Getting into character is an important part of being successful on a social engineering engagement. You may be physically impersonating a sales guy, engineer, employee, or you may be carrying out your fiendish work remotely gathering data, and setting up meetings. Either way you should be clear in your mind who you are, who you are engaging with, and what you want out of the activity, you need to be clear on your motivation.

When I think of this, my immature side (say nothing) hears a rather camp actor shouting at the director asking, “what’s my motivation darling”. OK so I am odd, lets use the above imagery to demonstrate the motivation to run through the opposition to score :)

So with this in mind I wanted to quickly talk about something a little NLP’esk that I think you will find helpful, and if full embraced will really help with your attitude, approach, body language, facial expression, tonality and more when carrying out an engagement. This little something is called Mind Scripts, and is something I first heard about when studying cold reading and hypnosis, but have also heard similar approaches from an NLP context, and in sales type books on engaging and building rapport with people. (I am not 100% sure who coined this term, I think it may have been Ian Rowland, but please don’t hold me to that).

So what is a Mind Script? Well a mind script is just a simple, short,concise and positive statement about the activity or interaction you are about to engage in. This statement you repeat to yourself mentally before and during the engagement.

Don’t reject this concept just yet please, as some pointless simplistic activity. You will actually find that you make a huge difference as to how you come across to the person(s) you are interacting with when you you run an appropriate mind script. If you think about it we are unconsciously running a mind script of some kind all of the time, simply waking up and telling yourself its going to be a crappy day, then becomes a script you will be running. This then effects how you interact, attitude and the effect you have on others unknowingly.

Here are a couple of example of a mind script to give you an idea of how simple they are. I then encourage you to try running appropriate scripts before going into meeting, interacting with people one to one as a form of practice. If you think about it, it really does make sense, but I would like to hear from people with their thoughts, comments, success and failures. Obviously remember there is NO FAIL :)

I know you, you know me, I belong here

I like you, you like me, this will go well

I respect you, you respect me, and we will have a good discussion

I am an expert, you know I am an expert, there will be confidence in my recommendations

Hopefully you get the general idea from these brief examples, think positive, be positive. A positive mental attitude, positive things happen to positive people, that’s what I tell myself anyway :)

You know when you see an object, or hear a song and it instantly takes you back to a moment, and you begin to experience feelings and emotions as if you where re living it. This is essentially what anchoring is, and this is an association we can force and link with an action, sound or situation. We can use this via an NLP approach, or using Hypnosis in the form of a post hypnotic suggestion based trigger.

Wikipedia Definition – Anchoring is a neuro-linguistic programming term for the process by which memory recall, state change or other responses become associated with (anchored to) some stimulus, in such a way that perception of the stimulus (the anchor) leads by reflex to the anchored response occurring. The stimulus may be quite neutral or even out of conscious awareness, and the response may be either positive or negative. They are capable of being formed and reinforced by repeated stimuli, and thus are analogous to classical conditioning.

So its all very interesting, but what good is the knowledge of anchoring to anyone. There are many benefits from a treatment perspective, as well as being a professional in general. In both of these scenarios the subject can focus, concentrate and imagine themselves in a situation of peacefulness, happy, or situation where confident assuming this is the goal. When the subject is in this state, reliving, seeing, feeling, hearing everything associated with this experience, and as it builds this can be anchored to a touch to a specific part of the body. The result should now be that this pleasurable, confident feeling or what ever it may be can be instantly associated when the specific part of the body is touched. These anchors don’t last forever so in the case of therapy should be reinforced on a regular basis, but I am sure its clear to see how this can help when perhaps nervous about giving a presentation, or a situation that may make you nervous, triggering the anchor to give you a boost.

I know what your thinking, this is all well and good, but I am a social engineer, I am about manipulation and getting the job done, I am not interested in therapy for others, and trying to cheer people up when they are feeling down. So don’t you think there may be situations where it would be advantageous to bring someone into a cheerful state when you are trying to manipulate them? Are we not more responsive and accommodating when happy, rather than sad? How about creating a situation of confusion or doubt, where there is uncertainty in your presence somewhere.

These are all situations you can generate and then anchor for later use, alternatively if you observe a naturally occurring anchored sequence that could be used to your benefit, you can simply steal that anchor. As with other methods I have described, my standard approach to these techniques is to carry out the work in a non work environment, so in a bar, cafe etc. A simple effect for confusion could be making someone think green was yellow, and then anchoring that confused state to an arm tap. If you decided to go the hypnosis route, its really more a post hypnotic trigger. So you will give someone instruction under hypnosis that at a later date when you show them something, say something or touch them somewhere they will act in a certain way. Under hypnosis the trigger can be alot more detailed, and seems to last for a longer period of time.

