where an attacker can exploit vulnerabilities.

  • Authentication Bombing

    Flooding a user with authentication requests to confuse or coerce them into granting access.

  • Authority Amplification

    Simulating multiple trusted sources to strengthen a false claim.

  • Authority Exploitation

    Using perceived authority to manipulate targets into compliance.

  • Automated Phishing Defense

    Technological systems that use automation to detect, block, and respond to phishing attempts in real-time.

b

  • BEC (Business Email Compromise)

    A sophisticated attack where an attacker impersonates a company executive or vendor to request unauthorized transfers of funds or data.

  • Baiting

    Using false promises or enticing offers to lure individuals into a trap, such as downloading malware.

  • Behavioral Analytics

    Monitoring user behavior to detect and respond to abnormal or potentially malicious activities.

  • Blockchain-Based Social Engineering

    Leveraging blockchain tools for anonymity in fraudulent schemes.

  • Brow Phishing

    Using fake browser pop-ups or alerts to deceive users into sharing credentials.

  • Browser-in-the-Browser (BitB) Attack

    Simulating legitimate browser login prompts to steal credentials.

  • Business Logic Exploitation

    Manipulating legitimate business processes to achieve malicious goals.

c

  • CEO Fraud

    A specific type of BEC where the attacker pretends to be the CEO or another high-ranking official to manipulate employees into transferring money or sensitive information.

  • Catfishing

    Creating fake online personas to gain trust and manipulate individuals into revealing personal details.

  • Clickbaiting

    Creating enticing or misleading links to trick users into clicking.

  • Cognitive Load Exploitation

    Overloading a target with information to confuse them and make them more likely to comply.

  • Cold Call Phishing

    Using direct phone calls to build trust and extract sensitive details.

  • Compromised Account

    An account that has been either hacked or accessed by unauthorized individuals or entities. In the context phishing simulations, compromised accounts are accounts for which the password has been leaked.

  • Consent Phishing

    Tricking users into granting permissions that lead to unauthorized access.

  • Credential Harvesting

    Collecting usernames, passwords, or other authentication details, often through phishing or malware.

  • Credential Stuffing

    Using stolen username-password combinations from data breaches to access accounts across multiple systems.

  • Cryptocurrency Phishing

    Targeting individuals or companies to steal cryptocurrency assets.

  • Cryptolocker

    A type of ransomware that encrypts files and demands payment for decryption.

  • Cyber Crime

    Criminal activities carried out using computers or the internet, such as hacking, fraud, or identity theft.

  • Cyber Deception

    The use of deceptive strategies, such as honeypots or decoy systems, to mislead attackers and gather intelligence.

  • Cyber Hygiene

    Practices and precautions taken to maintain the security of devices and data.

  • Cyber Resilience

    The ability of an organization to prepare for, respond to, and recover from cyberattacks while minimizing disruption.

d

  • DKIM (DomainKeys Identified Mail)

    An email authentication method that uses cryptographic keys to verify the authenticity of the sender.

  • DMARC (Domain-based Message Authentication, Reporting, and Conformance)

    An email authentication protocol that helps prevent email spoofing and phishing attacks.

  • DNS

    The Domain Name System is a decentralized system that translates domain names into IP addresses. It is used to locate websites and other resources on the internet.

  • DNS Spoofing

    Redirecting users to malicious websites by altering the DNS entries of legitimate sites.

  • DNS Spoofing

    Redirecting users to malicious websites by altering the DNS entries of legitimate sites.

  • Data Classification

    Categorizing data based on its sensitivity to ensure appropriate protection and handling (e.g., public, private, confidential).

  • Data Exfiltration

    Unauthorized transfer of data from a system or network to an external location.

  • Data Leaks

    Unintentional exposure of sensitive data, often due to misconfigurations or human error.

  • Data Loss Prevention (DLP)

    Tools and strategies used to prevent unauthorized access, sharing, or loss of sensitive data.

  • Data Poisoning

    Introducing false data to undermine the integrity of AI systems.

