CAPEC-410 Information Elicitation

CAPEC ID: 410

CAPEC-410 Metadata

Likelihood of Attack

High

Typical Severity

Low

Overview

Summary

An adversary engages an individual using any combination of social engineering methods for the purpose of extracting information. Accurate contextual and environmental queues, such as knowing important information about the target company or individual can greatly increase the success of the attack and the quality of information gathered. Authentic mimicry combined with detailed knowledge increases the success of elicitation attacks.

Prerequisites

No prerequisites listed.

Potential Solutions / Mitigations

No specific solutions listed.

Stay Ahead of Attack Patterns

Understanding CAPEC patterns helps security professionals anticipate and thwart potential attacks. Leverage these insights to enhance threat modeling, strengthen your software development lifecycle, and train your security teams effectively.