Information Harvesting
Information harvesting includes interactive elicitation and non-interactive reconnaissance used to prepare or strengthen social engineering activity. It may collect information about identities, relationships, processes, systems, suppliers, timing, physical environments, or exposed organisational material.
Information that appears low in sensitivity may become more useful when combined with other details, although a single item may also be sufficient to support targeting or access. Collection method and information subject are separate dimensions, so more than one information-harvesting technique may apply to the same activity.
Information harvesting can be assessed by asking:
- What information is being collected?
- How is it being obtained: public source, conversation, observation, document, technical source, or prior leak?
- What later pretext, access attempt, fraud, or targeting decision could it support?
- What exposure, disclosure, or monitoring control is relevant to the source?
Techniques
Section titled “Techniques”Information Harvesting includes the techniques below. Select a technique to open its behavioural method, common examples, relevant taxonomy boundaries, and control-domain orientation in the Technique Catalogue.
- SE-T006.001Open-Source Intelligence CollectionGathering publicly available information about people, organisations, systems, suppliers, or operations.
- SE-T006.002Organisational Process ReconnaissanceCollecting information about workflows, approvals, reporting lines, systems, or operational procedures.
- SE-T006.003Relationship & Trust MappingIdentifying trusted relationships, reporting structures, suppliers, teams, or external contacts.
- SE-T006.004Physical Observation & Environmental ReconnaissanceCollecting information through physical presence, observation, or environmental exposure.
- SE-T006.005Casual Information ElicitationUsing informal conversation or low-risk interaction to collect contextual information.
- SE-T006.006Identity & Authentication ReconnaissanceCollecting usernames, account formats, identity providers, MFA methods, authentication portals, or recovery-process information.
- SE-T006.007Document & Artefact CollectionCollecting discarded, exposed, printed, shared, or improperly secured information assets.
- SE-T006.008Digital Presence ProfilingIdentifying technology platforms, cloud services, vendors, security tooling, or communication methods.
- SE-T006.009Event & Operational Timing CollectionGathering information about schedules, staffing, travel, meetings, projects, deadlines, or operational cycles.
- SE-T006.010Breach & Leak Data AggregationUsing data from prior breaches, leaks, or stealer logs to accelerate targeting, impersonation, or identity abuse.
Behavioural Indicators
Section titled “Behavioural Indicators”Information harvesting activity may involve one or more of the following behaviours:
Information-seeking behaviour
- asking casual or low-risk questions that slowly build a picture of internal operations
- confirming names, roles, contact details, reporting structures, approval paths, or handoff points
- asking who handles a process, who approves a change, or which team owns a system
- asking for small details that appear harmless in isolation but become useful when combined
- returning later with follow-up questions that increase specificity or sensitivity
Process, relationship, and operational probing
- gathering process or workflow information under the guise of a routine enquiry
- collecting details about finance, helpdesk, HR, procurement, facilities, supplier, or identity workflows
- identifying trusted relationships, executive assistants, approvers, suppliers, contractors, or escalation paths
- asking about travel, staffing, meeting schedules, rosters, payroll timing, project deadlines, events, or operational cycles
- contacting multiple departments to compare answers or fill gaps
Physical and environmental reconnaissance
- observing physical environments, staff movements, badge visibility, screens, whiteboards, printers, reception flow, or document handling
- collecting discarded, printed, exposed, shared, or unattended documents and artefacts
- photographing badges, signage, screens, office layouts, visitor processes, access points, or delivery routines
- testing how reception, facilities, security, or frontline staff respond to seemingly harmless enquiries
Digital and public exposure behaviour
- collecting publicly available organisational information and correlating it across sources
- reviewing staff profiles, social media posts, job advertisements, public documents, presentations, supplier pages, and event material
- probing for technology, identity, cloud, access, portal, MFA, email-format, domain, subdomain, or vendor details
- searching for exposed repositories, cloud storage, certificates, metadata, public documents, or login portals
- aggregating already-leaked data, breach dumps, combolists, stealer logs, non-public leaked records, or paste-site content, to recover credentials, email formats, or personal identifiers for reuse
Preparation for follow-on activity
- using harmless-seeming questions to prepare later impersonation, phishing, fraud, access, or physical entry attempts
- building context that can make a later message sound internal, familiar, urgent, or legitimate
- collecting enough information to target a specific person, team, supplier, executive assistant, helpdesk process, or approval workflow