  • Deepfake Phishing

    The use of AI-generated audio or video to impersonate a trusted individual, often for BEC or other scams.

  • Deepfake Video Scams

    Using AI-generated videos to impersonate executives or leaders.

  • Distributed Social Engineering

    Coordinated attacks by multiple individuals to manipulate a target into revealing sensitive information.

  • Domain Poisoning

    Manipulating DNS or domains to redirect users to malicious sites.

  • Domain Spoofing

    Creating fake but convincing website domains to trick users into entering credentials.

  • Doxing

    Publishing private or identifying information about an individual without their consent.

  • Dumpster Diving

    Searching through physical trash or discarded materials to find sensitive information like passwords, documents, or hardware.

e

  • E-discovery

    The process of identifying, collecting, and producing electronic information for legal purposes.

  • Eavesdropping

    Intercepting verbal or electronic communications to gather sensitive information.

  • Electronic Communication

    The exchange of information through electronic devices, such as emails, text messages, or social media.

  • Email Archiving

    The process of storing and managing email messages for compliance, legal, or business purposes.

  • Email Filtering

    The process of sorting and blocking unwanted or malicious emails.

  • Email Gateway

    A security solution that filters and blocks malicious emails before they reach the recipient's inbox.

  • Email Header Spoofing

    Altering email headers to make fraudulent messages appear legitimate.

  • Email Phishing

    Phishing attempts carried out via email to trick recipients into clicking malicious links or providing credentials.

  • Email Scams

    Fraudulent schemes conducted via email to deceive recipients into sending money or sensitive information.

  • Email Security

    Measures and technologies used to protect email systems from cyber threats.

  • Emotional Anchoring

    Using strong emotions to sway decision-making.

  • Encryption Techniques

    Methods used to secure data by converting it into a code that can only be read by authorized parties.

  • Evil Maid Attack

    Physical attacks on unattended devices to install malware or steal sensitive data.

  • Evil Twin Attack

    Creating a fake Wi-Fi network to intercept data and credentials from unsuspecting users who connect.

  • Executive Impersonation

    Pretending to be a senior executive to coerce employees into unauthorized actions.

f

  • FOMO (Fear of Missing Out) Exploitation

    Creating urgency by implying a missed opportunity or critical deadline.

  • Fake Payment Confirmation

    Sending falsified payment receipts to deceive targets into delivering goods or services.

  • Fear-Based Messaging

    Using fear to compel action or disclosure of information.

  • Friend-in-Trouble Scam

    Pretending to be a friend or acquaintance in distress to solicit money or information.

g

  • GenAI Phishing

    Phishing attacks generated by advanced AI tools, enabling highly personalized and convincing messages at scale.

  • Gift Card Scams

    Tricking victims into purchasing gift cards as a form of payment.

  • Graymail

    Unwanted emails that are not classified as spam but are often ignored or deleted.

h

  • Hacking

    Creating fake customer service numbers to intercept sensitive information.

  • Helpline Spoofing

    Creating fake customer service numbers to intercept sensitive information.

  • Honey Credentials

    Intentionally planting fake credentials to detect phishing or compromise attempts.

  • Honey Trap

    Using fake romantic or personal relationships to manipulate a target into divulging confidential information.

  • Honeypot

    A decoy system or network designed to attract and deceive attackers, gather intelligence, or divert attacks from critical assets.

  • Human Firewall

    Employees trained to detect and prevent cyberattacks by adhering to security best practices.

  • Hybrid Attacks

    Combining multiple social engineering vectors, such as phishing and smishing, for higher success.

i

  • ITDR (Identity Threat Detection and Response)

    The process of identifying and responding to identity-related threats.

  • Impersonation

    Pretending to be a trusted individual or entity to gain access to sensitive information or systems.

  • Imposter Syndrome Exploitation

    Targeting individuals with self-doubt to extract sensitive information.

  • Incident Response

    The process of identifying, containing, and recovering from security incidents.

  • Influence Campaigns

    Coordinated efforts to manipulate public opinion or behavior.

