home/dictionary/Social engineering

Social engineering

nouncandidate·updated May 12, 2026

A general term for attackers trying to trick people into revealing sensitive information or performing certain actions, such as downloading and executing files that appear to be benign but are actually malicious.

Framework senses

SANS Glossary of Security Terms1 senseview framework →
§1
A euphemism for non-technical or low-technology means - such as lies, impersonation, tricks, bribes, blackmail, and threats - used to attack information systems.
ISACA Cybersecurity Glossary1 senseview framework →
§1
An attack based on deceiving users or administrators at the target site into revealing confidential or sensitive information
Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary1 senseview framework →
§1
A general term for trying to trick people into revealing confidential information or performing certain actions.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 24 sensesview framework →
§1
An attempt to trick someone into revealing information (e.g., a password) that can be used to attack systems or networks.
§2 · sense_2_pending_review
A general term for attackers trying to trick people into revealing sensitive information or performing certain actions, such as downloading and executing files that appear to be benign but are actually malicious.
§3 · sense_3_pending_review
The process of attempting to trick someone into revealing information (e.g., a password).
§4 · sense_4_pending_review
An attempt to trick someone into revealing information (e.g., a password) that can be used to attack an enterprise.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
An attempt to trick someone into revealing information (e.g., a password) that can be used to attack an enterprise.
NIST SP 800-1151 senseview framework →
§1
The process of attempting to trick someone into revealing information (e.g., a password).
NIST SP 800-611 senseview framework →
§1
An attempt to trick someone into revealing information (e.g., a password) that can be used to attack systems or networks.
NIST SP 800-1141 senseview framework →
§1
A general term for attackers trying to trick people into revealing sensitive information or performing certain actions, such as downloading and executing files that appear to be benign but are actually malicious.