Process Manipulation
Process manipulation exploits weak, informal, unclear, overloaded, or poorly enforced organisational processes. The attacker may seek a bypass, misuse an exception, alter an approval sequence, exploit unclear ownership, insert a changed action into a real workflow, or supply false evidence that a process has already occurred.
The request often appears administrative rather than security-sensitive. A payment change, access request, ticket update, hand-off, or approval may be framed as routine completion of work that someone else has already checked. The process itself then carries legitimacy into an action that lacks the required authority or evidence.
Process manipulation can be assessed by asking:
- Which process or decision path is being used?
- What step, owner, approval, evidence, or system of record is being bypassed or misrepresented?
- Is the exception or changed sequence authorised for this situation?
- Can the request be confirmed within the established workflow?
Techniques
Section titled “Techniques”Process Manipulation includes the techniques below. Select a technique to open its behavioural method, common examples, relevant taxonomy boundaries, and control-domain orientation in the Technique Catalogue.
- SE-T005.001Process Bypass RequestRequesting that a normal approval, verification, or workflow step be skipped.
- SE-T005.002Exception Handling AbuseExploiting edge cases, urgent exceptions, or unclear exception pathways.
- SE-T005.003Payment, Payroll or Supplier Change ManipulationTargeting payment destinations, payroll records, invoices, supplier records, or bank-detail change processes.
- SE-T005.004Access Provisioning Workflow ManipulationExploiting onboarding, reactivation, role-change, temporary-access, offboarding-reversal, or privileged-access provisioning workflows.
- SE-T005.005Existing Ticket or Workflow AbuseUsing, altering, expanding, or redirecting a genuine ticket, case, queue, or workflow record to create legitimacy or drive an unauthorised action.
- SE-T005.006Approval Sequence ManipulationExploiting the order, substitution, scope, or completion state of approvals so an action proceeds without the intended decision path.
- SE-T005.007Process Ownership ConfusionExploiting uncertainty about who owns a process, decision, request, or escalation path.
- SE-T005.008Control Fatigue ExploitationTargeting busy, overloaded, repetitive, or high-volume process environments where review quality may drop.
- SE-T005.009Fabricated Workflow EvidenceSupplying counterfeit process artefacts to make a request appear already approved or in workflow.
Behavioural Indicators
Section titled “Behavioural Indicators”Process manipulation activity may involve one or more of the following behaviours:
Workflow and approval behaviour
- requesting exceptions to normal process
- asking for manual handling, workaround, override, or direct approval
- claiming a process is blocking urgent, important, or routine work
- presenting a risky request as administrative, ordinary, already approved, or low-impact
- referencing previous approval without evidence
- asking for approval after the action has already started or been completed
Ownership and handoff behaviour
- exploiting unclear ownership or approval paths
- creating ambiguity around responsibility, authority, or process state
- contacting multiple departments to find the weakest point in a handoff
- claiming another team, manager, supplier, customer, or system owner is responsible for the request
- using “finance said IT handles it” or “HR told me to contact you” style handoff pressure
- pushing staff to resolve ambiguity quickly rather than confirm process ownership
Identity, access, supplier, and asset behaviour
- targeting access provisioning, onboarding, reactivation, role-change, temporary-access, or privileged-access workflows
- requesting supplier bank detail changes, payroll changes, invoice updates, or payment redirection
- using tickets, forms, workflow references, or approval language to create legitimacy
- supplying forged, doctored, recycled, or fabricated documents, screenshots, ticket numbers, or approval references that cannot be validated in the system of record
Pressure and control-fatigue behaviour
- targeting busy periods, queues, incidents, payroll runs, finance cut-offs, enrolment windows, holidays, or after-hours conditions
- pressuring staff to “just do it this once”
- resisting ticket creation, workflow entry, callback, second approval, or documented verification
- escalating when the target attempts to follow process
- exploiting helpfulness, urgency, authority, familiarity, or confusion to bypass checkpoints