  • Info Stealer Malware

    Malware designed specifically to exfiltrate sensitive data from victims.

  • Insider Threat Engineering

    Manipulating insiders to carry out malicious actions or provide unauthorized access.

  • IoT Exploitation

    Targeting vulnerabilities in Internet of Things devices for information gathering or attacks.

j

  • Juice Jacking

    Exploiting public charging stations to extract data or inject malware onto a victim's device.

l

  • Lateral Phishing

    Using compromised accounts within an organization to launch phishing attacks on others.

  • Leaky Forms

    Exploiting insecure online forms to extract sensitive user information.

  • Least Privilege

    Limiting user access to only the data and resources necessary for their role.

m

  • Machine Learning Poisoning

    Manipulating AI models to introduce vulnerabilities or bias into their decision-making.

  • Malvertising

    Using malicious advertisements to direct victims to phishing sites or deliver malware.

  • Malvertising Campaigns

    Using malicious advertisements to redirect victims to phishing sites or deliver malware.

  • Malware

    Malicious software designed to damage, disrupt, or gain unauthorized access to systems.

  • Man-in-the-Browser (MitB) Attack

    Intercepting and manipulating browser communication for malicious purposes.

  • Man-in-the-Middle (MitM) Attack

    Intercepting and altering communication between two parties without their knowledge.

  • Microtargeting

    Using data analytics to target specific individuals with customized social engineering attacks.

  • Mobile Security

    Measures and technologies used to protect mobile devices from cyber threats.

  • Multi-Channel Phishing

    Combining multiple methods (e.g., email, SMS, voice) to enhance phishing success rates.

n

  • Name-Drop Exploitation

    Using references to known individuals to gain trust and access.

  • Nudge Attacks

    Subtly influencing user behavior to make security-compromising decisions.

o

  • OSI Model (Open Systems Interconnection)

    A conceptual framework that standardizes the functions of communication systems into seven layers: physical, data link, network, transport, session, presentation, and application.

p

  • Password Spraying

    Using a few common passwords across many accounts to avoid detection.

  • Personally Identifiable Information (PII)

    Any data that can be used to identify an individual, such as names, addresses, social security numbers, or biometric data.

  • Pharming

    Redirecting users from legitimate websites to fake ones to steal sensitive information.

  • Phishing

    Fraudulent attempts to obtain sensitive information, such as passwords or credit card details, by pretending to be a trustworthy entity.

  • Phone-Based Scams

    Fraudulent calls aimed at extracting sensitive information or convincing victims to take harmful actions.

  • Piggybacking

    Gaining access to restricted areas by closely following someone authorized, similar to tailgating but with implied consent.

  • Preloading

    Manipulating cognitive biases to influence a target's behavior or decisions.

  • Pretexting

    Creating a fabricated scenario to gain the trust of a target and extract information or access systems.

  • Pretexting Variants

    Tailoring pretexting scenarios to align with specific victim profiles.

  • Pretexting for Reconnaissance

    Using fabricated scenarios to gather preliminary information about a target.

  • Privilege Escalation

    Gaining higher levels of access or permissions than intended.

  • Privileged Identity Management (PIM)

    The process of managing and securing privileged accounts to prevent unauthorized access.

q

  • QR Code Phishing (Quishing)

    Exploiting QR codes to direct users to malicious websites or download harmful content.

  • Quid Pro Quo Attack

    A social engineering tactic where an attacker offers a benefit or service in exchange for sensitive information or access.

r

  • Ransomware

    A type of malware that encrypts a victim's files, demanding payment for the decryption key.

  • Replay Attacks

    Intercepting and reusing valid credentials or session tokens to gain unauthorized access.

  • Reverse Social Engineering

    Convincing a target to contact the attacker for help, allowing the attacker to manipulate the target further.

  • Risk Management

    The process of identifying, assessing, and mitigating risks to an organization's assets.