Obviously creating the opportunity is the really difficult part, so that will all be dependant on people styles and how touchy feely, both you are your subject are, as obviously for anchoring some physical contact is usually required.

So this is pretty easy for you to practice with a friend or partner, if you look on YouTube you can see various videos of people doing this. Essentially get your friend or partner to close their eyes and remember a time when they felt  a great sense of well being, get them to develop that thought, so they are back there now, seeing what they say, hearing what they heard. As you see the smile, grin or laughter give a firm touch to the right knee (as an example), I normally add the comment of “Thats Right” as you re-experience those emotions now.

Now have them relax and become kinda neutral in feeling, then touch the knee again, this should bring a smile to the face, having them once again experience those positive, enjoyable thoughts, putting them into a happy state. It sounds simple, and it is. Get permission from those you practice with, remember to be responsible and ethical. You can practice anchoring on yourself, however I find trying to focus more difficult as you try and remember what your doing, so leave this until after you are familiar with the process.

We have had our brief introduction to NLP, buts now lets give you some patterns you can try out and put to good use. I will point out that many NLP patterns seem very simple, but you need to remember they are all words we are familiar with. NLP is all about the construction of the sentence, and the use of language in an appropriate context. Be brave and try them out, you may be surprised by the results.

If you check out the resources page I have recommended a couple of books, obviously these will be growing lists over time. The aim of the following is just to give you some examples of NLP Patterns / Sentences to give you some awareness, and to give you something to try out yourself.

As stated before I am not a NLP Practitioner, however the use of language, and understanding how to construct your sentences for manipulation and influence is knowledge worth having. See what you think, give them a go, and then research them further.

Redefinition – Changing the focus of conversation from their point, to your point, and then applying focus with a question. Imagine using this pattern when posing as a network engineer.

The issue is not about me not having my ID badge with me, but about the consequences to the business if I don’t repair the fault with the firewall. Can you imagine the trouble we will both be in if I don’t get this sorted ASAP?

What we are achieving here is refocusing on what is important to you, and using a question to ensure visualisation and consideration for your point of view.

Agreement Framing – Creating an opportunity to voice an opinion and increasing peoples attention through agreement. Imagine using this scenario when looking to get approval for an expensive conference.

I agree that the cost of attending Defcon is expensive, and that is why so much useful information, and valuable networking is available. I would add the issue isn’t the expense, but the value of information and contacts that will be gained from attending.

We take the approach of agreement, as when we state we disagree people shut down and don’t listen. Using agreement is interpreted that we agree with what was said, so we pay attention, and then listen to the additional information.

Interruption – Interrupting or defusing a situation by interrupting the train of thought, and the set out planned activities with a random pattern of information. Imagine a situation during an SE exercise and you are found to be somewhere you shouldn’t be, and someone is all set to escort you out and contact security.

You are approached rapidly, and as the person starts to talk and question you, you blurt out something completely random “Damn I forgot to feed my fish”. In confusion the person starts to question, you interrupt again “I have lovely fish, I bet you would love to see them”. You then move along the conversation, and make your exit as appropriate.

The approach here is really a pattern interrupt. You are stopping someone in their tracks from their planned actions both physical and verbal. You have then added confusion with a random and unrelated statement. When the question begins, you again interrupt. This is about changing perception and even where possible build rapport. Approach this one with caution is my advice, unless a close get away is available, it may result in receiving physical harm :)

Awareness – Bringing attention and focus to a topic, using language that will help visualise the topic / concept.

Do you realise how powerful NLP patterns can be to a social engineer? Imagine the experiences you will be able to achieve with this new found knowledge.

The objective of the awareness pattern is to provide information, that ensures people become aware of a topic, this may be subconscious but it will often not be questioned. In the event of questioning it could be followed up with another similar pattern.

Obviously these are just a few examples, there are many defined patterns in many books. The idea here is for you to get some examples, you can then spot them when you hear them, and easily create your own.

Not long after kicking off Head Hacker, I got speaking to Mike Murray. I am sure many of you will be familiar with his thoughts and work in the SE space. Well he made me aware of a recent project he has also kicked of which is NLP for Social Engineers.

As Mike rightly pointed out, we share some common thoughts, and there is some overlap. I have now listened to his first two episodes, and have enjoyed the content.

