Technique Catalogue
Each technique records an attacker method. Expand a technique to review the behavioural method, common examples, and relevant taxonomy boundaries.
Loaded techniques: 123
Showing 123 techniques.
| Technique | Tactic | Manipulation Levers | Control Domains |
|---|---|---|---|
Posing as a senior leader or decision-maker so that authority, urgency, or seniority discourages scrutiny. | Impersonation | Authority, Urgency, Fear | IDAAVEPHM |
Executive or senior leader impersonation is the adoption of a senior organisational identity to lend authority to a request or action. The attacker presents as an executive, director, board member, business owner, or other senior figure so the target interprets the interaction through the authority associated with that role. Apparent seniority can imply that a requested action has already been considered, approved, or accepted at a higher level. This reduces the need for the request itself to appear fully credible and may make delay, refusal, or independent confirmation feel professionally difficult. The technique exploits expectations around senior communication. Brief messages, direct instructions, unusual timing, confidentiality, and limited context may be consistent with genuine executive behaviour, allowing inconsistencies to be rationalised rather than challenged. Attackers may strengthen the claimed identity with organisational knowledge, reporting relationships, current business activity, writing-style mimicry, or synthetic voice and video. Executive impersonation can be used to influence payments, information disclosure, access, approvals, process changes, or exceptions to established workflows. These supporting requests and deception methods may vary, but the technique remains centred on using borrowed senior authority to shape how the target interprets and responds to the interaction. Common examplesCEO, CFO, director, board member, principal, chair, trustee, business owner, senior manager Technique boundariesExecutive or senior leader impersonation is distinguished from Authority & Obligation Pressure by the adoption of a senior organisational identity. Authority pressure can influence behaviour without the attacker claiming to be a senior leader. Where an attacker controls a genuine executive account or authenticated session, Compromised Account Impersonation may better describe the identity method. Synthetic voice or video may reinforce executive impersonation, while Synthetic Media or Deepfake Impersonation applies where fabricated media is central to establishing the false identity. | |||
Posing as a colleague or internal role to trade on familiarity, workflow trust, and assumed legitimacy. | Impersonation | Familiarity, Trust, Social Proof | IDAAVEPHM |
Internal staff impersonation uses the appearance of an internal relationship or business function to make a request feel ordinary. The attacker may present as a colleague, manager, HR representative, finance contact, payroll officer, facilities staff member, or another internal role and refer to real teams, systems, projects, tickets, or organisational activity. The method trades on familiarity with internal work. A request to confirm personal details, share a file, approve access, update payroll information, or assist with an internal task can appear routine when it is framed in the language of normal business. The claimed role may remain deliberately vague, giving the attacker enough internal context to feel plausible without exposing the impersonation to detailed role-specific questions. Common examplescolleague, manager, HR, finance, payroll, facilities, security Technique boundariesInternal Staff Impersonation applies to a general employee or internal function where no more specific impersonation technique better describes the adopted identity. Familiar Relationship Exploitation can use an existing or assumed relationship without the attacker claiming to be a particular employee. Compromised Account Impersonation applies when a genuine account or authenticated session is under attacker control. | |||
Posing as technical or identity support to influence credential, access, device, or MFA actions. | Impersonation | Trust, Authority, Urgency | IDAFSTAVEDTM |
Helpdesk or IT support impersonation presents the attacker as a service desk, system administrator, identity team, technical support function, or known technology provider. The target is led to believe that a problem needs to be resolved or that support activity is already underway, then asked to take an action that would be plausible in a genuine support interaction. Support roles are legitimately associated with technical instructions, which can shift the target into a cooperative service-recipient mindset. MFA approval, one-time codes, password resets, remote access tools, verification links, or troubleshooting steps may therefore be accepted as part of fixing the stated problem. The attacker may initiate unexpected contact, create urgency around an account lockout, compromise or service failure, and direct the target to an attacker-controlled support channel or resolution process. Common examplesservice desk, system admin, password reset team, remote support, identity team, MSP or outsourced IT, vendor support Technique boundariesHelpdesk or IT Support Impersonation is defined by the adopted support identity. Fake Support & Troubleshooting Interfaces use a deceptive technical surface, while Account Recovery Manipulation describes the identity outcome sought through a reset, unlock or recovery process. | |||
Posing as an external organisation with an existing or plausible business relationship. | Impersonation | Familiarity, Reciprocity, Trust, Scarcity | IDAFSTAVEDTMPHM |
Supplier, vendor or partner impersonation borrows the identity of an external organisation with an existing or plausible business relationship. The interaction may refer to a real project, invoice, delivery, contract, support arrangement, software service, or ongoing commercial activity so the request fits an expected third-party context. The method is commonly used to influence bank-detail changes, invoices, supplier records, deliveries, access arrangements, or portal activity. Because genuine third parties routinely request operational changes, the attacker can present a material deviation as ordinary business. Lookalike domains, known project details, delivery pressure, renewal timing, or service disruption may reinforce the supplier identity without changing the central method: the external relationship is being borrowed to legitimise the request. Common examplessupplier, contractor, MSP, SaaS provider, consultant, delivery partner Technique boundariesSupplier, Vendor or Partner Impersonation is an identity technique: the attacker claims to be a specific external organisation or relationship. Third-Party & Supply Chain Exploitation covers the broader abuse of real or assumed third-party dependencies, workflows, access, and trust without requiring direct impersonation. | |||
Posing as an official authority to manufacture fear, compliance pressure, or a sense of obligation. | Impersonation | Authority, Fear, Urgency, Obligation | IDAAVEPHM |
Authority, regulator or law enforcement impersonation adopts an official identity so the target treats the interaction as carrying legal, regulatory, investigative, or governmental weight. The attacker may present as police, a regulator, a tax authority, an auditor, a legal representative, or a government agency and use official language, case references, badge numbers, or procedural terminology to make the role appear established. The claimed authority is then used to increase the perceived cost of resistance. Threats of fines, legal action, arrest, licence consequences, or compliance failure can make immediate cooperation feel mandatory and can discourage the target from ending the call or seeking independent confirmation. The technique remains impersonation even when fear or obligation drives the response, because the attack depends on the target accepting the false official identity. Common examplesregulator, police, tax authority, legal representative, auditor, government agency, compliance body | |||
Posing as a legitimate external stakeholder to influence service, support, access, or information-handling decisions. | Impersonation | Familiarity, Social Proof, Helpfulness | AVEPHM |
Customer, client or community member impersonation presents the attacker as a legitimate external stakeholder who is entitled to service, assistance, access, or information. The claimed role may be a customer, client, patient, parent, student, resident, tenant, or member, depending on the organisation and the people who routinely interact with it. The attacker uses expectations of service and responsiveness to make an unusual request feel like a stakeholder problem that staff should solve. Loyalty, personal emergencies, emotional appeals, or a claimed critical need can be used to press for information, credits, access, account changes, or exceptions. The method is especially effective where frontline staff are expected to help quickly and where the claimed stakeholder role is easier to assert than to verify in the moment. Common examplescustomer, client, patient, parent, student, resident, member, tenant Technique boundariesCustomer, Client or Community Member Impersonation applies where the attacker falsely presents as a person entitled to a particular service, account, relationship or stakeholder status. Community or Stakeholder Affinity Exploitation uses shared affiliation or belonging without requiring that false identity. | |||
Posing as someone with a legitimate physical reason to be onsite or near assets, people, or restricted spaces. | Impersonation | Familiarity, Helpfulness | DTMPHYPHM |
Physical role impersonation adopts a plausible onsite function so the attacker appears to have a legitimate reason to be near people, assets, devices, or restricted spaces. Couriers, cleaners, technicians, inspectors, maintenance workers, contractors, and visitors are useful roles because their presence can vary by location and may not be personally known to staff. The attacker reinforces the role through clothing, equipment, deliveries, tools, confident movement, or a simple operational story. Carrying bulky items, claiming a forgotten badge, making friendly conversation, or waiting near staff entrances can turn a missing access decision into a social interaction about being helpful or keeping work moving. The technique is centred on the false role making physical presence appear expected. Common examplescourier, cleaner, technician, inspector, maintenance worker, visitor Technique boundariesPhysical Role Impersonation is defined by the false onsite role or function. Environmental Blending uses clothing, equipment, timing, movement or behaviour to fit the setting and may reinforce the impersonation. | |||
Posing as a trusted technology platform, portal, service, or digital brand. | Impersonation | Trust, Familiarity, Urgency, Scarcity | IDAMPEDTMPHM |
Digital service or platform impersonation presents a trusted technology service, portal, platform, or brand as the source of an interaction. The attacker may imitate Microsoft 365, Google, a bank, a payroll portal, a file-sharing service, an e-signature platform, or another service the target associates with routine digital tasks. Familiar service language and visual cues can make a login request, shared document, account action, or verification prompt feel service-generated rather than attacker-initiated. The target may focus on completing the expected platform action while overlooking an unfamiliar sender, shortened link, lookalike domain, or service they do not normally use. Fake notifications and specific interface artefacts may support the impersonation. Common examplesMicrosoft 365, Google, bank, payroll portal, secure file service, e-signature service, HR platform Technique boundariesDigital Service or Platform Impersonation is centred on presenting a service, brand or portal as the claimed identity. Fake Artefacts & Interface Deception techniques describe the interface, notification, link or other artefact used to drive the action and may be recorded alongside it. | |||
Using generated or altered voice, video, image, or writing to make a borrowed identity appear authentic. | Impersonation | Trust, Familiarity, Authority | IDAAVEPHM |
Synthetic media or deepfake impersonation uses generated or altered voice, video, imagery, or writing to make a borrowed identity appear directly observable. Instead of relying only on a name, address, or claimed role, the attacker creates media that resembles how a known person looks, sounds, or communicates and uses that resemblance as evidence of authenticity. The media may be combined with real names, projects, travel, business events, or other current context to make the interaction feel specific and timely. A realistic voice call, video appearance, voicemail, or writing-style imitation can support payment, access, credential, MFA, supplier, or disclosure requests while discouraging the target from questioning what appears to be familiar evidence. The technique is defined by fabricated media being central to establishing the false identity. Common examplesAI voice clone, synthetic executive video, altered voicemail, AI-generated writing style mimicry, synthetic supplier call, fake video meeting appearance, cloned authority message Technique boundariesSynthetic Media or Deepfake Impersonation applies where generated or altered media is central to establishing the claimed identity. Synthetic media may support Executive, Internal Staff, or Supplier Impersonation without becoming the primary technique when the deception would still function through the borrowed role alone. | |||
Using a genuine but compromised account or session to impersonate a trusted user, supplier, or role. | Impersonation | Trust, Familiarity | IDAAVEMPEDTMIRR |
Compromised account impersonation uses a genuine account, mailbox, collaboration profile, token, or authenticated session to act as a trusted user, supplier, executive, or role. The account may pass normal sender, domain, or platform checks because the technical identity is real, even though the person controlling the interaction is not authorised. The attacker can use existing threads, contact history, account reputation, and familiar platform context to introduce a new payment instruction, access request, portal, phone number, or approval path. Changes in tone, timing, recipients, or workflow may be easier to rationalise because the message originates from a trusted account. Common examplescompromised employee mailbox, hijacked supplier account, stolen collaboration session, compromised executive account, attacker-controlled inbox rule, OAuth-token abuse, message sent from a genuine account after credential theft Technique boundariesCompromised Account Impersonation requires use of a genuine account, mailbox, session, or authenticated identity under attacker control. Other impersonation techniques can mimic the same person or role but do not rely on control of the legitimate account itself. | |||
Using an existing or assumed relationship to make a request feel normal, safe, or expected. | Trust Exploitation | Familiarity, Trust, Social Proof | AVEPHM |
Familiar relationship exploitation uses an existing or assumed relationship to make a request feel normal, safe, or already trusted. The attacker may refer to a prior conversation, a known colleague, a long-standing supplier contact, or an established client relationship so the target interprets the interaction as continuity rather than a new trust decision. Once that continuity is accepted, the relationship can be used to normalise off-channel contact, an unusual request, or a process shortcut. Phrases such as "we have worked together for years" or references to a conversation that never occurred can make fresh verification feel unnecessary or socially awkward. Common examplescolleague request, manager follow-up, known supplier contact, familiar client message Technique boundariesFamiliar Relationship Exploitation uses a direct relationship or apparent continuity between the requester and target. Trust Transfer relies on association with another trusted person, organisation, event or relationship. | |||
Leveraging a person’s desire to be useful, responsive, polite, or service-oriented. | Trust Exploitation | Helpfulness, Reciprocity, Familiarity, Social Proof | AVEPHM |
Helpfulness exploitation targets a person's desire to be useful, responsive, polite, or service-oriented. The attacker begins with a request that appears reasonable and easy to assist with, often approaching reception, service desks, customer support, or other roles where helping people is an expected part of the job. The request may then expand into information disclosure, access, an exception, or another more sensitive action. Statements that the target is "the only person who can help" or that refusing would create hardship can make normal boundaries feel obstructive or unkind. The method uses the target's own service instinct to increase cooperation before the sensitivity of the request is fully reassessed. Common examplesreception call, service desk request, customer support interaction, visitor assistance, holding a secure door for someone carrying items Technique boundariesHelpfulness Exploitation describes the use of a person’s desire to assist. Tailgating & Piggybacking describes entry through another person’s authorised access. Both may apply where an attacker uses an apparent need for assistance to pass through a controlled entry point. | |||
Establishing personal connection or friendly familiarity before making a more sensitive request. | Trust Exploitation | Familiarity, Trust | AVEPHM |
Rapport building establishes personal connection or friendly familiarity before the attacker introduces a more sensitive request. The contact may begin through casual conversation, social media, a conference interaction, or a recruiter-style approach and use shared interests, flattery, background details, or informal communication to create a sense of easy connection. The relationship is deliberately developed ahead of the operational ask. A target who has already exchanged personal details, jokes, professional interests, or repeated messages may be less likely to treat the later request as coming from a stranger. The method becomes visible when friendly continuity shifts into requests for information, files, introductions, access, or off-channel activity without a natural reason for the escalation. Common examplescasual conversation, social media contact, conference interaction, recruiter-style approach Technique boundariesRapport Building establishes familiarity before a later request. Long-Game Relationship Cultivation extends this method over a sustained period and may develop dependency, emotional investment, or a persistent synthetic persona; Gradual Trust Escalation is defined by the increasing sensitivity of requests rather than the relationship-building phase alone. | |||
Abusing trust placed in professional roles, expertise, or business relationships. | Trust Exploitation | Authority, Trust | AVEPHM |
Professional trust exploitation uses the credibility attached to expertise, qualifications, a recognised professional role, or an established engagement. Consultants, auditors, technicians, lawyers, recruiters, and managed service providers may legitimately ask detailed questions or request documents within their authorised scope. The technique arises where that professional credibility is used to make a request appear appropriate without adequate confirmation of its scope, authority or purpose. Technical language, confidentiality, name-dropping, or reference to a genuine engagement can make scrutiny feel like interference with professional work. Where the attacker adopts a false professional identity, the applicable impersonation technique may also apply. Common examplesconsultant, auditor, technician, legal contact, recruiter, managed service provider Technique boundariesProfessional Trust Exploitation concerns credibility attached to expertise, professional standing or an established engagement. Where a false professional role is adopted, the applicable impersonation technique should also be recorded. | |||
