Skip to Content
Unmasking the Social Engineer: The Human Element of Security
book

Unmasking the Social Engineer: The Human Element of Security

by Christopher Hadnagy, Paul Kelly F., Paul Ekman
February 2014
Intermediate to advanced
256 pages
5h 1m
English
Wiley
Content preview from Unmasking the Social Engineer: The Human Element of Security

Chapter 6

Understanding Nonverbal Displays of Comfort and Discomfort

Comfort zones are most often expanded through discomfort.

—Peter McWilliams

Whenever I teach a class about social engineering, I cover body language and facial expressions, in a similar manner to the previous chapters of this book. Some students are overwhelmed by all the things they are told to look for and feel that trying to notice too many things will distract them. Instead of trying to come up with tricks to help them notice all the expressions or signs, I tell them to do one thing: Look for signs of comfort and discomfort. Noticing that someone has a certain baseline body language that changes to discomfort can tell you a lot as a social engineer. PK, one of the “truth wizards” mentioned earlier, notes that Dr. Ekman refers to such changes in baseline as “hot spots.” Dr. O'Sullivan, who coordinated research on the “wizard project,” noted that the wizards often cited recognition of such displays while observing their subjects as a factor in their assessments.

Imagine that your target is Ben. Your goal is to start a conversation that will lead to elicitation. As you approach him, you see him sitting with his hands behind his head and a contented look on his face, as shown in Figure 6-1.

Figure 6-1 Ben is content and feeling comfortable and confident.

image

As you start speaking to him, your conversation starts to ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Social Engineering in IT Security: Tools, Tactics, and Techniques

Social Engineering in IT Security: Tools, Tactics, and Techniques

Sharon Conheady
The Art of Deception: Controlling the Human Element of Security

The Art of Deception: Controlling the Human Element of Security

Kevin D. Mitnick, William L. Simon, Steve Wozniak
Social Engineering Penetration Testing

Social Engineering Penetration Testing

Gavin Watson, Andrew Mason, Richard Ackroyd

Publisher Resources

ISBN: 9781118899564Purchase book