Albert Einstein was once quoted as saying “Imagination is more important than knowledge. For knowledge is limited to all we now know and understand, while imagination embraces the entire world, and all there ever will be to know and understand”.
I believe this is very appropriate to social engineering today, and could be what separates someone being successful or not in their abilities to persuade and influence. Remember as a child how you could imagine anything, invisible friends, a scribble on some paper could tell a life’s story, you could make anything and everything from a cardboard box and a toilet roll. To top it all off, you had every adult wrapped right around your finger. As we grow and develop into adulthood we learn new expectations on behaviour and interaction, and we struggle to observe anything that isn’t blindly obvious and poo poo the impossible.
What got me thinking about all this was some new research that has been going on around influence and hypnosis, and imagination is a key attribute to some of the success. I have been doing a small amount of research on this myself (hoping to get some video together for future talks) and I have found imagination can be a powerful frame. Those of you who have done any reading on NLP will know that imagination is a key word in language, and if you have looked into neuroscience you will know that some studies with MRI scanners have shown that when we imagine a situation, the same parts of the brain are stimulated, we can feel the associated emotions and our senses are stimulated.
So why do I think this is going to help you on your social engineering engagement, well I have three things based on the way I do things.
- We all know how important the pretext is, you have done your recon and research, and you know how you are planning to approach your target. So now you have to BE your character. Imagination is an awesome way to achieve this. Imagination what it would be like for you to go about your day as this character, what would your mannerisms be, how would you handle conflict, whats your opinion on yourself and your job? This might sound obvious, but if this is the first time using this character it would be well worth sitting in a chair for 15 minutes or so and just carrying out this exercise. Then when it comes to actually doing this for real, you have been there before in your imagination, so there will be some sense of familiarisation. Its basically DÃ©jÃ vu.
- Utilise the imagination language. Factual information is important, however it can also be restrictive. When we include key words in conversation such as imagine, experience and feel we are requesting the mind run that scenario, asking them to mentally go on the journey we describe, or recall a similar situation of their own experience. You need to take somewhat of a gamble at times that you are going to invoke the emotions you want for your influencing desires are. If you have set yourself up as an engineer, and gaining entry is reaching some challenge, you could talk about not believing you forgot your badge, how you feel embarrassed and cant imagine the trouble your going to be in for not repairing / replacing the device. This will help to build the rapport you need to get the person on your side, to then execute other stages of your planned attack (Don’t forget your multiple outs).
- If you are magically inclined like myself you may want to try out some imagination research. I have discussed before about my opinions on Hypnosis, what it is or isn’t, but I still think really its all just language. So whats my point. Well, there are constantly all sorts of Psychology studies and research going on, so I thought I would use this to my advantage. So I become the annoying research person with the clipboard, researching how good peoples imagination is, based on age, sex, industry they work in etc. This is all kinda irrelevant, but facilitates the pretext of whats coming. From here I go into the Non Trance approach of a hand stick or similar, then the name amnesia, and its during this interval before bringing the name back information of value is extracted. This information could be passwords, pin numbers, ID badge, all sorts. Everyone has different imaginations and different barriers internally so results will be varied. I am still trying to get consent for video footage to show this approach in a non targeted approach, so you can just get an idea of how it works.
So this is why I think imagination is very powerful. You may not know all the answers, you may not know what someone who actually does that role would do, but you can take a stab at it and imagine it based on your research and observations. All of which will leave you better prepared than someone who hasn’t done this. At this point I think there is value in pointing out some research on airplane crash survivors. Many survivors of plane crashes who managed to escape the wreck said the reason for the miracle escape was that they had played the scenario out in their mind many times. What would it be like, how would I get out, what would the likely route be, what obstacles would I face. So when it became reality they had better preparation, and where able to remain calmer and tackle the challenge of escape more successfully that their fellow passenger.
* Disclaimer – I share this information based on my own research and experiences. Should you decide to try out any of these techniques I am not responsible for the outcome, I say this as not everyone reacts well to being duped, and I have had people be a little peeved when they realise they have given or disclosed information, and even after explaining (and rightly so perhaps) are not the best of sports.