Using shared membership, affiliation, values, or belonging to lower scrutiny without necessarily adopting another person’s identity. | Trust Exploitation | Familiarity, Social Proof | AVEPHM |
Community or stakeholder affinity exploitation uses shared membership, affiliation, values, or belonging to make an interaction feel socially credible. The attacker may refer to a school community, professional association, resident group, customer community, member base, cause, or other population with which the target identifies. The claimed affinity can make requests for introductions, information, exceptions, access, or assistance feel like cooperation with someone from the same group. Community-specific language and knowledge may reinforce the connection. The technique does not require the attacker to claim another person’s identity; false presentation as a particular customer, patient, parent, student, tenant, or member remains Customer, Client or Community Member Impersonation. Common examplesshared community membership, alumni connection, professional association, resident or member affiliation, shared cause or values Technique boundariesCommunity or Stakeholder Affinity Exploitation uses shared affiliation or belonging as the source of trust. Customer, Client or Community Member Impersonation applies where the attacker falsely presents as a person entitled to a particular service, account, relationship or stakeholder status. | |||
Developing trust through low-risk interactions before introducing progressively more sensitive requests. | Trust Exploitation | Trust, Familiarity | AVEDTM |
Gradual trust escalation develops credibility through low-risk interactions before the attacker introduces more sensitive requests. Early contact may involve ordinary conversation, harmless questions, useful information, or a minor task that gives the target little reason to challenge the relationship. As trust develops, the requests move toward documents, protected data, payments, access, credentials, or approval. The defining mechanism is the growth of trust before the escalation. Gradual Commitment Escalation applies where the target’s earlier participation or investment is used to make withdrawal harder. Common examplesconfirming names, requesting process details, asking for documents, requesting access or approval Technique boundariesGradual Trust Escalation is defined by trust developing before requests become more sensitive. Gradual Commitment Escalation is defined by prior participation, consistency pressure or accumulated involvement making disengagement more difficult. | |||
Borrowing legitimacy from a trusted person, organisation, brand, event, supplier, or relationship. | Trust Exploitation | Social Proof, Trust, Familiarity | FSTAVEDTMPHM |
Trust transfer borrows legitimacy from a trusted person, organisation, brand, event, supplier, or relationship and applies it to the attacker. Claims such as “referred by”, “introduced by”, “working with”, “associated with”, or “following up from” encourage the target to treat another party’s credibility as evidence that the current contact is legitimate. The attacker may name a colleague, partner, supplier, event, or existing project and use signatures, logos, titles, or familiar phrasing to strengthen the association. The method does not require the attacker to impersonate the trusted source directly. Claims that another person approved, authorised or directed the action are instead Delegated Authority Abuse. Common examples“referred by”, “introduced by”, “working with”, “associated with”, “following up from” Technique boundariesTrust Transfer borrows legitimacy from an association with another person, organisation, event or relationship. Delegated Authority Abuse specifically claims that an authority approved, authorised or directed the action. | |||
Sustaining a relationship over time so later requests feel earned, safe, or expected. | Trust Exploitation | Familiarity, Trust, Commitment | AVEPHM |
Long-game relationship cultivation sustains a relationship over an extended period so a later request feels earned, safe, or expected. The attacker may maintain a romantic, professional, recruiter, investment, or social persona for weeks or months without making an obvious early request, investing time and personalisation in the continuity of the contact. Harmless conversation can gradually move toward money, access, identity, recruitment, documents, or sensitive information once the relationship itself has become evidence of trustworthiness. Shared values, affection, career opportunity, or personal understanding may be reinforced while official channels and outside validation are avoided. The long duration is central to the method: the attacker allows trust history to accumulate before using it operationally. Common examplesromance or pig-butchering approach, fake recruiter pipeline, long-running social media grooming, long-running professional grooming, AI chat companion, synthetic persona maintained over time Technique boundariesLong-Game Relationship Cultivation is distinguished from ordinary Rapport Building by sustained relationship maintenance and delayed exploitation. Affection & Emotional Attachment Development is defined by emotional attachment and may occur within a long-running relationship. | |||
Using an existing thread, channel, cadence, or routine to make a changed request feel already trusted. | Trust Exploitation | Familiarity, Trust | IDAFSTAVEMPEDTM |
Trusted channel or routine exploitation uses a familiar communication channel, recurring cadence, or established business rhythm to make a changed request feel already trusted. The target recognises the surrounding interaction, such as an invoice cycle, recurring approval, supplier follow-up, or collaboration channel, and may apply less scrutiny to the latest instruction. The attacker introduces a new destination, attachment, portal, approver, account, or contact path inside that familiar routine. Language such as “same as last time” or “as per the usual process” can encourage momentum rather than fresh verification. Insertion into a genuine conversation history is Thread Hijacking & Authentic-Context Insertion. Common examplesrecurring-invoice rhythm, expected-approval cadence, routine supplier follow-up, familiar collaboration-channel request, “as per our usual process” Technique boundariesTrusted Channel or Routine Exploitation relies on a familiar channel, cadence or routine and does not require insertion into a genuine conversation. Thread Hijacking & Authentic-Context Insertion uses authentic conversation history itself. | |||
Using executive seniority or leadership status to pressure rapid action or bypass scrutiny. | Authority & Obligation Pressure | Authority, Fear, Urgency, Displaced Responsibility | GOVAVEPHM |
Executive authority pressure uses seniority or leadership status to make rapid action feel expected and challenge feel professionally risky. The attacker invokes a CEO, board member, executive, or senior manager and frames the request as something that has already been decided at a level above the target. Direct orders, brusque language, personal attention from a senior title, or statements that the matter is "not up for discussion" can narrow the target's perceived room to question the request. The method does not require the attacker to impersonate the executive directly; it relies on executive status being used as pressure to bypass approval, payment, access, or procurement scrutiny. Common examplesCEO request, executive payment approval, urgent board request, senior manager escalation Technique boundariesExecutive Authority Pressure uses the power associated with seniority to compel action and does not require the attacker to claim a false executive identity. Executive or Senior Leader Impersonation is classified under Impersonation when adoption of the senior identity is the primary method. | |||
Exploiting ordinary reporting lines, supervisory authority, or chain-of-command expectations below executive level. | Authority & Obligation Pressure | Authority, Obligation, Displaced Responsibility | GOVAVEPHM |
Organisational hierarchy pressure exploits ordinary reporting lines and chain-of-command expectations below executive level. A manager, supervisor, department head, team lead, or other internal authority is presented as having the power to direct the target, approve the action, or escalate non-cooperation. The request is framed as an instruction moving through the hierarchy rather than as a new action requiring independent assessment. The target may be encouraged to believe that the decision belongs to the manager or reporting line and that they are responsible only for execution. Executive or board-level pressure is classified as Executive Authority Pressure. Common examplesmanager request, supervisor instruction, department head request, team lead escalation Technique boundariesOrganisational Hierarchy Pressure applies to managers, supervisors, team leads and ordinary reporting lines. Executive Authority Pressure applies where executive, board or senior organisational leadership status is the source of pressure. | |||
Using perceived legal, compliance, regulatory, or enforcement authority to compel action. | Authority & Obligation Pressure | Authority, Fear, Obligation | GOVAVEPHM |
Regulatory or legal pressure uses perceived legal, compliance, regulatory, or enforcement authority to compel action. The interaction may reference statutes, case numbers, audit obligations, formal notices, police powers, tax requirements, or regulatory consequences so the request appears to sit outside ordinary organisational discretion. The target may be told that delay will create fines, legal action, licence consequences, or another formal breach and that standard verification cannot be allowed to slow the matter. The method can support requests for records, payments, personal data, access, or credentials. Its central mechanism is the target treating a claimed legal or regulatory obligation as binding before the request has been independently established. Common examplesregulator contact, compliance audit request, legal notice, police or government request Technique boundariesRegulatory or Legal Pressure is centred on perceived legal, compliance, or enforcement consequence. Authority, Regulator or Law Enforcement Impersonation applies when the attacker adopts the false official identity itself as the primary method. | |||
Framing action as part of professional duty, organisational responsibility, or role expectation. | Authority & Obligation Pressure | Obligation, Commitment, Authority | GOVAVEPHM |
Duty and responsibility exploitation frames the requested action as part of the target's professional role, organisational responsibility, or expected contribution. The attacker does not need a powerful title if they can make refusal feel like neglecting a duty the target already believes they hold. Statements such as "this is your responsibility", "you are the only person who can handle this", or "we all need to step up" can tie compliance to professional pride and role identity. An unusual action may be described as simply part of the process or necessary for operations. The method works by making verification feel obstructive, disloyal, or inconsistent with being competent and dependable. Common examples“this is your responsibility”, “we need you to handle this”, “required for operations” | |||
Leveraging fear of non-compliance, policy breach, disciplinary action, or operational failure. | Authority & Obligation Pressure | Fear, Obligation, Authority | GOVAVEPHM |
Compliance expectation manipulation leverages fear of breaking policy, failing an audit, attracting disciplinary action, or creating an operational compliance issue. The attacker uses the language of HR, security, policy enforcement, or mandatory controls so the target believes the safest course is to complete the requested step immediately. Fake breach notices, security warnings, or compliance records can demand credential entry, information, or another action that a legitimate control would not normally require. The target's desire to follow rules is turned against the rule-checking process itself. The method is effective when compliance language makes authenticity checks feel secondary to avoiding a recorded failure. Common examplesHR escalation, security warning, policy breach notice, compliance enforcement request Technique boundariesCompliance Expectation Manipulation uses fear of breach, discipline, audit failure or non-compliance to pressure action. Security & Compliance Framing uses security, governance or compliance language primarily as a cue of legitimacy. | |||
Using claimed authority or organisational standing to threaten or initiate an adverse consequence if the target does not comply. | Authority & Obligation Pressure | Authority, Fear, Urgency | GOVAVEPHM |
Authority-backed consequence pressure uses claimed organisational, professional, legal, or commercial standing to make a threatened consequence credible. The requester presents themselves, or an authority they represent, as able to initiate disciplinary action, escalation, service restriction, a formal complaint, or another adverse outcome if the target does not comply. The target is encouraged to focus on the requester’s apparent power to impose the outcome rather than on whether the underlying action is authorised. Consequence of Delay Framing presents harm as the result of waiting or inaction without requiring the requester to claim power over the consequence. Common examplesmanagerial escalation, disciplinary referral, formal complaint, supplier penalty, executive dissatisfaction Technique boundariesAuthority-Backed Consequence Pressure requires claimed authority or standing to impose, initiate or escalate the consequence. Consequence of Delay Framing presents an adverse outcome as the result of delay or inaction, while Coercion, Threat & Extortion Pressure uses direct threatened harm to force compliance. | |||
Claiming to act on behalf of a trusted authority or decision-maker. | Authority & Obligation Pressure | Authority, Social Proof, Trust, Displaced Responsibility | GOVAVEPHM |
Delegated authority abuse claims that a trusted decision-maker has already approved, requested, or authorised an action. The attacker may say they are acting for the CEO, finance, legal, a director, or another authority and use the named person's status to give weight to a request they are not personally entitled to make. The delegation is often difficult to verify because the named authority is said to be unavailable, busy, travelling, or protected by confidentiality. Urgency can then be used to make direct confirmation appear unnecessary or disrespectful. The method borrows authority without adopting the authority figure's identity, making the claimed relationship between requester and decision-maker the key source of legitimacy. Common examples“approved by the CEO”, “acting for finance”, “requested by legal”, “on behalf of the director” Technique boundariesDelegated Authority Abuse claims that another person approved, authorised or directed the action. Trust Transfer borrows legitimacy from association with another person or relationship without necessarily claiming delegated decision authority. | |||
Creating a short deadline to encourage rapid action before normal verification occurs. | Urgency, Scarcity & Consequence Framing | Urgency, Fear, Scarcity | GOVAVE |
Time pressure creates a short deadline so the target acts before normal verification or consultation occurs. The attacker frames the request as expiring within minutes, hours, or by close of business and presents delay itself as the main risk. Countdowns, rapid follow-ups, same-day approval demands, or claims that there is no time for the usual process can compress the target's decision window. The deadline may be arbitrary or disproportionate to the task, but the target is kept focused on completing the action before the stated cut-off. The method works by making the cost of pausing feel greater than the value of checking. Common examplesexpiring document, immediate payment request, urgent approval, same-day deadline Technique boundariesTime Pressure applies where a shortened decision window is the main mechanism. Other urgency or consequence techniques may also apply when the deadline is supported by an emergency, scarcity or threatened outcome. | |||
Presenting time, access, availability, capacity, or choice as limited so the target acts before normal review occurs. | Urgency, Scarcity & Consequence Framing | Scarcity, Urgency, Fear | AVEPHM |
Scarcity framing presents time, access, availability, capacity, or choice as limited so the target feels that delay will remove the option to act. The attacker may claim that only one slot, approval window, allocation, access period, or limited quantity remains. The technique narrows the target’s perceived alternatives and encourages immediate engagement before comparison or verification. Where the limited item is itself a prize, career opportunity, community invitation, or financial benefit, the applicable incentive technique may also apply. Common exampleslimited access window, single remaining slot, closing registration period, expiring approval window Technique boundariesScarcity Framing reduces the perceived time, availability or choice surrounding an action. Scarcity & Exclusivity Incentives increase the appeal of a benefit by presenting it as limited or selective. | |||
Presenting the situation as an emergency that requires immediate exception handling. | Urgency, Scarcity & Consequence Framing | Fear, Urgency, Obligation, Authority | GOVAVE |
Emergency framing presents the situation as a crisis that requires immediate exception handling. The attacker introduces a payroll failure, executive emergency, travel problem, legal crisis, health event, account lockout, or other high-stakes story and makes ordinary procedure appear too slow for the circumstances. Personal detail and urgency can make the emergency feel specific and emotionally credible, while the lack of time is used to justify bypassing logging, approval, or verification. The requested action may involve payments, gift cards, account changes, access, or supplier details. The method works by moving the target into crisis response mode before the claimed emergency has been independently established. Common examplespayroll emergency, executive emergency, gift card emergency, urgent travel issue Technique boundariesEmergency Framing uses a real or claimed urgent event to justify immediate or exceptional action. Manufactured Crisis Framing fabricates the problem and then supplies an attacker-controlled resolution path. | |||
Using after-hours, weekend, holiday, or low-staffing periods while claiming that the action cannot wait for normal personnel or processes. | Urgency, Scarcity & Consequence Framing | Urgency, Fear, Scarcity | GOVAVE |
