Skip to Content
The Art of Attack
book

The Art of Attack

by Maxie Reynolds
August 2021
Beginner to intermediate
304 pages
7h 15m
English
Wiley
Content preview from The Art of Attack

Chapter 6Information Processing: Observation and Thinking Techniques

A long habit of not thinking a thing wrong, gives it a superficial appearance of being right… Time makes more converts than reason.

—Thomas Paine

Processing information to weaponize and leverage is a neccessary cognitive skill to get into the attacker mindset and use it to its greatest potential. To process information, you have to collect it. You can collect information four main ways: by obtaining, observing, theorizing, and inferring. If you choose the latter two, you will then have to search for information to validate your thoughts.

After you have collected the information, you have to parse it. You will then put it in one of these three buckets:

  • Recon: Made up of information that familiarizes you with your targets and their environments
  • Pretext: Consists of information that you can directly weaponize in order to disguise yourself as a threat
  • Disregard: Consists of items that aren't useful in either of these ways—information you simply dismiss

Once you've decided which bucket the information should go in, you have to weaponize it within its limits, which means not stretching the information for more than it's worth. For example, knowing a company uses Splunk doesn't permit you to call up impersonating a system administrator, security engineer, or Splunk administrator. You will likely not have enough information to fulfill your call objective if you hope to learn more than just how the organization reacts ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

The Goal

The Goal

Eliyahu M. Goldratt, Jeff Cox
Storytelling with You

Storytelling with You

Cole Nussbaumer Knaflic
The Art of Social Engineering

The Art of Social Engineering

Cesar Bravo, Desilda Toska
The Manager's Path

The Manager's Path

Camille Fournier

Publisher Resources

ISBN: 9781119805465Purchase Link