TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Black Hills InfoSec

Social Engineering – Sometimes It’s Too Easy

BHIS · 2017-03-14 · Read original ↗

ATT&CK techniques detected

3 predictions
T1566.004Spearphishing Voice
87%
". fourth call “ sorry, resetting your password is against security policy. ” but she did say, “ my heart is in my throat for you, ” so that made me feel better! fifth call i wait two days before making the last call. this time i created a new user account on my windows vm with a …"
T1598.003Spearphishing Link
58%
"social engineering – sometimes it ’ s too easy social engineering – sometimes it ’ s too easy a fun story from an adventure in social engineering not too long ago. thought i ’ d pass on some things i learned and ways to be more prepared in the future. the goal call the it help de…"
T1566.004Spearphishing Voice
52%
"up the windows command prompt which says “ users / carrie roberts ”, not the person i was posing as but this did not appear to raise suspicions. she gives me a new password for the owa account : “ password @ 123 ” and i ’ m in. i ask if i should change my password now and she say…"

Summary

Carrie Roberts // A fun story from an adventure in social engineering not too long ago. Thought I’d pass on some things I learned and ways to be more prepared in the […]

The post Social Engineering – Sometimes It’s Too Easy appeared first on Black Hills Information Security, Inc..