Out-of-hours and low-staffing pressure uses nights, weekends, holidays, or other reduced-coverage periods and claims that the action cannot wait for normal personnel or processes. The attacker times the request for a period when approvers, specialists, or established verification paths may be unavailable. A late payment change, access issue, supplier request, or account recovery may be framed as something the available target must resolve alone before ordinary coverage resumes. The technique requires more than unusual timing; the reduced staffing or unavailable process is used as pressure to act. Common exampleslate-night executive request, weekend payment change, holiday access request, low-staffing support issue Technique boundariesOut-of-Hours & Low-Staffing Pressure applies where reduced coverage is actively used to justify action before normal personnel or processes return. Event & Operational Timing Collection describes gathering that timing information during reconnaissance. | |||
Increasing the intensity, seriousness, urgency, or threatened consequence after hesitation, refusal, or attempted verification. | Urgency, Scarcity & Consequence Framing | Urgency, Fear, Obligation | GOVAVEPHM |
Escalation pressure increases intensity after hesitation, non-response, refusal, or an attempt to verify the request. The attacker treats delay as a problem to overcome and uses repeated contact or a changing tone to push the target back toward action. Multiple messages, rapid calls, personal mobile contact, demands for progress, or threats to involve a director can make continued resistance feel increasingly costly. The pressure is often triggered specifically by the target trying to follow process. The method uses persistence and rising social friction to wear down the pause that initially protected the target. Common examplesrepeated calls, follow-up messages, “why hasn’t this been done”, escalating tone Technique boundariesPressure Escalation After Resistance increases the seriousness, tone, urgency or threatened consequence following hesitation or challenge. Pressure Persistence relies on repeated prompts or requests without necessarily increasing their severity, while Authority-Backed Consequence Pressure relies on claimed power to impose the outcome. | |||
Presenting delay or inaction as likely to cause operational disruption, financial loss, loss of access, reputational harm, legal exposure, or another adverse outcome. | Urgency, Scarcity & Consequence Framing | Fear, Urgency, Obligation | GOVAVEPHM |
Consequence of delay framing presents waiting, checking, or failing to complete the action as likely to cause an adverse outcome. The claimed consequence may involve operational disruption, financial loss, loss of access, reputational harm, legal exposure, service interruption, or harm to a client or supplier. The attacker makes the target feel responsible for preventing that outcome and portrays verification as the action that could cause it. The requester does not need to claim personal power to impose the consequence. Authority-Backed Consequence Pressure applies where the requester’s claimed standing makes the threatened outcome credible, while Coercion, Threat & Extortion Pressure involves direct threatened harm. Common examplesservice disruption, missed payment or deadline, loss of access, client or supplier impact, legal or reputational exposure Technique boundariesConsequence of Delay Framing presents an adverse outcome as the result of waiting or inaction. Authority-Backed Consequence Pressure relies on claimed authority to impose or initiate the outcome. Manufactured Crisis Framing fabricates a problem and supplies the supposed resolution. | |||
Fabricating a crisis and positioning an attacker-supplied action, channel, or process as the resolution. | Urgency, Scarcity & Consequence Framing | Fear, Urgency, Authority | GOVAVEPHM |
Manufactured crisis framing begins by inventing a problem that the target is expected to treat as real. The attacker may claim fraud, account compromise, a system outage, legal exposure, or a compliance failure, then immediately position a supplied link, portal, support number, payment path, or approval route as the way to resolve it. The method compresses the target’s decision around the alleged emergency. Fear and urgency make delay feel dangerous, while the attacker’s proposed resolution appears practical because it is presented as part of the same crisis response. Timing the contact around operational stress, after-hours coverage, finance close, or incident activity can make the fabricated problem easier to accept before its existence is independently established. Common examplesfake fraud or security alert, bogus account-compromise warning, invented system outage, false legal or compliance breach, we've detected suspicious activity Technique boundariesManufactured Crisis Framing fabricates the problem and then directs the target toward an attacker-controlled action, channel or resolution. Emergency Framing uses a real or claimed urgent event without requiring the attacker to have created the problem. | |||
Applying repeated prompts, requests, or follow-ups to wear down resistance through volume and fatigue. | Urgency, Scarcity & Consequence Framing | Cognitive Load, Urgency, Fear | AVEPHM |
Pressure persistence uses repetition as the mechanism of influence. The attacker continues sending prompts, approval requests, calls, messages, or follow-ups after silence, delay, or refusal, treating resistance as temporary rather than as a stop signal. The individual request may not become more convincing or threatening. Instead, volume, interruption, and timing create fatigue until the target accepts the action, makes an error, or responds simply to clear the repeated disruption. The technique can move across channels or cluster around busy periods so the pressure remains active when one contact path fails. Common examplesMFA prompt bombing, repeated approval requests, persistent follow-up until the target relents, approval fatigue Technique boundariesPressure Persistence uses repeated prompts or requests to create attrition and may occur through one channel. Cross-Channel Communication Saturation uses clustered or simultaneous contact across several channels. Control Fatigue Exploitation takes advantage of an already overloaded operating environment. | |||
Requesting that a normal approval, verification, or workflow step be skipped. | Process Manipulation | Urgency, Authority, Opportunity | GOVAVE |
Process bypass request asks the target to skip a normal approval, verification, form, ticket, or workflow step. The attacker presents the deviation as temporary, harmless, or necessary for speed, using language such as "just this once", "we can add the paperwork later", or "there is no time for the usual process". The method relies on the target treating the control as administrative friction rather than part of the authorisation decision. A manual action, direct approval, or undocumented workaround can then be used to reach payments, access, identity changes, assets, or sensitive data. The process is not attacked technically; the attacker persuades a person to suspend it on their behalf. Common examples“can we do this manually”, “skip the form”, “approve it directly”, “just this once” Technique boundariesProcess Bypass Request asks someone to omit or suspend a required step. Exception Handling Abuse invokes an existing exception, override or emergency pathway under false or misleading circumstances. Convenience & Shortcut Lures make an easier or faster route attractive. Process Bypass Request describes the requested omission of the required step. | |||
Exploiting edge cases, urgent exceptions, or unclear exception pathways. | Process Manipulation | Urgency, Fear, Obligation | GOVAVE |
Exception handling abuse targets edge cases, urgent exceptions, or poorly defined override pathways. The attacker claims that the normal process cannot accommodate the situation and that an emergency, unusual circumstance, or after-hours problem requires an immediate manual exception. The request may concern access, payments, credential resets, supplier changes, or data release and is often directed at a time when the normal exception owner is unavailable. Vague justification, resistance to documentation, or repeated "one-off" exceptions can keep the action outside formal review. The method exploits the organisation's need to handle legitimate exceptions by presenting the malicious request as one of them. Common examplesemergency access, urgent payment change, after-hours access, manual override Technique boundariesException Handling Abuse uses a legitimate exception, override or emergency route under false or misleading circumstances. Process Bypass Request asks for a required step to be skipped without using an established exception path. | |||
Targeting payment destinations, payroll records, invoices, supplier records, or bank-detail change processes. | Process Manipulation | Authority, Urgency, Trust, Familiarity | GOVFSTAVEDTM |
Payment or supplier change manipulation targets the workflows used to alter bank details, payroll records, invoices, supplier information, or payment destinations. The attacker introduces a change that appears commercially routine and attempts to move it through finance or procurement before the new details are independently established. Lookalike domains, compromised supplier accounts, fake invoices, portal links, service-disruption stories, or payment-run timing can make the change feel expected. The request may deliberately bypass supplier master-data checks, callbacks, or dual approval. The method is centred on manipulating the change process itself so an attacker-controlled financial destination is treated as an authorised business update. Common examplessupplier bank-detail change, payroll account change, invoice amendment, payment redirection, supplier master-data update | |||
Exploiting onboarding, reactivation, role-change, temporary-access, offboarding-reversal, or privileged-access provisioning workflows. | Process Manipulation | Authority, Familiarity, Trust, Urgency | GOVIDAAVEDTMIRRPHM |
Access provisioning workflow manipulation exploits onboarding, reactivation, role change, temporary access, offboarding reversal, or privileged-access provisioning processes. The attacker frames missing paperwork, ownership, or approval as an administrative delay and presents access as operationally necessary before the formal process catches up. A new starter, returning employee, contractor, project, or role-change story may be supported with a real manager’s name or a plausible business need. The technique is centred on manipulating the organisational provisioning workflow. Access & Consent Approval Manipulation applies where a user or approver is persuaded to approve a specific consent grant, share, privilege or access-enabling action. Common examplesnew starter access, temporary access, role change, access reactivation, offboarding reversal, privileged access Technique boundariesAccess Provisioning Workflow Manipulation concerns onboarding, reactivation, role change, temporary access, offboarding reversal and other provisioning processes. Access & Consent Approval Manipulation concerns a specific approval or consent action that creates access. | |||
Using, altering, expanding, or redirecting a genuine ticket, case, queue, or workflow record to create legitimacy or drive an unauthorised action. | Process Manipulation | Social Proof, Trust, Familiarity | GOVAVEDTM |
Existing ticket or workflow abuse uses a genuine ticket, case, queue, or workflow record and changes, expands, redirects, or misrepresents the action associated with it. The valid record gives the interaction a real process anchor even though the new request is not supported by the original scope or approval. A real support ticket may be escalated into credential or access activity, a genuine finance case may be redirected to new payment details, or an existing facilities request may be used to justify additional access. Fabricated Workflow Evidence applies when the record or proof itself is counterfeit, while Workflow & Process Mirroring imitates the expected sequence without using a genuine record. Common examplesgenuine support ticket expanded into a sensitive request, real case redirected to a new destination, existing workflow record altered, legitimate queue item used to introduce a changed action Technique boundariesExisting Ticket or Workflow Abuse requires a genuine workflow record. Fabricated Workflow Evidence supplies counterfeit proof, while Workflow & Process Mirroring imitates the appearance or sequence of a workflow. | |||
Exploiting the order, substitution, scope, or completion state of approvals so an action proceeds without the intended decision path. | Process Manipulation | Displaced Responsibility, Authority, Urgency | GOVAVEDTM |
Approval sequence manipulation exploits the order, substitution, scope, or completion state of approvals. The attacker may replace an approver, begin execution before approval is complete, treat partial approval as approval of the whole action, split a request to avoid a threshold, or use an unavailable approver to justify an alternative path. The target is encouraged to believe that the decision belongs elsewhere and that they are responsible only for the next operational step. Delegated Authority Abuse concerns a claim that another authority approved or directed the action, while Fabricated Workflow Evidence provides counterfeit proof of an approval or workflow state. Common examplesapprover substitution, execution before approval, partial approval treated as complete, request split below an approval threshold, unavailable approver bypass Technique boundariesApproval Sequence Manipulation targets the structure, order, substitution or scope of the approval path. Delegated Authority Abuse claims that another authority approved or directed the action, and Fabricated Workflow Evidence supplies counterfeit proof. | |||
Exploiting uncertainty about who owns a process, decision, request, or escalation path. | Process Manipulation | Displaced Responsibility, Helpfulness, Obligation | GOVAVE |
Process ownership confusion exploits uncertainty about which team, person, provider, or role owns a request or escalation path. The attacker moves between functions and uses organisational hand-offs to make the current staff member feel responsible for resolving a matter that lacks a clear owner. Statements such as “HR told me to contact IT” or “finance said this sits with your team” can make the target reluctant to appear unhelpful. Shared queues, outsourced services, and poorly documented boundaries increase the room to keep searching for someone willing to act. The method shifts responsibility across hand-offs without establishing a valid authorisation path. Common examplesunclear handoff, “finance said IT handles it”, “HR told me to contact you” | |||
Targeting busy, overloaded, repetitive, or high-volume process environments where review quality may drop. | Process Manipulation | Cognitive Load, Urgency | GOVAVE |
Control fatigue exploitation targets busy, repetitive, high-volume, or overloaded process environments where review quality may fall. The attacker times or shapes the request so it resembles one more routine item in a queue during month-end, payroll cut-off, enrolment, incident response, outages, or helpdesk backlogs. A slightly abnormal change can be hidden among ordinary work, and several low-risk actions may be bundled around one higher-risk request. The method takes advantage of existing organisational load. Pressure Persistence creates repeated prompts or requests itself, while Cross-Channel Communication Saturation creates clustered contact across several channels. Common examplesmonth-end finance pressure, helpdesk queue overload, enrolment period, incident surge Technique boundariesControl Fatigue Exploitation takes advantage of an already overloaded queue or operating period. Pressure Persistence creates repeated prompts or requests, while Cross-Channel Communication Saturation creates clustered or simultaneous contact across several channels. | |||
Supplying counterfeit process artefacts to make a request appear already approved or in workflow. | Process Manipulation | Authority, Social Proof, Trust | GOVAVEDTMPHM |
Fabricated workflow evidence gives the target counterfeit proof that a request has already passed through a legitimate process. The attacker may supply a forged approval email, ticket number, purchase order, form, screenshot, or recycled workflow reference so the current action appears to be the next routine step rather than a new decision. The method transfers credibility from the artefact to the request. A plausible record can make staff assume that another person has already checked the identity, authority, scope, or approval, particularly when the evidence resembles familiar internal templates or arrives under time pressure. The attacker is therefore manufacturing process state, not merely claiming that approval exists. Common examplesforged approval email, fabricated or recycled ticket number, doctored form, screenshot of a non-existent authorisation, fake purchase order Technique boundariesFabricated Workflow Evidence supplies counterfeit proof of a workflow, ticket, approval or process state. Approval Sequence Manipulation exploits the order, scope or completion state of a real approval path. Fake Artefacts & Interface Deception may also apply where a deceptive document or interface carries the false evidence. | |||
Gathering publicly available information about people, organisations, systems, suppliers, or operations. | Information Harvesting | IEXPHM | |
Open-source intelligence collection gathers publicly available information about people, organisations, systems, suppliers, and operations. The attacker uses social media, corporate websites, job advertisements, public documents, conference material, procurement notices, and other open sources to build context without directly approaching the target. Individual details such as job titles, travel, projects, technology names, email formats, suppliers, or internal terminology may appear harmless in isolation. Their value comes from aggregation: the attacker can combine them into a more specific pretext, select a better target, identify a trusted relationship, or time a later approach around real organisational activity. The method turns public exposure into operational context for subsequent social engineering. Common examplesLinkedIn review, social media profiling, website review, job advertisements, public documents | |||
Collecting information about workflows, approvals, reporting lines, systems, or operational procedures. | Information Harvesting | IEX | |
Organisational process reconnaissance collects information about workflows, approvals, reporting lines, systems, and operational procedures. The attacker asks how things work rather than asking for the high-value action directly, often approaching reception, helpdesk, finance, HR, procurement, or facilities with an innocent-sounding procedural question. Questions about laptop requests, purchase orders, ticketing systems, payroll cycles, callback procedures, or hand-off points can reveal where control decisions occur and who owns them. Multiple departments may be contacted to compare answers and map gaps between teams. The method uses low-risk process curiosity to identify the route a later pretext should follow or bypass. Common exampleshelpdesk process probing, finance workflow questions, reception enquiries, support process discovery | |||
Identifying trusted relationships, reporting structures, suppliers, teams, or external contacts. | Information Harvesting | IEXPHM | |
