Skip to content

Information Harvesting

Information harvesting includes interactive elicitation and non-interactive reconnaissance used to prepare or strengthen social engineering activity. It may collect information about identities, relationships, processes, systems, suppliers, timing, physical environments, or exposed organisational material.

Information that appears low in sensitivity may become more useful when combined with other details, although a single item may also be sufficient to support targeting or access. Collection method and information subject are separate dimensions, so more than one information-harvesting technique may apply to the same activity.

Information harvesting can be assessed by asking:

  • What information is being collected?
  • How is it being obtained: public source, conversation, observation, document, technical source, or prior leak?
  • What later pretext, access attempt, fraud, or targeting decision could it support?
  • What exposure, disclosure, or monitoring control is relevant to the source?

Information Harvesting includes the techniques below. Select a technique to open its behavioural method, common examples, relevant taxonomy boundaries, and control-domain orientation in the Technique Catalogue.


Information harvesting activity may involve one or more of the following behaviours:

Information-seeking behaviour

  • asking casual or low-risk questions that slowly build a picture of internal operations
  • confirming names, roles, contact details, reporting structures, approval paths, or handoff points
  • asking who handles a process, who approves a change, or which team owns a system
  • asking for small details that appear harmless in isolation but become useful when combined
  • returning later with follow-up questions that increase specificity or sensitivity

Process, relationship, and operational probing

  • gathering process or workflow information under the guise of a routine enquiry
  • collecting details about finance, helpdesk, HR, procurement, facilities, supplier, or identity workflows
  • identifying trusted relationships, executive assistants, approvers, suppliers, contractors, or escalation paths
  • asking about travel, staffing, meeting schedules, rosters, payroll timing, project deadlines, events, or operational cycles
  • contacting multiple departments to compare answers or fill gaps

Physical and environmental reconnaissance

  • observing physical environments, staff movements, badge visibility, screens, whiteboards, printers, reception flow, or document handling
  • collecting discarded, printed, exposed, shared, or unattended documents and artefacts
  • photographing badges, signage, screens, office layouts, visitor processes, access points, or delivery routines
  • testing how reception, facilities, security, or frontline staff respond to seemingly harmless enquiries

Digital and public exposure behaviour

  • collecting publicly available organisational information and correlating it across sources
  • reviewing staff profiles, social media posts, job advertisements, public documents, presentations, supplier pages, and event material
  • probing for technology, identity, cloud, access, portal, MFA, email-format, domain, subdomain, or vendor details
  • searching for exposed repositories, cloud storage, certificates, metadata, public documents, or login portals
  • aggregating already-leaked data, breach dumps, combolists, stealer logs, non-public leaked records, or paste-site content, to recover credentials, email formats, or personal identifiers for reuse

Preparation for follow-on activity

  • using harmless-seeming questions to prepare later impersonation, phishing, fraud, access, or physical entry attempts
  • building context that can make a later message sound internal, familiar, urgent, or legitimate
  • collecting enough information to target a specific person, team, supplier, executive assistant, helpdesk process, or approval workflow