  • Rogue Wi-Fi Hotspots

    Setting up fake Wi-Fi networks to intercept user data.

s

  • SIM Swapping

    Taking over a victim's phone number by convincing the carrier to transfer it to a new SIM card.

  • SPF (Sender Policy Framework)

    An email authentication protocol that helps prevent email spoofing by verifying the sender's IP address.

  • Sandbox

    A secure, isolated environment used to test suspicious files or applications without risking the host system.

  • Security Awareness Training (SAT)

    Educational programs designed to teach employees how to recognize and prevent cyber threats.

  • Security Operations Center (SOC)

    A centralized team responsible for monitoring, detecting, and responding to cybersecurity threats.

  • Session Hijacking

    Taking control of an active user session to gain unauthorized access.

  • Shoulder Surfing

    Observing someone's private information, like passwords or PINs, by looking over their shoulder.

  • Smishing

    Phishing attacks conducted via SMS or text messages to trick users into divulging personal or financial information.

  • Social Engineering

    The use of psychological manipulation to deceive individuals into divulging confidential information or performing actions that compromise security.

  • Social Media Exploitation

    Leveraging social media platforms to gather information about targets or deliver malicious content.

  • Social Proof Exploitation

    Leveraging the influence of group behavior to manipulate a target.

  • Spam

    Unsolicited or irrelevant messages sent in bulk, often for commercial purposes.

  • Spear Phishing

    A targeted phishing attack directed at a specific individual or organization using personalized information to increase success rates.

  • Spear Smishing

    Combining personalized spear phishing with SMS communication.

  • Spoofing

    The act of impersonating a trusted source, such as an email address or phone number, to deceive victims.

  • Spyware

    A type of malware that secretly gathers information about a user's activities without their knowledge.

t

  • Tailgating (Piggybacking)

    Gaining physical access to a secured area by following someone authorized, without proper credentials.

  • Tech Support Scams

    Pretending to offer technical assistance to gain access to devices or data.

  • Telemetry

    The process of collecting and transmitting data from remote devices.

  • Threat Simulation

    Staging mock cyberattacks to trick organizations into sharing security details.

  • Trojan Horse

    A type of malware that disguises itself as legitimate software to gain access to a system.

  • Trust Anchoring

    Exploiting trust in well-known brands or individuals to deceive targets.

  • Typosquatting

    The practice of registering domains similar to legitimate ones to trick users into visiting malicious websites.

u

  • URL Shortener Abuse

    Using shortened URLs to conceal malicious links and trick users into clicking them.

  • Unsolicited Social Proof

    Providing fake reviews or endorsements to manipulate decision-making.

  • Urgency Tactics

    Creating a sense of immediate action to bypass rational decision-making.

v

  • VPN (Virtual Private Network)

    A secure connection that encrypts data transmitted between a user's device and the internet.

  • Virtual Meeting Phishing

    Impersonating legitimate virtual meeting invitations to steal credentials.

  • Virus

    A computer virus is a type of malware that can replicate itself and spread to other devices.

  • Vishing

    Phishing conducted through voice calls, often involving impersonation of trusted entities like banks or government agencies.

  • Voice Cloning

    Using AI-generated voice mimicking technology to impersonate trusted individuals and conduct scams.

w

  • Watering Hole Attack

    Compromising a website frequently visited by a target to infect them with malware or gather credentials.

  • Weak Credential Targeting

    Exploiting accounts protected by weak passwords.

  • Whaling

    A type of spear phishing targeting high-profile individuals like executives or board members, often to exploit their access to sensitive data.

  • Whistleblower Impersonation

    Pretending to be a whistleblower to gather confidential information from organizations.

x

z

  • Zero Trust

    A security model that assumes no user or system is trustworthy by default.

  • Zero-Day Social Engineering

    Exploiting newly discovered vulnerabilities to manipulate users before patches are available.

Recognized by cybersecurity experts

The most innovative companies choose Arsen

Inquest Risk Login Sécurité Iliane Cloud Temple

Ready to see Arsen in action?

Discover how Arsen helps CISOs, cyber experts, and IT teams protect their organizations.