Relationship and trust mapping identifies the people, teams, suppliers, service providers, approvers, assistants, gatekeepers, banks, legal firms, couriers, payroll providers, and other external contacts that carry influence or legitimacy around an organisation. The attacker seeks to understand who knows whom, who owns which relationship, and which contacts a target is likely to recognise. Names and connections may be collected through organisational charts, public sources, reception calls, role-based questions, or direct enquiries. The resulting map can support referrals, delegated-authority claims, supplier impersonation, third-party access abuse, or target selection. The technique describes the relationship information being collected, regardless of whether the source is public, conversational, physical, or leaked. Common examplessupplier and service-provider mapping, executive assistant identification, organisational chart collection, external approver and account-owner mapping | |||
Collecting information through physical presence, observation, or environmental exposure. | Information Harvesting | DTMPHYIEX | |
Physical observation and environmental reconnaissance gathers information through presence, sight, and exposure to the workplace or surrounding environment. The attacker observes badge use, entry routines, office layout, visitor flow, screens, whiteboards, printer trays, conversations, and other physical cues that reveal how the organisation operates. Lobbies, cafés, loading areas, smoking zones, shared offices, public transport, and conference spaces can provide access to information without formal entry into a restricted system. Photos, repeated observation, or casual loitering may reveal door timings, badge design, sensitive material, or opportunities for tailgating and shoulder surfing. The method converts ordinary environmental visibility into planning detail for later interaction or access. Common examplesbadge observation, shoulder surfing, office layout observation, visitor flow analysis | |||
Using informal conversation or low-risk interaction to collect contextual information. | Information Harvesting | Familiarity, Helpfulness, Reciprocity | IEX |
Casual information elicitation uses informal conversation or a low-risk interaction to obtain contextual information without making the collection objective obvious. The attacker may approach through networking, a conference, reception, a support chat, or another setting where curiosity and professional conversation are normal. Shared interests, compliments, industry topics, or questions about current work can gradually steer the target toward projects, systems, suppliers, upcoming events, or internal practices. The conversation may feel natural enough that the target only recognises the amount disclosed afterward. The method uses social ease to collect information in fragments rather than asking for obviously sensitive material. Common examplesconference conversation, reception discussion, networking event interaction, support chat Technique boundariesCasual Information Elicitation is an information-harvesting method in which conversation is used to obtain details without making the collection purpose explicit. Elicitation-like rapport or helpfulness techniques may support the conversation, but the defining objective here is acquisition of information. | |||
Collecting usernames, account formats, identity providers, MFA methods, authentication portals, or recovery-process information. | Information Harvesting | IDADTMIEX | |
Identity and authentication reconnaissance collects usernames, email formats, employee identifiers, identity providers, MFA methods, authentication portals, naming conventions, and recovery-process details. The attacker seeks the information needed to make a later credential, recovery, or impersonation attempt fit the organisation’s actual identity environment. The information may be obtained through public login pages, helpdesk questions, address checks, error messages, documentation, or other reconnaissance. The technique is preparatory and does not require a direct manipulation interaction. Where conversation is used to obtain the information, Casual Information Elicitation may also apply. Common examplesemail and username formats, login portal identification, identity-provider discovery, MFA method discovery, recovery-process mapping Technique boundariesIdentity & Authentication Reconnaissance concerns identity structure, account formats, authentication methods and recovery processes. Digital Presence Profiling concerns the broader technology platforms, cloud services, vendors and technical environment used by the organisation. | |||
Collecting discarded, exposed, printed, shared, or improperly secured information assets. | Information Harvesting | MPEDTMPHYIEX | |
Document and artefact collection gathers information from discarded, exposed, printed, shared, or poorly secured physical material. The attacker may retrieve printouts, search waste or recycling, photograph whiteboards, collect badges or sticky notes, or access meeting and printer areas where organisational information is left behind. Artefacts can reveal names, projects, schedules, suppliers, systems, access levels, contact details, or internal language that later strengthen a pretext. Physical roles such as cleaner, courier, maintenance worker, or facilities staff may be adopted to reach waste, storage, desks, or print areas. The method uses the organisation's own material as a source of authentic context. Common examplesdumpster diving, printer collection, exposed documents, screenshots, whiteboard capture Technique boundariesDocument & Artefact Collection applies where documents, records or other organisational material are obtained, copied or captured. Physical Observation & Environmental Reconnaissance applies where the primary activity is observing the environment, routines or physical security conditions. | |||
Identifying technology platforms, cloud services, vendors, security tooling, or communication methods. | Information Harvesting | DTMIEX | |
Digital presence profiling identifies the technology platforms, cloud services, vendors, security tooling, and communication methods used by an organisation. Public login portals, DNS records, certificates, job descriptions, vendor pages, code repositories, scripts, status pages, and technical documentation can all expose useful clues. The attacker builds a technology profile that shows which services and interfaces a target is likely to recognise. Knowledge of an HR platform, VPN, collaboration service, MSP, or authentication product can guide later phishing, platform impersonation, fake support, or access attempts. The method is not direct exploitation of the technology; it is collection of technical context for a more credible social interaction. Common examplesMicrosoft 365 usage, VPN platform identification, collaboration platform discovery Technique boundariesDigital Presence Profiling concerns the organisation’s broader technology environment, services, vendors and platforms. Identity & Authentication Reconnaissance concerns usernames, account formats, identity providers, MFA methods and recovery processes. | |||
Gathering information about schedules, staffing, travel, meetings, projects, deadlines, or operational cycles. | Information Harvesting | IEX | |
Event and operational timing collection gathers schedules, staffing patterns, travel, meetings, project milestones, deadlines, and recurring business cycles. The attacker seeks to learn when normal oversight will be reduced or when a later urgent request will fit real organisational activity. Executive travel, holiday staffing, support rosters, reception hours, payroll dates, payment runs, project launches, and security shift changes can all influence attack timing. The information may be obtained through conversation, public posts, calendars, or repeated observation. The method uses genuine timing to make later urgency, absence, or out-of-hours pressure feel plausible. Common examplesexecutive travel schedule, holiday staffing, payroll cycle, project launch timing Technique boundariesEvent & Operational Timing Collection gathers timing information. Timing & Operational Context Mirroring uses known timing to make a later interaction appear plausible. | |||
Using data from prior breaches, leaks, or stealer logs to accelerate targeting, impersonation, or identity abuse. | Information Harvesting | IDADTM | |
Breach and leak data aggregation uses information exposed by earlier compromise or non-public leakage as reconnaissance material. The attacker collects leaked credentials, old passwords, usernames, personal details, stealer logs, combolists, or paste-site content and combines them into a targeting picture without needing to gather each detail directly from the current target. Fragments from different sources can be used to validate identities, predict account formats, strengthen impersonation, support credential reuse, or make later contact appear unusually informed. The data may be stale or incomplete, but accurate details can shorten reconnaissance and trust-building stages. Common examplesbreach dump or combolist review, leaked-credential reuse, paste-site searches, stealer-log purchase, non-public leaked records Technique boundariesBreach & Leak Data Aggregation differs from Open-Source Intelligence Collection because the source material comes from prior compromise or non-public leakage rather than ordinary public exposure. It also differs from Credential & Identity Enumeration, which probes or validates current identities and accounts directly. | |||
Influencing a user to enter usernames, passwords, recovery codes, or other credentials into attacker-controlled systems. | Credential & Identity Access | Trust, Familiarity, Urgency | IDAMPEDTMIRR |
Credential capture influences a user to enter usernames, passwords, recovery codes, or other authentication material into an attacker-controlled system. The credential request is placed inside a plausible task such as viewing a secure message, opening a shared document, resolving an account warning, or signing in to a familiar service. A cloned login page, fake SSO portal, or lookalike service can reproduce enough of the expected authentication experience that the target focuses on completing the sign-in rather than checking the destination. Urgency and service familiarity may increase that effect. The defining method is the user voluntarily submitting credential material into a flow controlled by the attacker. Common examplesphishing page, fake SSO portal, fake secure message portal, cloned login page Technique boundariesCredential Capture applies where a person submits a password, recovery code or other secret into an attacker-controlled process. Authentication Relay & Interception applies where the attacker mediates a live authentication exchange, while Session & Token Access concerns authenticated state or token access. | |||
Influencing a user to approve, bypass, weaken, or interfere with MFA protections. | Credential & Identity Access | Trust, Authority, Urgency, Cognitive Load | IDADTMIRR |
MFA manipulation influences a user to approve, share, repeat, bypass, or weaken a multi-factor authentication step. The attacker may trigger repeated push notifications, claim to be IT resolving an account problem, request a one-time code, or present a fake re-enrolment process. Fatigue, confusion, urgency, and the expectation that support staff may guide authentication can make an unexpected prompt feel like part of a legitimate process. The user may be asked to approve a notification "we just sent" or read back a code to verify identity. The method turns the target into the party that completes or weakens the MFA control for the attacker. Common examplesMFA fatigue, repeated MFA prompts, fake MFA reset, push approval request Technique boundariesMFA Manipulation applies where the targeted action concerns an authentication factor or MFA challenge. Access & Consent Approval Manipulation applies where the target is asked to approve an application, sharing arrangement, privilege or other access grant. | |||
Exploiting account recovery, password reset, MFA reset, or identity proofing workflows. | Credential & Identity Access | Helpfulness, Authority, Urgency, Trust | IDAAVEDTMIRRPHM |
Account recovery manipulation exploits password reset, MFA reset, lost-device, account unlock, and identity proofing workflows to gain or restore access. The attacker presents a plausible recovery problem and attempts to make the fastest recovery path appear operationally necessary. Personal details gathered elsewhere can be used to satisfy weak identity questions, while urgency, distress, friendliness, seniority, or business impact pressures helpdesk staff to accept reduced proof. The requested action may reset a password, add a device, change security information, or weaken an authentication method. The method uses the recovery process itself to obtain an identity outcome the attacker could not reach through normal sign-in. Common exampleshelpdesk password reset, lost phone MFA reset, account unlock request Technique boundariesAccount Recovery Manipulation applies where an attacker seeks an identity or access outcome through password reset, authenticator reset, account unlock or recovery. Process Bypass Request and Exception Handling Abuse may also apply where required recovery safeguards are omitted or an exception path is misused. | |||
Influencing a user to expose, transfer, or surrender authenticated session or token access, including session cookies, device-code access, or other authenticated state. | Credential & Identity Access | Trust, Familiarity, Urgency | IDAMPEDTMIRR |
Session and token access influences a user to expose, transfer, or surrender authenticated session or token access. The attacker may direct the target through a device-code flow, ask them to export or share session material, take over an authenticated browser session, or otherwise obtain access to an existing authenticated state. The technique applies where social engineering or an attacker-directed workflow materially enables the access. A stolen session cookie obtained without user interaction is not social engineering by itself. Access & Consent Approval Manipulation concerns a decision that grants new application, service, sharing or privilege access. Common examplesdevice-code phishing, session-cookie transfer, authenticated browser-session handoff, token or session export, remote-session access Technique boundariesSession & Token Access concerns authenticated state or token access. Access & Consent Approval Manipulation concerns the decision to grant an application, service or person new access. | |||
Mediating or relaying a live authentication exchange through an attacker-controlled channel. | Credential & Identity Access | Trust, Familiarity, Urgency | IDAMPEDTMIRR |
Authentication interception redirects or relays an authentication interaction through an attacker-controlled channel. A deceptive proxy or fake login flow sits between the user and the real service, capturing credentials, MFA responses, session cookies, or other authentication material while preserving the appearance of a working sign-in. The page may mirror the real service dynamically and respond to user input, making the flow feel more convincing than a static credential form. Unexpected redirects, repeated prompts, or a sign-in launched from email, SMS, chat, QR code, or support contact can place the target inside the relay. The method is defined by the attacker mediating the authentication exchange rather than simply collecting a submitted password. Common examplesfake login relay, fake MFA verification page, credential interception portal Technique boundariesAuthentication Relay & Interception requires the attacker to mediate or relay a live authentication exchange. A static attacker-controlled login form is Credential Capture supported by Fake Authentication Interfaces. | |||
Exploiting shared accounts, generic credentials, shared mailboxes, informal delegation, or unclear account ownership. | Credential & Identity Access | Displaced Responsibility, Familiarity, Helpfulness | IDAAVEDTMIRRPHM |
Shared or delegated access abuse exploits weak account ownership, shared credentials, delegated permissions, or informal access-sharing practices. The attacker asks to be added to a shared mailbox, use a generic account, inherit another person's rights, or receive temporary access without a clear owner and approval record. Business continuity, leave coverage, project urgency, or familiarity with a team can make the delegation feel practical. Where generic accounts or shared secrets already exist, the attacker may seek the credential directly; in other cases they influence someone to grant or copy access. The method uses ambiguity over who legitimately owns or may share the access to reduce individual accountability. Common examplesshared mailbox access, generic account use, shared credentials, informal delegation, unclear account ownership Technique boundariesAccess & Consent Approval Manipulation applies where a specific approval creates access. Shared Account & Delegated Access Abuse applies where existing sharing, delegation or ownership practices are exploited. | |||
Influencing a user or approver to authorise application consent, external sharing, delegated access, privileges, or another access grant. | Credential & Identity Access | Trust, Authority, Urgency, Displaced Responsibility | IDAAVEMPEDTMIRRPHM |
Access and consent approval manipulation influences a user or approver to authorise an application consent grant, external share, privileged request, delegated access, or another access-enabling action. The attacker frames the approval as part of an audit, support case, collaboration task, or system workflow so the target treats approval as completion of an existing process. The technique is defined by the approval or consent decision that creates access. MFA Manipulation concerns an authentication factor or challenge, Access Provisioning Workflow Manipulation concerns organisational provisioning processes, and Session & Token Access concerns authenticated state after it exists. Common examplesapplication consent approval, privileged access request, external sharing approval, delegated access grant, attacker-controlled service authorisation Technique boundariesMFA Manipulation concerns an authentication factor or challenge. Access Provisioning Workflow Manipulation concerns onboarding, role changes, reactivation and other provisioning processes. Session & Token Access concerns authenticated state or token access after it exists. | |||
Manipulating a mobile carrier to transfer a victim's number and take control of phone-based authentication or recovery. | Credential & Identity Access | Trust, Authority, Urgency | IDADTMIRR |
SIM swap and phone-number takeover targets a mobile carrier or number-transfer process. The attacker impersonates or otherwise convinces the carrier to port, reassign, or transfer the victim’s number to a SIM or service under attacker control. Control of the number may allow the attacker to receive calls, messages or recovery codes that services send to that number. This can support downstream account recovery or authentication activity, although number control does not by itself defeat every identity or recovery process. Common examplescarrier port-out fraud, SIM reassignment, number-transfer request, SMS OTP interception Technique boundariesSIM Swap & Phone-Number Takeover differs from direct MFA Manipulation or Account Recovery Manipulation because the primary manipulation target is a third-party mobile carrier. Those techniques influence the user or organisational recovery process directly; SIM swap changes who controls the telephone number used by those processes. | |||
Mimicking login, SSO, MFA, or identity verification interfaces to capture credentials, approvals, or authentication material. | Fake Artefacts & Interface Deception | Trust, Familiarity, Urgency | IDAMPEDTM |
