home/glossary/Social engineering

Social engineering

nounid 4178·updated Aug 30, 2026
verified· unreviewed

A general term for attackers trying to trick people into revealing sensitive information or performing certain actions, such as downloading and executing files that appear to be benign but are actually malicious.

polysemousMWE

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems3 citations · 3 machine-matched · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.02.01.a.303.02.01.b ¶ 303.02.01.b ¶ 3

Classifications

Entity Type

Threat0%rule-basedmulti_axis_classifier_low_confidence.v1

Sensitivity

60%llm-generatedllm:claude-haiku-4-5

Information Class

50%llm-generatedllm:claude-haiku-4-5

Variants

plural
Social engineerings
possessive
Social engineering's
pluralpossessive
Social engineerings'

Framework definitions

SANS Glossary of Security Terms1 senseview framework →
§1
A euphemism for non-technical or low-technology means - such as lies, impersonation, tricks, bribes, blackmail, and threats - used to attack information systems.
ISACA Cybersecurity Glossary1 senseview framework →
§1
An attack based on deceiving users or administrators at the target site into revealing confidential or sensitive information
Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary1 senseview framework →
§1
A general term for trying to trick people into revealing confidential information or performing certain actions.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 24 sensesview framework →
§1
An attempt to trick someone into revealing information (e.g., a password) that can be used to attack systems or networks.
§2 · sense_2_pending_review
A general term for attackers trying to trick people into revealing sensitive information or performing certain actions, such as downloading and executing files that appear to be benign but are actually malicious.
§3 · sense_3_pending_review
The process of attempting to trick someone into revealing information (e.g., a password).
§4 · sense_4_pending_review
An attempt to trick someone into revealing information (e.g., a password) that can be used to attack an enterprise.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
An attempt to trick someone into revealing information (e.g., a password) that can be used to attack an enterprise.
NIST SP 800-1151 senseview framework →
§1
The process of attempting to trick someone into revealing information (e.g., a password).
NIST SP 800-611 senseview framework →
§1
An attempt to trick someone into revealing information (e.g., a password) that can be used to attack systems or networks.
NIST SP 800-1141 senseview framework →
§1
A general term for attackers trying to trick people into revealing sensitive information or performing certain actions, such as downloading and executing files that appear to be benign but are actually malicious.
NIST SP 800-171r31 senseview framework →
§1 · attested_usage_pack_match
No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
A general term for attackers trying to trick people into revealing sensitive information or performing certain actions, such as downloading and executing files that appear to be benign but are actually malicious.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.