US 12,015,633 B2
System and method for conducting social engineering red team campaigns
Jason Thomas, Arlington, VA (US); Zach Seid, Arlington, VA (US); Blake Howald, Northfield, MN (US); James Tuttle, Fairport, NY (US); Spencer Torene, Potomac, MD (US); Hannah Lensing, Herndon, VA (US); Casey Fallin, Fort Campbell, KY (US); Matt Machado, Herndon, VA (US); Berk Ekmekci, Sterling, VA (US); William Garcia, Falls Church, VA (US); and Nathan Maynes, Falls Church, VA (US)
Assigned to Thomson Reuters Enterprise Centre GmbH, Zug (CH)
Filed by Thomson Reuters Enterprise Centre GmbH, Zug (CH)
Filed on Sep. 1, 2021, as Appl. No. 17/464,230.
Claims priority of provisional application 63/073,191, filed on Sep. 1, 2020.
Prior Publication US 2022/0070204 A1, Mar. 3, 2022
Int. Cl. G06F 21/00 (2013.01); H04L 9/40 (2022.01)
CPC H04L 63/1433 (2013.01) [H04L 63/1483 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A computer implemented method for facilitating social engineering campaigns, the method comprising:
maintaining, by a computer, at least one database comprising:
metadata for a plurality of fictional personas;
metadata for a plurality of potential targets;
information for a plurality of social engineering campaigns, including a plurality of campaign scenarios; and
information regarding social engineering successes with respect to at least one of: at least one fictional persona, at least one potential target, at least one social engineering campaign, or a combination thereof;
receiving, by the computer, a selection of a campaign scenario from the plurality of campaign scenarios;
receiving, by the computer, a selection of at least one of the plurality of potential targets;
selecting, by the computer, at least one of the plurality of fictional personas for use in a social engineering campaign based on an expected effectiveness of the at least one of the plurality of fictional personas, the expected effectiveness determined based at least in part on metadata associated with the selected at least one of the plurality of potential targets;
populating, by the computer, a communication template associated with the selected campaign scenario with metadata for a selected target and a selected fictional persona;
sending, by the computer, a communication using the populated communication template to the selected target;
tracking, by the computer, interactions with the selected target;
accessing, by a dialog manager computer, the at least one database, the selection of the campaign scenarios, the selected target, the populated communication template and the tracked interactions with the selected target; and
managing, by the dialog manager computer, a plurality of states and a flow of communications with the selected target.