Fake authentication interfaces mimic login, SSO, MFA, or identity-verification screens to capture credentials, approvals, or authentication material. The attacker reproduces the branding, layout, loading behaviour, and prompts of a real service so the target recognises the interface before they inspect where it is hosted. A lookalike domain may display a familiar Microsoft 365, Google, SSO, or MFA flow and request passwords, codes, recovery material, or device information. HTTPS and realistic error handling can further reduce suspicion. The method uses the expected visual and interaction pattern of authentication to make an attacker-controlled interface feel like the normal place to sign in. Common examplesfake Microsoft 365 login, cloned SSO page, MFA verification portal Technique boundariesFake Authentication Interfaces imitate a login or authentication step to obtain or influence identity actions. Credential Capture is classified by the credential outcome, while Branding & Visual Mimicry describes the visual legitimacy cues that may make the interface convincing. | |||
Using fake service alerts, browser warnings, endpoint notices, security-product messages, or operational notifications to drive an unsafe action. | Fake Artefacts & Interface Deception | Fear, Urgency, Authority | MPEDTM |
Fake system notifications and warnings imitate automated alerts, browser messages, endpoint notices, security-product warnings, quota messages, or service updates. The attacker presents the message as a technical event generated by a system rather than as a request from another person. Password expiry, unusual sign-in, mailbox quota, malware, browser safety, endpoint, or account suspension warnings may direct the target to a link, portal, support number, download, or verification step controlled by the attacker. The method relies on users treating familiar alert patterns as evidence that an underlying system event has already occurred. Common examplespassword-expiry notice, mailbox quota warning, account suspension alert, browser security warning, fake antivirus alert, operating-system or update notice Technique boundariesFake System Notifications & Warnings describe the deceptive alert or message. Manufactured Crisis Framing describes the fabricated problem and attacker-supplied resolution that may sit behind it. Digital Service or Platform Impersonation applies where the service or platform itself is presented as the claimed identity. | |||
Using files or attachments that appear legitimate, important, or work-related. | Fake Artefacts & Interface Deception | Trust, Curiosity, Urgency | MPEDTMPHM |
Malicious attachment and file lures use documents, spreadsheets, PDFs, archives, disk images, or other files that appear relevant to the target's work. The filename, sender context, and surrounding message are chosen to make opening the file feel necessary for an invoice, recruitment process, project, strategy document, or other normal business task. Risky extensions, double extensions, password-protected archives, cloud-hosted delivery, or prompts to enable content can be hidden behind a familiar file icon and personalised context. A known or compromised sender can strengthen the lure further. The method uses the apparent business purpose of the file to motivate the target to open or interact with content that would otherwise receive more scrutiny. Common examplesinvoice attachment, recruitment document, shared PDF, macro-enabled document Technique boundariesMalicious Attachment & File Lures use a file presented as part of a business or operational interaction. Free Resource & Download Lures offer a perceived benefit, tool or resource as the reason for obtaining the file. | |||
Concealing malicious or deceptive destinations behind trusted-looking links, redirects, buttons, or shortened URLs. | Fake Artefacts & Interface Deception | Trust, Familiarity, Curiosity | IDAMPEDTM |
Deceptive links and redirects conceal an attacker-controlled destination behind trusted-looking text, buttons, shortened URLs, misleading domains, or redirect chains. The visible call to action is made to resemble a normal service, document, delivery, or account link while the underlying route leads somewhere different. Typosquatting, misleading subdomains, multiple redirects, and button-style links can make the destination difficult to assess before the target arrives. QR-Code Workflow Deception applies where scanning a visual code is the central transition into the attacker-controlled workflow. Common examplesshortened URL, hyperlink masking, misleading button destination, redirect chain, lookalike destination Technique boundariesDeceptive Links & Redirects concern clickable links, buttons, shortened URLs and redirect chains. QR-Code Workflow Deception applies where scanning a visual code transfers the target into the attacker-controlled workflow. | |||
Presenting fake support, troubleshooting, repair, or technical assistance workflows. | Fake Artefacts & Interface Deception | Authority, Fear, Urgency | IDAFSTAVEMPEDTM |
Fake support and troubleshooting interfaces present an attacker-controlled repair, diagnostic, recovery, or technical assistance workflow as legitimate support. Browser pop-ups, full-screen warnings, fake helpdesk portals, or device alerts can claim that malware, a network problem, or another technical fault requires immediate attention. The interface may instruct the target to call a supplied number, install a remote-access tool, run a diagnostic, enter administrative credentials, or keep the browser open. Familiar support branding and technical language make the steps appear like remediation rather than attacker direction. The method uses a false technical problem and a fake support surface to guide the target through unsafe actions. Common examplesfake IT support portal, browser pop-up, remote support prompt Technique boundariesFake Support & Troubleshooting Interfaces are deceptive technical artefacts or interaction surfaces presented as support. Helpdesk or IT Support Impersonation is centred on the claimed support identity, and the two techniques may occur together. | |||
Mimicking trusted communication, collaboration, or file-sharing platforms. | Fake Artefacts & Interface Deception | Familiarity, Trust | MPEDTM |
Fake collaboration and communication services mimic platforms used for messaging, meetings, file sharing, or secure communication. Teams, Slack, SharePoint, Zoom, Dropbox, or a secure-message service may be copied so a document, recording, voice note, meeting invite, or new message appears to arrive through a familiar collaboration workflow. The target is directed from the notification into a cloned portal, credential page, or malicious file while the platform branding carries the initial trust. These lures are effective because collaboration tools encourage rapid, low-friction interaction with shared content. The method uses the expected communication service as the wrapper for an attacker-controlled destination or artefact. Common examplesfake Teams message, fake SharePoint page, fake secure file transfer portal Technique boundariesFake Collaboration & Communication Services present an attacker-controlled imitation of a messaging, meeting, file-sharing or collaboration service. Technical Environment Context Mirroring uses accurate knowledge of the organisation’s real platforms or technical environment without necessarily presenting a copied interface. | |||
Using a QR code to transfer the target into an attacker-controlled mobile, payment, authentication, information, or support workflow. | Fake Artefacts & Interface Deception | Trust, Familiarity, Curiosity, Urgency | IDAAVEMPEDTM |
QR-code workflow deception uses a visual code to transfer the target into an attacker-controlled mobile, payment, authentication, information, or support workflow. The code may appear in an email, document, poster, sign, parcel, invoice, parking notice, sticker, or physical replacement placed over a legitimate code. The destination is difficult to inspect before scanning, and the transition to a mobile device may separate the action from organisational browser controls or familiar URL cues. Deceptive Links & Redirects apply to clickable links and redirect chains, while this technique is defined by the QR-code transition itself. Common examplesQR-code login lure, payment-code replacement, malicious poster or flyer, tampered sign or sticker, mobile support workflow Technique boundariesQR-Code Workflow Deception is defined by scanning a visual code to enter the workflow. Deceptive Links & Redirects concern clickable links, buttons, shortened URLs and redirect chains. | |||
Persuading a target to install or run attacker-supplied software or grant a remote-access session. | Fake Artefacts & Interface Deception | Authority, Fear, Trust | FSTAVEMPEDTMIRRPHM |
Malicious software and remote-access tool installation uses social influence to make execution or access feel necessary and safe. The attacker may present a support issue, security warning, update, troubleshooting step, or urgent fix, then direct the target to download, install, run, approve, or keep open an attacker-supplied tool. Authority, fear, and technical trust can turn the target into the execution path. The attacker may ask the person to ignore operating-system or browser warnings, enable screen sharing, approve unattended access, or continue a remote session outside an established support process. The defining action is the user enabling software execution or live device control. Common examplestech-support scam remote session, fake software update, trojanised installer, run this fix tool, unsolicited remote-access invite Technique boundariesMalicious Software & Remote-Access Tool Installation differs from Fake Support & Troubleshooting Interfaces because the defining mechanism is installation, execution, or a live remote session rather than the deceptive interface itself. It differs from Software & Update Supply-Chain Compromise where trust in a distribution path, package ecosystem, or supplier software channel is the main source of legitimacy. | |||
Copying trusted branding, logos, layouts, colours, templates, or interface design. | Legitimacy & Context Mirroring | Familiarity, Trust | IDAAVEMPEDTM |
Branding and visual mimicry copies trusted logos, colours, layouts, templates, and visual design so an artefact resembles a legitimate organisation or service. The attacker uses recognition of the brand to create an immediate sense of familiarity before the target examines the sender, destination, or workflow. A cloned login, copied invoice, fake HR portal, or reproduced email template can look accurate while links, reply addresses, payment details, or domains point elsewhere. High visual quality may encourage the target to treat appearance as proof of origin. The method uses familiar visual identity to explain away inconsistencies that would be more obvious in an unbranded interaction. Common examplescloned Microsoft login, copied invoice template, fake HR portal Technique boundariesBranding & Visual Mimicry describes copied visual identity across portals, documents, forms, emails and other artefacts. Specific fake-interface techniques may also apply where the copied branding is used within an attacker-controlled login, support, collaboration or notification surface. | |||
Using internal terminology, communication style, naming conventions, or operational language. | Legitimacy & Context Mirroring | Familiarity, Social Proof | IDAAVEPHM |
Organisational language mirroring copies internal terminology, naming conventions, communication style, and operational language. The attacker uses project codes, acronyms, policy terms, team names, or familiar process wording to make the message sound as though it originated inside the organisation. The language does not need to be perfect if enough internal terms are correct to create familiarity. Outdated jargon, a term used in the wrong business unit, or process language without the expected ticket or approval context may still be rationalised when the message sounds "internal". The method uses linguistic familiarity as evidence of organisational belonging. Common examplesinternal project names, finance terminology, IT support wording Technique boundariesOrganisational Language Mirroring copies internal terms, acronyms, project names, process labels and operational vocabulary. Sender Communication Style Mirroring copies the tone, phrasing, punctuation, formatting and signature habits of a particular person or role. | |||
Mimicking legitimate business workflows, approvals, or operational processes. | Legitimacy & Context Mirroring | Familiarity, Trust, Authority | GOVAVEDTMPHM |
Workflow and process mirroring recreates the expected steps, sequence, terminology, and hand-offs of a legitimate organisational process. The attacker may reproduce the order in which a request is normally raised, reviewed, approved, or completed so the interaction fits staff expectations. The technique concerns imitation of the workflow pattern rather than use of a genuine record or counterfeit proof. Existing Ticket or Workflow Abuse uses a real workflow record, while Fabricated Workflow Evidence supplies counterfeit evidence that a process, ticket or approval occurred. Common examplesapproval chain imitation, fake procurement workflow, payroll process imitation Technique boundariesWorkflow & Process Mirroring recreates the appearance or sequence of a process. Existing Ticket or Workflow Abuse uses a genuine process record, while Fabricated Workflow Evidence supplies counterfeit proof that a process or approval occurred. | |||
Aligning activity with real-world business timing, events, or operational cycles. | Legitimacy & Context Mirroring | Familiarity, Social Proof | AVEDTMPHYIEX |
Timing and operational context mirroring aligns an attack with genuine business cycles, events, absences, or deadlines. The attacker uses real organisational timing so a sensitive request arrives when its subject matter and urgency already fit what the target expects to be happening. Payroll periods, month-end, recruitment cycles, executive travel, project rollouts, procurement deadlines, events, or maintenance windows can provide natural cover. A fake invoice or project follow-up may arrive soon after a real business event, or a request may be timed for when an approver is unavailable. The method uses genuine timing to make unusual content feel situationally normal. Common examplespayroll period, holiday staffing, executive travel, project rollout Technique boundariesEvent & Operational Timing Collection gathers timing information. Timing & Operational Context Mirroring uses known timing to make a later interaction appear plausible. | |||
Referencing real relationships, suppliers, teams, reporting lines, or previous communications. | Legitimacy & Context Mirroring | Social Proof, Trust, Familiarity | IDAFSTAVEIEX |
Relationship context mirroring uses accurate or plausible knowledge of colleagues, suppliers, teams, reporting relationships, handovers, known projects, and prior business interactions to make a separate interaction appear connected to the organisation. The attacker may refer to a real contact, recent meeting, shared project, supplier owner, or internal relationship and use that context as a substitute for proving the current identity or request. Familiar Relationship Exploitation uses a direct or assumed relationship between requester and target, while Thread Hijacking & Authentic-Context Insertion uses the genuine conversation history itself. Common examplesknown supplier follow-up, “as discussed”, existing email thread continuation Technique boundariesFamiliar Relationship Exploitation uses a direct or assumed relationship between the requester and target. Relationship Context Mirroring uses accurate relationship information to make a separate interaction appear connected to the organisation. Thread Hijacking & Authentic-Context Insertion applies where the genuine conversation history itself is used. Relationship & Trust Mapping gathers relationship information during reconnaissance. Relationship Context Mirroring uses that information in a later interaction. | |||
Referencing accurate details of the organisation’s technology environment to make a request, warning, or support interaction appear plausible. | Legitimacy & Context Mirroring | Familiarity, Trust | IDADTMIEX |
Technical environment context mirroring references accurate details of the organisation’s technology environment to make a request, warning, or support interaction appear plausible. The attacker may name the real identity provider, collaboration platform, VPN, service desk tool, cloud provider, payroll platform, security product, or normal technical terminology. The technique uses correct environmental knowledge without requiring an attacker-controlled copy of the service. Fake Collaboration & Communication Services presents a false interface or service, while Digital Service or Platform Impersonation presents the service or platform itself as the claimed identity. Common examplesreal identity provider, known collaboration platform, actual VPN or service desk tooling, genuine cloud provider, known payroll or HR platform, real security product Technique boundariesTechnical Environment Context Mirroring uses accurate knowledge of real platforms and tooling as context. Fake Collaboration & Communication Services presents an attacker-controlled imitation, while Digital Service or Platform Impersonation presents the platform or service as the claimed identity. | |||
Referencing legitimate operational activity to create plausibility. | Legitimacy & Context Mirroring | Familiarity, Social Proof, Trust | IDAAVE |
Business activity mirroring references legitimate operational activity to create plausibility. The attacker aligns the pretext with a real invoice, open role, active project, procurement exercise, audit, delivery, event, customer interaction, or other business activity that the target already expects to encounter. Public tenders, press releases, supplier case studies, recruitment pages, and known project details can provide enough context to make the message feel current. The attacker then introduces an unusual payment, access, credential, or disclosure action inside the genuine activity. The method uses real business events as camouflage for a request that does not belong to them. Common examplesreal invoice, active project, current procurement, recruitment cycle | |||
Copying the tone, phrasing, punctuation, formatting, greeting, or signature habits associated with a particular person or role. | Legitimacy & Context Mirroring | Familiarity, Trust | IDAAVEPHM |
Communication style mirroring copies tone, phrasing, signatures, formatting, greetings, sign-offs, and other expected communication behaviour. The attacker adapts the message to resemble an executive, supplier, recruiter, auditor, helpdesk, or internal team and may reproduce details from genuine correspondence. A realistic signature block, familiar punctuation, characteristic brevity, or role-appropriate tone can make the message feel recognisable even when the channel or requested action is wrong. Style may also be adjusted for the audience, such as formal language for procurement or casual chat for technical teams. The method borrows credibility from how a trusted sender is expected to communicate. Common examplesexecutive tone imitation, realistic signature block, copied writing style Technique boundariesSender Communication Style Mirroring copies the communication habits of a particular person or role. Organisational Language Mirroring copies internal vocabulary, acronyms, project names and process terminology. | |||
Presenting activity as part of legitimate security, compliance, governance, or operational policy activity. | Legitimacy & Context Mirroring | Trust, Authority, Familiarity | GOVAVEPHM |
