Skip to content
← LibraryTechnique entry
SE-PRETEXTInitial Access

Pretexting

Plausible cover story (auditor, contractor, courier, fire marshal) that gets the attacker through human checks — usually combined with physical or phone access.

§ Where this technique fits

SE-PRETEXT is catalogued under the Initial Access tactic of the offensive-security kill-chain. It appears in 4 approved dossiers in the registry, typically at step 1.8 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    RFID / Badge Cloning
    SE-RFID-CLONE · Initial Access
    seen 1×
  2. 02
    User Execution
    T1204 · Execution
    seen 1×
  3. 03
    Valid Accounts
    T1078 · Initial Access
    seen 1×
  4. 04
    Vishing (Voice Phishing)
    SE-VISHING · Initial Access
    seen 1×