Security and compliance framing uses security, governance, audit, protected-process, encryption, verification, or compliance language as a cue of legitimacy. The interaction may claim to use a secure transfer, encrypted channel, verified process, protected portal, approved workflow, or formally controlled handling arrangement. Security terminology, padlock imagery, compliance labels, and claims of approval can make the action appear safer or more official than it is. Compliance Expectation Manipulation applies where fear of breach, discipline, audit failure or non-compliance is used to pressure the target. Common examplessecurity review, compliance notice, policy update, audit workflow Technique boundariesSecurity & Compliance Framing uses security, governance, audit or protected-process language primarily as a cue of legitimacy. Compliance Expectation Manipulation pressures the target with threatened breach, disciplinary action, audit failure or another consequence. | |||
Inserting attacker-controlled requests into a genuine conversation or reply chain so authentic context carries the deception. | Legitimacy & Context Mirroring | Familiarity, Trust | IDAFSTAVEMPEDTMIRR |
Thread hijacking and authentic-context insertion places an attacker-controlled request inside a genuine conversation, reply chain, or collaboration history. Often through a compromised mailbox or account, the attacker inherits real participants, prior messages, business context, timing, and subject matter instead of recreating them. The authentic history carries legitimacy while the attacker changes a smaller operational detail such as a payment destination, contact path, document, portal, delivery instruction, or approval step. Because most of the surrounding context is accurate, the target may treat continuity of the thread as sufficient verification and focus less scrutiny on the changed detail. Common examplesreply-chain insertion, compromised-supplier mailbox, hijacked invoice thread, real conversation continued by an attacker Technique boundariesCompromised Account Impersonation describes control of the genuine identity. Thread Hijacking & Authentic-Context Insertion describes use of the authentic conversation history. Existing Ticket or Workflow Abuse applies where the authentic context is a workflow record rather than a communication thread. | |||
Coordinating two or more communication channels so repeated or sequenced contact makes the same pretext, request, or claimed event appear corroborated. | Multi-Channel Reinforcement | Social Proof, Trust, Familiarity | IDAAVEDTM |
Cross-channel pretext reinforcement coordinates two or more communication channels so repeated or sequenced contact makes the same pretext, request, or claimed event appear corroborated. An email may be followed by a related call, an SMS may precede a support interaction, or a chat may refer to a message sent through another service. The apparent agreement between channels can be mistaken for independent confirmation even when the same actor controls or influences each one. Out-of-Band Verification Manipulation applies where a formal or expected verification step is made to appear independent, while Cross-Channel Communication Saturation uses contact volume and simultaneity to create cognitive pressure. Common examplesemail followed by a related call, SMS preceding a support interaction, chat referring to a recent email, coordinated messages repeating the same event Technique boundariesCross-Channel Pretext Reinforcement applies where multiple channels reinforce the same interaction or story. Out-of-Band Verification Manipulation applies where a verification step is made to appear independent. Cross-Channel Communication Saturation applies where volume and simultaneity create cognitive pressure. | |||
Moving interaction to a channel with weaker monitoring, retention, verification, governance, or organisational oversight. | Multi-Channel Reinforcement | Secrecy, Urgency, Familiarity | AVEDTMPHM |
Channel switching to avoid controls moves an interaction from a monitored or governed channel into one with weaker oversight, retention, verification, or organisational visibility. The attacker may shift corporate email or Teams activity into personal SMS, WhatsApp, Signal, Telegram, private email, or social direct messages. Convenience, privacy, technical problems, or urgency are commonly used to justify the move. Once the target is off-channel, riskier requests can be made without the same reporting tools, audit trail, or colleague visibility. The method uses the channel change to separate the target from the controls and social context that might otherwise interrupt the interaction. Common examplescorporate email to WhatsApp; Teams chat to personal phone; LinkedIn to private email Technique boundariesChannel Switching to Avoid Controls is defined by movement between communication channels to weaken monitoring, retention, identity assurance or organisational oversight. Emotional Isolation & Dependency applies where the target is discouraged from seeking advice or support, regardless of whether the channel changes. | |||
Using simultaneous or tightly clustered calls, messages, prompts, or notifications across several channels to create interruption and information load. | Multi-Channel Reinforcement | Cognitive Load, Urgency, Fear | AVEMPEDTMIRR |
Cross-channel communication saturation uses simultaneous or tightly clustered calls, messages, prompts, or notifications across several channels to create interruption and information load. The target is forced to divide attention between contacts that appear related or urgent. The pressure comes from volume, simultaneity, and channel switching rather than from the credibility of any single message. Pressure Persistence relies on repeated requests or prompts and may occur through one channel. Control Fatigue Exploitation takes advantage of an operating environment that is already overloaded. Common examplesemail flood followed by a support call, simultaneous SMS and chat messages, clustered calls and approval prompts, multiple channels active during the same request Technique boundariesCross-Channel Communication Saturation uses simultaneous or clustered contact across several channels. Pressure Persistence relies on repeated requests or prompts and may occur through a single channel. | |||
Manipulating a verification process so one attacker-controlled or attacker-influenced channel appears to independently confirm another. | Multi-Channel Reinforcement | Trust, Authority, Familiarity | IDAFSTAVEDTM |
Out-of-band verification manipulation makes one attacker-controlled or attacker-influenced channel appear to independently confirm another. The attacker may supply a callback number, generate a confirming SMS, misrepresent an authentication code as identity proof, or use one fake or compromised channel to validate another. The technique contaminates the independence of the verification path rather than simply discouraging the check. Verification Suppression seeks to prevent the confirming step from occurring, while Cross-Channel Pretext Reinforcement uses multiple channels to support the same story without necessarily presenting them as formal verification. Common examplescallback number supplied during the interaction, attacker-generated SMS used as confirmation, code misrepresented as identity proof, one fake channel confirming another, compromised channel used as independent confirmation Technique boundariesOut-of-Band Verification Manipulation contaminates or controls the supposed confirming path. Verification Suppression seeks to prevent the confirming step from occurring. Cross-Channel Pretext Reinforcement uses multiple channels to support the same pretext without necessarily representing a formal verification step. | |||
Repeated benign interactions across channels that condition the target to trust the pattern before a malicious request. | Multi-Channel Reinforcement | Familiarity, Trust | IDAAVEDTM |
Recurring touchpoint conditioning uses repeated benign interactions to train the target to trust a sender, cadence, channel, or pattern before a malicious request appears. A supplier may send harmless weekly updates, or a familiar bot may routinely share useful links, creating an expected rhythm of low-risk engagement. Once the pattern is established, a bank-detail change, credential link, or other sensitive action can be inserted into the familiar cadence. The target may act from habit because previous interactions were harmless and predictable. The method uses routine as conditioning, allowing the attack to inherit trust from a history of deliberately benign touchpoints. Common examplesregular supplier WhatsApp updates followed by bank change; recurring Teams links followed by malicious link Technique boundariesRecurring Touchpoint Conditioning deliberately establishes a benign communication pattern before inserting the malicious request. Trusted Channel or Routine Exploitation abuses a routine that already exists independently of the attacker. Long-Game Relationship Cultivation develops an interpersonal relationship rather than primarily conditioning a communication pattern. | |||
Exploiting compassion, kindness, supportiveness, or desire to help others. | Emotional Influence | Sympathy, Helpfulness, Guilt | AVEPHM |
Sympathy and empathy exploitation uses compassion, kindness, or the desire to support someone in distress as the reason to cooperate. The attacker presents a personal emergency, illness, family problem, charity need, or overwhelmed colleague and gives the target an emotionally credible reason to want to help quickly. The emotional story is then linked to a concrete request for money, access, information, credentials, or a process exception. Verification may be framed as cold, obstructive, or lacking compassion, especially when the attacker says the target is the only person they can turn to. The method uses the target's concern for another person to reduce scrutiny of the requested action. Common examplesdistressed colleague, personal emergency, charity request, emotional support appeal Technique boundariesSympathy & Empathy Exploitation uses concern for the attacker or another person to motivate assistance. Unsolicited Assistance & Rescue Framing presents the attacker as the person helping the target. | |||
Using personal responsibility, disappointment, shame, or fear of letting others down to make refusal emotionally difficult. | Emotional Influence | Guilt, Obligation, Commitment | AVEPHM |
Guilt and shame pressure makes the target feel personally responsible for disappointing others, causing harm, failing a promise, or appearing selfish or disloyal. The attacker may invoke a previous mistake, omission, favour, or commitment and frame refusal as evidence of poor character or professional failure. The mechanism is emotional discomfort rather than formal duty or threatened exposure. Duty & Responsibility Exploitation invokes an existing professional role, while Embarrassment & Reputation Pressure concerns possible humiliation, criticism or reputational damage. Common examples“you are letting the team down”, “I thought I could rely on you”, blame for delay, reminder of a prior promise or mistake Technique boundariesDuty & Responsibility Exploitation invokes an existing professional or organisational duty. Guilt & Shame Pressure relies on emotional discomfort, personal responsibility or fear of disappointing others. Embarrassment & Reputation Pressure concerns possible exposure, humiliation, criticism or reputational damage. | |||
Developing affection, friendship, romance, or emotional attachment so later requests feel personally important or difficult to refuse. | Emotional Influence | Trust, Familiarity, Commitment | AVEPHM |
Trust and affection development builds emotional connection, familiarity, attraction, or personal trust over time. A professional, social, romantic, mentoring, or supportive relationship may deepen quickly through personal stories, photos, private details, and apparent emotional vulnerability. Once the bond is established, small requests for money, information, access, or help can be framed as emergencies or signs of trust. Outside concern may be dismissed because the target feels that friends, colleagues, or managers do not understand the relationship. The method uses emotional attachment itself as the influence mechanism and can gradually shift connection into dependency, secrecy, or repeated requests. Common examplesromantic attachment, intense friendship, personal confidant role, emotionally supportive persona, affection used before a request Technique boundariesAffection & Emotional Attachment Development is defined by emotional attachment. Long-Game Relationship Cultivation is defined by sustained relationship maintenance and delayed exploitation and may involve professional, social or emotional relationships. | |||
Exploiting fear of embarrassment, failure, exposure, or reputational damage. | Emotional Influence | Fear, Guilt, Secrecy | AVEPHM |
Embarrassment and reputation pressure exploits fear of failure, exposure, public criticism, or reputational damage. The attacker presents a mistake, inappropriate message, performance issue, or sensitive incident and makes the target believe that wider disclosure will be more damaging than taking the requested action privately. Claims that HR, the board, colleagues, or the public may learn about the issue can create urgency and shame. The target may be pressured to pay, disclose data, share credentials, or stay silent in order to "fix" the problem before anyone notices. The method uses the desire to contain embarrassment as a reason to avoid the normal people and processes that would validate the claim. Common examplesmistake exposure threat, public criticism concern, performance pressure Technique boundariesEmbarrassment & Reputation Pressure applies where the target acts to avoid perceived exposure, humiliation, criticism or reputational damage without an explicit threat from the attacker. Coercion, Threat & Extortion Pressure applies where the attacker directly threatens exposure or harm unless the target complies. | |||
Discouraging outside advice and making the attacker the target’s primary source of guidance, reassurance, or emotional support. | Emotional Influence | Trust, Commitment, Secrecy, Fear | AVEPHM |
Emotional isolation and dependency discourages the target from seeking outside advice and makes the attacker the primary source of guidance, reassurance, or emotional support. The attacker may claim that colleagues, family, security staff, or other support figures will not understand or will damage the relationship. As dependence grows, consultation and reporting can feel disloyal, unsafe, or personally costly. Channel Switching to Avoid Controls concerns movement to a less governed communication channel, while this technique is defined by emotional separation and reliance regardless of the channel used. Common examplesdiscouraging advice from colleagues or family, claiming others will not understand, exclusive reliance on the attacker, separating the target from support, relationship dependency Technique boundariesChannel Switching to Avoid Controls concerns movement between communication channels to weaken safeguards. Emotional Isolation & Dependency concerns discouraging advice and creating reliance on the attacker, regardless of whether the channel changes. Affection & Emotional Attachment Development concerns the attachment itself. Emotional Isolation & Dependency concerns the reduction of outside support and increasing reliance on the attacker. | |||
Claiming that peers, colleagues, or respected people have already complied, approved, joined, or adopted the requested action. | Emotional Influence | Social Proof, Familiarity, Obligation | AVEPHM |
Peer conformity pressure claims that peers, colleagues, or respected people have already complied, joined, approved, adopted a tool, or accepted the request. The target is encouraged to treat group behaviour or endorsement as evidence that the action is normal and safe. The technique relies on claimed consensus rather than on a benefit offered to the target. Belonging & Community Access Incentives offer membership, access, inclusion or status as the reward. Common examples“everyone else has completed it”, claimed peer approval, colleagues said to have joined, respected people presented as users Technique boundariesPeer Conformity Pressure uses claimed group behaviour or endorsement to make compliance appear normal. Belonging & Community Access Incentives offer membership, access, status or inclusion as the benefit. | |||
Using direct threats of harm, exposure, loss, or consequence to compel action or continued cooperation. | Emotional Influence | Fear, Secrecy, Obligation | AVEIRRPHM |
Coercion, threat and extortion pressure uses an explicit threatened harm to compel action. The attacker may threaten exposure, reputational damage, data release, financial loss, harm to the target or another person, or consequences for refusing to cooperate, then present payment, disclosure, access, or continued assistance as the way to prevent that outcome. The threat changes the target’s decision context from persuasion to duress. Fear, shame, secrecy, and perceived responsibility can isolate the target and make ordinary reporting or consultation feel dangerous. The technique may also pressure an insider or employee to misuse legitimate access because the attacker is exploiting the consequences of non-compliance rather than the apparent legitimacy of the request. Common examplesblackmail or sextortion, threats to safety, reputation, or family, pay or your data is leaked, threat-backed insider pressure Technique boundariesConsequence of Delay Framing presents an adverse outcome as the result of waiting or failing to complete the action. Coercion, Threat & Extortion Pressure uses threatened harm, exposure or retaliation as the means of forcing compliance. | |||
Offering assistance, benefit, or service in exchange for action, information, credentials, approval, or access. | Reciprocity, Incentive & Baiting | Reciprocity, Opportunity, Obligation | AVEPHM |
Quid pro quo exchange offers assistance, a benefit, or a service in return for action, information, credentials, approval, or access. The attacker makes the interaction feel reciprocal, giving the target a reason to believe that cooperation will solve a problem or produce a direct benefit. Fake support may offer to fix an access issue in exchange for a password or MFA approval, while a survey reward or small favour can precede a larger concession. The exchange is often uneven, with the target giving up something far more valuable than the benefit received. The method uses the expectation of reciprocity to make the requested action feel like a reasonable part of a transaction. Common examplesfake IT support, survey reward, support exchange, “help me and I’ll help you” Technique boundariesQuid Pro Quo Exchange requires an explicit or implied exchange of benefit for action, information, or access. Assistance & Rescue Framing offers help as the engagement mechanism and may create reciprocity, but does not require the target to understand the interaction as an exchange. | |||
Triggering curiosity, intrigue, uncertainty, or novelty to encourage unsafe interaction. | Reciprocity, Incentive & Baiting | Curiosity, Scarcity, Urgency | MPEDTMPHM |
Curiosity baiting triggers intrigue, uncertainty, novelty, or a desire to know more so the target interacts before verifying. A mysterious document, unknown USB, suggestive subject line, video reference, leaked-information claim, or unexplained QR code can create a question the target wants answered immediately. The lure is deliberately incomplete enough that opening, clicking, scanning, plugging in, or downloading feels like the easiest way to resolve the uncertainty. Personal relevance, such as "is this you?" or "this document mentions you", can increase the pull. The method uses the target's desire to close an information gap as the motivation to cross a security boundary. Common examplesunknown USB, “confidential salary list”, mystery document, leaked information lure Technique boundariesCuriosity Baiting applies where intrigue or incomplete information motivates interaction. Physical Baiting applies where a placed or discovered physical object is the mechanism that creates the opportunity to interact. | |||
Offering prizes, rewards, discounts, gifts, or exclusive access to reduce scrutiny. | Reciprocity, Incentive & Baiting | Opportunity, Reciprocity, Scarcity | PHM |
Reward and prize incentives offer gifts, vouchers, discounts, competitions, subscriptions, or other benefits to reduce scrutiny. The target is told they have won, been selected, or can claim something valuable and is directed toward a redemption process that appears to be the final step. The reward may require a small fee, corporate credentials, payment details, identity information, or an approval prompt. Urgent redemption and an unusually generous prize can encourage the target to act before questioning an unfamiliar sender or domain. The method uses anticipated reward to make the requested input feel like a minor cost of claiming the benefit. Common examplesgiveaway, voucher, competition, reward portal, free subscription | |||
Exploiting ambition, professional opportunity, recognition, or career interest. | Reciprocity, Incentive & Baiting | Opportunity, Authority, Trust | PHM |
Opportunity and career incentives exploit ambition, recognition, or professional interest. A recruiter, job offer, interview, leadership forum, conference invitation, or other career opportunity is tailored to the target and presented as a credible next step based on their experience or public profile. The opportunity can then introduce recruitment portals, attachments, forms, identity requests, bank or tax details, or unusual access requirements. A perfect career moment and a short application window can make the target more willing to engage quickly. The method uses professional aspiration as the reason to enter an attacker-controlled process. Common examplesrecruiter approach, job offer, interview attachment, conference invitation | |||
Offering files, tools, resources, templates, or downloads that appear useful or beneficial. | Reciprocity, Incentive & Baiting | Opportunity, Curiosity, Trust, Reciprocity | MPEDTMPHM |
Free resource and download lures offer files, tools, templates, reports, software, or other useful material at no apparent cost. The resource is selected to match a genuine need or interest, such as policies, benchmarks, project tools, industry guides, or free software. Access to the resource may require a suspicious download, macro-enabled document, archive, executable, login, app consent, or excessive personal information. A polished landing page and relevant content can make the offer feel legitimate even when the domain or file type is unusual. The method uses practical value as the reason to interact with an untrusted artefact or process. Common examplessoftware download, free template, fake toolkit, document pack Technique boundariesFree Resource & Download Lures use perceived utility or free access as the reason to obtain a file or tool. Malicious Attachment & File Lures present the file as part of a business, operational or communication task. | |||
Using physical objects or environments to encourage unsafe interaction or access. | Reciprocity, Incentive & Baiting | Curiosity, Helpfulness, Familiarity | MPEDTMPHYPHM |
Physical baiting places an object or physical artefact where the target is likely to find and interact with it. USB drives, access cards, phones, laptops, chargers, power banks, promotional items, or other devices can be branded or positioned to trigger curiosity, helpfulness, responsibility, or a sense of discovery. The target may plug in the device, test the card, scan a QR code, connect the accessory, or attempt to return the item without first treating it as untrusted. Event context, company branding, or plausible labels can strengthen the lure. The method uses the physical object's presence and apparent purpose to motivate the unsafe interaction. Common examplesdropped USB, fake access card, abandoned device, promotional material Technique boundariesPhysical Baiting is defined by placement or presentation of a physical object. Curiosity Baiting describes the psychological trigger and may also apply where intrigue motivates interaction with the object. | |||
Offering membership, group access, social status, inclusion, or admission to a community as the benefit for engaging. | Reciprocity, Incentive & Baiting | Opportunity, Social Proof, Familiarity | AVEPHM |
Social and community incentives offer belonging, inclusion, member access, or status within a professional, organisational, or social group. The target may be invited to a private Slack community, WhatsApp group, advisor panel, team channel, or other exclusive space that aligns with their identity or interests. Joining the group may require authentication, identity verification, or use of a fake platform, and later interaction can introduce links, information requests, or pressure to invite others. Exclusivity and social relevance make the invitation feel less suspicious because participation appears to connect the target with peers. The method uses belonging as the benefit that drives engagement. Common examplesprivate community invitation, exclusive group access, membership offer, social status or inclusion, peer-network admission Technique boundariesBelonging & Community Access Incentives offer membership, access, status or inclusion as a benefit. Peer Conformity Pressure uses claimed group behaviour or endorsement to make compliance appear normal. | |||
Offering an easier, faster, or lower-friction route so the target chooses an unsafe shortcut. | Reciprocity, Incentive & Baiting | Opportunity, Trust, Familiarity | GOVAVEPHM |
Convenience and efficiency lures present a shortcut, simplified workflow, or easier alternative to normal process. The attacker promises faster access, one-click sign-in, a direct link, automated approval, or another improvement that removes friction from a task the target already wants to complete. The convenience often masks the loss of a security checkpoint, such as bypassing VPN, granting OAuth consent, installing an extension, or weakening approval rules. The shortcut may be framed as modern, helpful, or officially recommended. The method uses the appeal of efficiency to make the removal of protective steps feel like a feature rather than a risk. Common examplesfaster login method, manual shortcut, one-click access, unofficial tool, reduced-step process Technique boundariesConvenience & Shortcut Lures make an easier or faster route attractive. Process Bypass Request describes the action of asking someone to omit a required step. Both may apply where the promised convenience is used to secure the bypass. | |||
Framing access, reward, or opportunity as rare, limited, selective, or exclusive. | Reciprocity, Incentive & Baiting | Scarcity, Opportunity, Social Proof | PHM |
Scarcity and exclusivity incentives make a reward or opportunity appear rare, selective, or limited to a small number of people. VIP access, early registration, partner-only offers, limited rates, or a small number of remaining places can make the target feel chosen and reluctant to lose the opportunity. A short response window and claims that only selected people were invited can reduce the time the target spends comparing or validating the offer. The benefit itself may be artificial, but scarcity increases its perceived value. The method uses limited availability and privileged status as the reason to act before normal caution catches up. Common examplesVIP access, limited-time invitation, early-access opportunity Technique boundariesScarcity & Exclusivity Incentives use limited availability or special access to increase the attractiveness of a benefit. Scarcity or Opportunity Framing under Urgency, Scarcity & Consequence Framing is centred on reducing perceived time or choice, even where no incentive is offered. | |||
Presenting the attacker as able to solve, prevent, or relieve a problem so the target accepts their guidance or access. | Reciprocity, Incentive & Baiting | Trust, Reciprocity, Authority | FSTAVEPHM |
Unsolicited assistance and rescue framing presents the attacker as able to solve, prevent, or relieve a problem for the target. The contact may offer technical help, fraud prevention, account recovery, financial rescue, or another intervention before the target has independently sought assistance. The offer of help establishes cooperation and can lead to remote access, credential entry, payment, disclosure, or process exceptions. Quid Pro Quo Exchange requires an understood exchange, while Manufactured Crisis Framing applies where the attacker fabricated the problem and then supplied the resolution. Common examplesunsolicited technical help, fraud rescue, account recovery offer, problem-solving contact, protective intervention Technique boundariesQuid Pro Quo Exchange requires an understood exchange of benefit for action or information. Unsolicited Assistance & Rescue Framing uses the offer of help without requiring an explicit exchange. Manufactured Crisis Framing applies where the attacker fabricates the problem and then supplies the resolution. Fake Support & Troubleshooting Interfaces apply where a deceptive technical interface carries the supposed assistance. | |||
Promising financial return or investment opportunity to induce the target to transfer funds, credentials, or access. | Reciprocity, Incentive & Baiting | Opportunity, Trust, Scarcity, Commitment | FSTAVEPHM |
Investment and financial-gain baiting presents the target with an opportunity to increase, recover, or multiply their own money. The attacker may introduce a trading platform, investment scheme, cryptocurrency opportunity, adviser, wallet, or advance-fee arrangement and frame participation as profitable, exclusive, or time-sensitive. The lure encourages the target to commit their own funds or financial access in pursuit of a promised return. Trust can be built through rapport, small apparent gains, fabricated balances, screenshots, or testimonials, while scarcity and opportunity framing make independent advice or delay feel costly. The financial return remains the engine of the interaction even when a long-term relationship is used to deliver it. Common examplesfake investment or trading platform, guaranteed returns, crypto opportunity, advance-fee scheme, pig-butchering investment fraud Technique boundariesInvestment & Financial-Gain Baiting differs from Reward & Prize Incentives because the target is induced to commit their own money, credentials, or access in pursuit of a return rather than claim a benefit they supposedly already won. Long-Game Relationship Cultivation may deliver the lure, but the promised financial gain is the defining mechanism here. | |||
Framing the interaction as confidential, restricted, private, or sensitive to discourage verification or consultation. | Secrecy, Verification Suppression & Commitment Escalation | Secrecy, Authority, Trust, Fear | GOVAVEPHM |
Confidentiality pressure frames an interaction as restricted, private, sensitive, or need-to-know so the target feels unable to discuss it with others. The attacker may invoke an executive matter, HR issue, legal case, investigation, or other subject where limited circulation appears reasonable. Secrecy language can prevent callbacks, second-person review, documentation, or consultation with a manager by making those actions seem like breaches of trust. Flattery may reinforce the pressure by suggesting the target was chosen for their integrity. The method uses the claimed sensitivity of the matter to remove the independent people and records that could challenge the request. Common examplesconfidential executive request, sensitive HR issue, private legal matter Technique boundariesConfidentiality Pressure uses the claimed sensitivity of a matter to restrict consultation, documentation or review. Verification Suppression directly discourages or obstructs a verification step and does not require confidentiality framing. | |||
Starting with low-risk requests and progressively increasing sensitivity, access, or impact over time. | Secrecy, Verification Suppression & Commitment Escalation | Commitment, Trust, Guilt | AVEPHM |
Gradual commitment escalation begins with low-risk participation and increases the sensitivity, access, or impact of later requests. The attacker first secures a small favour or harmless disclosure and then presents each new request as a continuation of work the target has already agreed to support. Earlier cooperation can be referenced directly, such as "since you already helped with the first part", making refusal feel inconsistent or awkward. The target may also become invested in completing the supposed project or relationship. The method uses prior participation as leverage, increasing the psychological and social cost of stopping as the requests become more consequential. Common examplessmall favour followed by approval request, information gathering before access request Technique boundariesGradual Commitment Escalation uses prior participation, consistency pressure or accumulated involvement to make withdrawal harder. Gradual Trust Escalation relies on trust developing before requests become more sensitive. | |||
Explicitly discouraging, obstructing, or discrediting callbacks, consultation, escalation, or independent confirmation. | Secrecy, Verification Suppression & Commitment Escalation | Displaced Responsibility, Authority, Urgency, Secrecy | GOVAVEPHM |
Verification suppression explicitly discourages, obstructs, or discredits callbacks, consultation, escalation, or independent confirmation. The attacker may claim that the check has already occurred, that another person accepted the risk, that verification will cause delay or harm, or that the usual contact cannot be trusted. The technique requires active suppression rather than a verification step simply being missed. Out-of-Band Verification Manipulation contaminates or controls the supposed confirming channel, while Confidentiality Pressure uses sensitivity or restricted handling to limit consultation. Common examples“don’t contact finance”, “this must stay private”, “handle this directly” Technique boundariesOut-of-Band Verification Manipulation contaminates or controls the supposed confirming channel. Verification Suppression seeks to prevent or discredit the confirming step. Confidentiality Pressure uses the claimed sensitivity of a matter to restrict consultation or review. Verification Suppression does not require confidentiality framing. | |||
Providing incomplete, fragmented, or selectively framed information so the target acts without enough context to assess the request independently. | Secrecy, Verification Suppression & Commitment Escalation | Secrecy, Authority, Trust | GOVAVE |
Selective disclosure and context control provides incomplete, fragmented, or selectively framed information so the target acts without enough context to assess the request independently. The attacker may withhold relevant history, present only favourable records, release information in stages, or prevent the target from seeing how separate requests connect. The target may still be permitted to discuss the matter, but the available information has been curated to shape the decision. Confidentiality Pressure restricts consultation because the matter is claimed to be sensitive, while this technique controls the substance and completeness of the information available. Common exampleswithholding relevant history, fragmented instructions, selective screenshots, one-sided account of events, information released only in stages Technique boundariesSelective Disclosure & Context Control limits the information available for assessment. Confidentiality Pressure restricts consultation or review because the matter is presented as sensitive or restricted. | |||
Renewing contact after refusal, disengagement, a stalled interaction, or an attempted report in order to reopen the relationship or request. | Secrecy, Verification Suppression & Commitment Escalation | Familiarity, Commitment, Trust | AVEIRR |
Persistent re-engagement after refusal renews contact after the target has refused, disengaged, stopped responding, attempted to report the interaction, or allowed the request to stall. The attacker may return after a pause, change tone or identity, refer to the earlier exchange, or present a new reason to reopen the relationship. The technique is defined by re-entry after apparent disengagement. Pressure Persistence repeats prompts or requests as an ongoing attrition mechanism, while Long-Game Relationship Cultivation develops the relationship before the operational request. Common examplesreturning after a refusal, new contact after disengagement, reopening a stalled request, contact after a reporting attempt Technique boundariesPersistent Re-Engagement After Refusal returns after the target appears to have disengaged or refused. Pressure Persistence relies on repeated requests or prompts as an ongoing attrition mechanism. Long-Game Relationship Cultivation develops the relationship before the operational request. | |||
Testing how far controls, policies, or verification behaviour can be pushed before escalating further. | Secrecy, Verification Suppression & Commitment Escalation | Commitment, Familiarity, Helpfulness | GOVAVEDTM |
Incremental boundary testing probes how far a person, control, or process can be pushed before meaningful resistance occurs. The attacker begins with a very small exception or informal request that feels disproportionate to challenge and observes whether the target bends the rule. A successful minor bypass becomes precedent for the next request, often supported by "since you helped me last time" or another appeal to consistency. Over time, the target may become desensitised to deviations they would have rejected at the beginning. The method uses a series of small tests to identify weak boundaries and progressively expand the attacker's room to operate. Common examplessmall policy exception, harmless access request, informal process test Technique boundariesIncremental Boundary Testing probes whether a person, process or control will tolerate small deviations. Gradual Commitment Escalation uses earlier participation to make withdrawal harder, while Exception Handling Abuse invokes an existing exception pathway under misleading circumstances. | |||
Making the target feel uniquely trusted, selected, or responsible so consultation or refusal feels inconsistent with the special role they have been given. | Secrecy, Verification Suppression & Commitment Escalation | Obligation, Commitment, Scarcity, Trust | AVEPHM |
Exclusive trust and responsibility framing makes the target feel uniquely trusted, selected, or responsible so referring the request, consulting others, or declining involvement feels inconsistent with the special role they have been given. The attacker may describe the target as the only suitable person, a trusted confidant, or someone chosen for sensitive responsibility. The technique creates a personal or exclusive responsibility rather than relying only on an existing job duty. Duty & Responsibility Exploitation invokes a formal or professional obligation, while Belonging & Community Access Incentives offer inclusion, status or membership as a benefit. Common examples“only you can handle this”, special trusted role, exclusive responsibility, selected confidant, private assignment Technique boundariesDuty & Responsibility Exploitation invokes an existing professional or organisational duty. Exclusive Trust & Responsibility Framing creates a special or personal responsibility presented as belonging uniquely to the target. Belonging & Community Access Incentives offer inclusion, membership or status as a benefit. Exclusive Trust & Responsibility Framing uses special selection to increase responsibility and reduce consultation. | |||
Using time, money, information, policy breaches, emotional investment, or earlier participation to make disengagement feel more costly than continuing. | Secrecy, Verification Suppression & Commitment Escalation | Commitment, Fear, Guilt | AVEPHM |
Sunk-cost and prior-involvement exploitation uses time, money, information, policy breaches, emotional investment, or earlier participation to make disengagement feel more costly than continuing. The attacker reminds the target of what has already been invested or disclosed and presents withdrawal as wasteful, embarrassing, risky, or inconsistent. The target may continue because reporting would expose an earlier mistake, money has already been paid, information has already been shared, or the relationship has become personally important. Gradual Commitment Escalation describes the progressive increase in participation, while this technique uses accumulated cost or prior involvement as the pressure point. Common examplesmoney already paid, information already disclosed, time already invested, exception already granted, earlier breach feared to be reported Technique boundariesGradual Commitment Escalation describes progressive participation that makes withdrawal harder. Sunk-Cost & Prior-Involvement Exploitation uses accumulated time, money, disclosure, risk or emotional investment as the reason to continue. | |||
Entering a controlled area through another person’s authorised access, whether unnoticed or with that person’s assistance. | Physical Access Facilitation | Familiarity, Social Proof, Helpfulness | DTMPHYPHM |
Tailgating and piggybacking enter a controlled area through another person’s authorised access, whether unnoticed or with that person’s assistance. The attacker follows closely through a door, asks someone to hold it, carries items that make badge use difficult, or otherwise turns a controlled entry into a social interaction. The technique is defined by using another person’s entry rather than receiving a separate access decision. Gatekeeper Access Manipulation applies where a receptionist, guard, sponsor, or other gatekeeper actively admits, badges, or escorts the attacker. Common examplestailgating through secure door, piggybacking into office, controlled area entry Technique boundariesTailgating & Piggybacking use another person’s authorised entry without a separate access decision for the attacker. Gatekeeper Access Manipulation causes a gatekeeper to make or execute an access decision. | |||
Using badges, uniforms, tools, equipment, or other visual identity cues to make a physical role appear legitimate. | Physical Access Facilitation | Familiarity, Social Proof, Trust | DTMPHYPHM |
Badge, uniform and identity mimicry uses physical appearance and role-specific artefacts to signal legitimacy. Branded clothing, high-visibility equipment, hard hats, lanyards, badges, access cards, tools, clipboards, or packages are selected to match the kind of person staff expect to see in the environment. The mimicry is designed to pass a quick visual check rather than detailed verification. A badge may look correct from a distance while lacking expected formatting or access markings, and a borrowed or expired card may still support the appearance of belonging. The method uses recognisable physical identity cues to reduce the likelihood that staff stop and verify the person behind them. Common examplesfake badge, branded uniform, high-visibility clothing, fake access card Technique boundariesPhysical Role Impersonation is the claimed onsite role or function. Badge, Uniform & Physical Identity Mimicry uses badges, clothing, equipment or visual identity cues to support that claim. | |||
Influencing a person who controls or administers physical entry to admit, badge, escort, or otherwise grant access without the required verification or authorisation. | Physical Access Facilitation | Helpfulness, Authority, Urgency | AVEDTMPHYPHM |
Gatekeeper access manipulation influences a person who controls or administers physical entry to admit, badge, escort, or otherwise grant access without the required verification or authorisation. The target may be a receptionist, security officer, facilities contact, sponsor, or another person who can execute an access decision. The attacker may claim a forgotten badge, delayed sponsor, urgent delivery, executive meeting, or operational need and use helpfulness or authority to turn missing verification into an access decision. Physical Security Process Exploitation targets weaknesses in visitor, badge or exception administration rather than primarily influencing the individual gatekeeper. Common examplesreception admission, security-desk badge issue, visitor escort request, sponsor substitution, frontline access exception Technique boundariesTailgating & Piggybacking use another person’s entry without a separate access decision for the attacker. Gatekeeper Access Manipulation causes a gatekeeper to make or execute an access decision. Physical Security Process Exploitation targets weaknesses in visitor management, badge administration or physical-access exceptions. Gatekeeper Access Manipulation focuses on influencing the person who grants or facilitates entry. | |||
Influencing a person to permit temporary handling, proximity, viewing, or use of a device, document, token, key, badge, or other asset while it remains within the controlled environment. | Physical Access Facilitation | Trust, Authority, Helpfulness, Urgency | DTMPHYPHM |
Asset and device access facilitation influences a person to permit temporary handling, proximity, viewing, or use of a device, document, token, key, badge, printer, or other asset while it remains within the controlled environment. The access may be presented as maintenance, support, inspection, convenience, or an ordinary operational need. The technique concerns temporary exposure or use rather than release or removal. Asset Egress & Release Manipulation applies where the item is handed over, signed out, collected, redirected, or removed from the controlled environment. Common examplestemporary laptop handling, viewing a document or screen, access to a printer or token, using a device onsite, proximity to badges or keys Technique boundariesAsset & Device Access Facilitation applies while the asset remains within the controlled environment. Asset Egress & Release Manipulation applies where the item is handed over, signed out, collected, redirected or removed. Network & Infrastructure Access Facilitation applies where a person or access process permits connection, placement or interaction with technical infrastructure. | |||
Moving through or testing access to internal areas beyond the person’s authorised scope to identify where challenge, barriers, or stronger controls occur. | Physical Access Facilitation | Familiarity, Social Proof | DTMPHYPHM |
Restricted area probing moves through or tests access to internal spaces beyond the person’s authorised scope to identify where challenge, barriers, or stronger controls occur. The attacker may try doors, follow movement between zones, wander beyond a visitor area, or use confident behaviour to see how far they can progress before being challenged. The technique requires movement or attempted movement through unauthorised internal areas. Physical Observation & Environmental Reconnaissance is primarily concerned with gathering information about the environment and can occur without testing access boundaries. Common examplestrying internal doors, moving beyond the visitor area, testing challenge behaviour, following staff into controlled zones Technique boundariesRestricted Area Probing involves movement or attempted movement through unauthorised internal spaces. Physical Observation & Environmental Reconnaissance is primarily concerned with gathering information about the environment, routines or physical controls. | |||
Blending into expected operational or physical environments to avoid scrutiny. | Physical Access Facilitation | Familiarity, Social Proof | DTMPHYPHM |
Environmental blending makes the attacker look and behave like someone who naturally belongs in the surrounding physical environment. Clothing, equipment, pace, posture, language, and timing are aligned with staff, contractors, parents, event attendees, delivery workers, or other groups expected to be present. Walking purposefully, carrying familiar tools or bags, entering with a group, and using local room or department names can make a person seem embedded even when no one recognises them. The method reduces the social trigger to challenge by matching the environment's visual and behavioural baseline closely enough that the attacker becomes background rather than an exception. Common examplesdressing like staff, carrying tools, acting familiar onsite Technique boundariesEnvironmental Blending uses clothing, equipment, timing, movement and behaviour to fit the setting. Physical Role Impersonation is defined by the false onsite role, while Badge, Uniform & Physical Identity Mimicry uses visual identity cues to support that role. | |||
Exploiting weak visitor management, access control, badge issuance, or exception procedures. | Physical Access Facilitation | Displaced Responsibility, Authority, Helpfulness, Urgency | GOVAVEDTMPHYPHM |
Physical security process exploitation targets weaknesses in visitor management, badge issuance, access control, and exception procedures. Manual sign-in books, paper lists, temporary passes, shared reception inboxes, informal handovers, and after-hours approval paths can create gaps between the people responsible for physical access. A forgotten badge, emergency call, lost-and-found card, shift change, event registration period, or busy reception window may be used to obtain entry without strong verification. The attacker relies on process fragmentation and temporary exceptions rather than defeating the access technology directly. The method turns weak physical access administration into a path through the control. Common examplesmanual sign-in bypass, temporary pass abuse, after-hours access request Technique boundariesPhysical Security Process Exploitation applies to visitor management, badge issuance, access-control administration and physical-access exceptions. Exception Handling Abuse applies more broadly across organisational processes. | |||
Influencing a person or physical-access process to permit connection, placement, or interaction with network ports, communications equipment, access-control infrastructure, shared endpoints, or other technical systems. | Physical Access Facilitation | Trust, Authority, Helpfulness | MPEDTMIRRPHY |
Network and infrastructure access facilitation influences a person or physical-access process to permit connection, placement, or interaction with network ports, communications equipment, access-control infrastructure, shared endpoints, or other technical systems. The attacker may present the activity as maintenance, troubleshooting, testing, installation, or an approved operational task. The human or access-process decision must materially enable the technical interaction. Direct technical activity after entry, without further influence or access facilitation, is not social engineering by itself. Physical Baiting applies where a placed or discovered object induces another person to connect or use it. Common examplespermission to connect to a network port, placement of a device, access to communications equipment, interaction with access-control infrastructure, use of a shared endpoint Technique boundariesPhysical Baiting applies where a placed or discovered object induces another person to connect or use it. Network & Infrastructure Access Facilitation applies where access to technical infrastructure is granted, exposed, or enabled through a manipulated physical interaction or access process. | |||
Influencing a person or process to hand over, sign out, redirect, collect, or remove an asset without the required identity, authority, destination, or custody checks. | Physical Access Facilitation | Displaced Responsibility, Authority, Familiarity, Urgency | AVEDTMPHYPHM |
Asset egress and release manipulation influences a person or process to hand over, sign out, redirect, collect, or remove an asset without the required identity, authority, destination, or custody checks. The item may be a laptop, badge, key, token, document, device, storage media, or another controlled asset. The attacker may claim that a manager, courier, supplier, employee, or service team authorised the movement and present the current target as responsible only for completing the handover. Asset & Device Access Facilitation applies where temporary access or use occurs while the asset remains within the controlled environment. Common exampleslaptop pickup, device handover, courier collection, asset redirection, badge or key release Technique boundariesAsset Egress & Release Manipulation concerns handover, sign-out, redirection, collection or removal. Asset & Device Access Facilitation concerns temporary access or use while the asset remains within the controlled environment. Logistics & Delivery Workflow Exploitation concerns manipulation of the delivery or logistics process and may also apply where that workflow produces the asset release. | |||
Manipulating shipment, courier, customs, collection, redirection, handling, fee, or delivery-exception processes to influence access, payment, release, or destination decisions. | Third-Party & Supply Chain Exploitation | Urgency, Familiarity, Authority, Trust | FSTAVEDTMPHYPHM |
Logistics and delivery workflow exploitation manipulates shipment, courier, customs, collection, redirection, handling, fee, or delivery-exception processes. The attacker may change a destination, introduce a new courier, claim a blocked delivery, request an urgent fee, or use the workflow to gain site access or obtain an asset. The technique is defined by manipulation of the logistics or delivery process. Physical Role Impersonation concerns the claimed courier or logistics identity, Gatekeeper Access Manipulation concerns the access decision, and Asset Egress & Release Manipulation concerns the decision to hand over or remove an asset. Common examplesshipment redirection, false courier instruction, customs or fee request, delivery exception, changed collection details, logistics-based site access Technique boundariesLogistics & Delivery Workflow Exploitation concerns manipulation of the delivery or logistics process. Physical Role Impersonation concerns the claimed courier identity, while Asset Egress & Release Manipulation concerns the decision to release or remove an asset. | |||
Abusing a genuine supplier, contractor, partner, consultant, or service-provider relationship, participant, or business channel beyond its authorised scope or purpose. | Third-Party & Supply Chain Exploitation | Trust, Familiarity, Displaced Responsibility | FSTAVEDTMIRRPHM |
Established third-party relationship exploitation abuses a genuine supplier, contractor, partner, consultant, service-provider relationship, participant, or business channel beyond its authorised scope or purpose. The relationship itself is real, but the request may be malicious, coerced, compromised, mistaken, or outside the agreed engagement. A real contract, known contact, authentic channel, prior service history, or established workflow can make the changed request feel trustworthy. Supplier, Vendor or Partner Impersonation uses a false external identity. Compromised Account Impersonation may also apply where a genuine third-party account is under attacker control. Common examplesgenuine supplier employee making an unauthorised request, compromised supplier channel, malicious or coerced contractor, real contract used to support an out-of-scope action, authentic relationship history used for a changed request Technique boundariesSupplier, Vendor or Partner Impersonation uses a false external identity. Established Third-Party Relationship Exploitation uses a genuine relationship, participant or business channel whose trust is being abused. Compromised Account Impersonation may also apply where a genuine third-party account or authenticated session is under attacker control. Third-Party Access Path Exploitation applies where the authorised external access path itself is used or extended beyond its intended scope or period. | |||
Using or manipulating authorised supplier, contractor, partner, guest, integration, or external-administrator access beyond its intended purpose, scope, ownership, or period of need. | Third-Party & Supply Chain Exploitation | Trust, Authority, Familiarity, Displaced Responsibility | IDAFSTAVEDTMIRR |
Third-party access path exploitation uses or manipulates authorised supplier, contractor, partner, guest, integration, external-administrator, or managed-service access beyond its intended purpose, scope, ownership, or period of need. The path may involve accounts, VPN access, badges, integrations, guest identities, shared administration, or other trusted access arrangements. The technique remains within the social engineering catalogue where a person, relationship, approval, or access-management process is materially manipulated. Direct use of stolen third-party credentials without associated human or workflow manipulation is not social engineering by itself. Common examplesstale contractor account, supplier VPN access, overprivileged external administrator, guest or partner account, contractor badge, third-party integration, access extended without an owner Technique boundariesThird-Party Access Path Exploitation concerns genuine authorised external access used or extended beyond its intended scope or period. Access Provisioning Workflow Manipulation concerns the organisational process used to create, reactivate or change access. Established Third-Party Relationship Exploitation concerns abuse of the external relationship or business channel. Third-Party Access Path Exploitation concerns the authorised access path itself. | |||
Using trust in a software supplier, package source, repository, integration, or update channel to influence approval, installation, import, or acceptance of software or components. | Third-Party & Supply Chain Exploitation | Trust, Authority, Familiarity | FSTAVEMPEDTMIRR |
Software supplier and update trust exploitation uses trust in a software supplier, package source, repository, integration, or update channel to influence approval, installation, import, or acceptance of software or components. The interaction may refer to a genuine supplier relationship, maintenance window, security update, package dependency, or integration requirement. The technique covers the human decision point rather than every technical supply-chain compromise. An actual compromised build, repository, dependency, or distribution mechanism may underlie the interaction, but should not be assumed merely because a fake vendor update was presented. Malicious Software & Remote-Access Tool Installation concerns direct persuasion to install attacker-supplied tooling. Common examplesfake or abused supplier update, package or repository trust, integration approval, software component import, vendor installation request Technique boundariesSoftware Supplier & Update Trust Exploitation relies on perceived legitimacy of the supplier or software distribution path. Malicious Software & Remote-Access Tool Installation concerns direct persuasion to install attacker-supplied tooling, while fake notification or support techniques concern the artefact used to present the instruction. | |||