So I recommend you take some time, subscribe and see what you think. Please feel free to share your thoughts with both Mike and myself.

Mentalism. I am sure you will have heard the term mentalism, or someone telling you they are a mentalist, and I am sure you probably agreed. Thought they are a nut case, and should be put into a straight jacket and wheeled off to the funny farm. Mentalism in this context is not quite the same.

Wikipedia Definition – In psychology, mentalism refers to those branches of study that concentrate on mental perception and thought processes, like cognitive psychology. This is in opposition to disciplines, such as behaviorism, that see psychology as a structure of causal relationships to conditioned responses and seek to prove this hypothesis through scientific methods and experimentation.

Mentalism is a performing art in which its practitioners, known as mentalists, provide their audiences with a theatrical experience of witnessing or participating in demonstrations that appear to utilize highly developed mental or intuitive ability. These demonstrations may include telepathy, clairvoyance, divination, precognition, psychokinesis, mediumship, mind control, memorization, and rapid mathematics.

When I am thinking of mentalism I am thinking of a combination of perception, performance, and direction. To categorise yourself as a mentalist is something I am sure many people would not consider doing, but many most likely fit the bill. If you are using skills to build rapport, influence behaviour, mimic and read body language, read facial expressions and other such skills, this is essentially what a mentalist performer is doing.

We will cover different levels of skills, and what forms them in later posts, but skills such as cold reading, behavioural analysis and more, can help us all day to day, and especially when we consider social engineering.

A quick example is facial expressions, eye movement that we can use to our advantage. We can use these skills when in general discussion, persuasion, questioning and more. Some of the following is also discussed in regards to NLP, but this is just a simple example to show some commonalities in people when monitoring eye movement.

The face below represents that of an individual we are looking at them straight on. When you ask someone a question you will see eye movement towards a zone that represents their representational system. Remember everyone is different so we need to build up rapport, and monitor, measure and test for accuracy.

Zone 1 represents Visualistic, Zone 2 Auditory, and Zone 3 Kinaesthetic.

When you ask someone a question that requires them to access buried information in their memory, you will notice their eyes look towards their most dominant zone. Some people remember images better (Zone 1), some people remember how something sounded (Zone 2), and others with feeling and emotion (Zone 3).

To start of you need to ask a question that will trigger old memories, and that will get an honest response. A simple example here could be what was your first pet, or who was your best friend at primary school. Someone who visualises this memory will look up, and picture an image. Those who word better off sounds will look to the side, and hear a persons voice, or associated sound. An individual who feels and experience will tend to look down, recalling the great times experienced and the emotions associated. So this demonstrates we are all different, and that the key is asking the right trigger questions to build up a baseline, before probing further. Its abit like a visual lie detector.

If we look to get a better understanding we can go abit deeper. We can look to identify if a memory is actually being recalled, or if someone is making something up.

So you have determined the predominant zone, and we now use this information to gain extra information. Most people are visualistic people, so if you do struggle to identify it clearly, zone 1 is often a safe bet, just be aware.

If we look at the diagram above, if someone is looking towards area 4 they are most likely accessing a memory, if area 1 they are making something up. Similarly if they look to area 6, this may demonstrate a conflicting issue, perhaps touching on a difficult subject. However area 3 would demonstrate a more emotional response. When we see eyes moving between areas 2 and 5, this will verify the auditory nature, and lingering in area 2 it may signal a lie is being thought up.

The key here is to experiment, identify normal behaviour, measure it against normal questioning, and then under interrogation. Obviously there are many books on this, and this is just a brief overview.

So why did I discuss all this. Well one its interesting, but two it is to demonstrate how this information can be utilised, and one of the tools a mentalist may use to convince someone of their psychic abilities.

With this information we can not only use it to spot who is cheating, we can use this information for other benefits. So when we are explaining something, trying to get someone to buy in. We can focus our language according to the visualisitic, auditory and kinaesthetic representations to improve our chances of success.

Next we shall talk about Neuro Linguistic Programming (NLP). NLP has become more well known over the years now, but there is still some controversy and taboo on the subject.

Wikipedia Definition – Neuro-linguistic programming (NLP) is a controversial approach to psychotherapy and organizational change based on “a model of interpersonal communication chiefly concerned with the relationship between successful patterns of behaviour and the subjective experiences (esp. patterns of thought) underlying them” and “a system of alternative therapy based on this which seeks to educate people in self-awareness and effective communication, and to change their patterns of mental and emotional behaviour”

In the 1970′s Richard Bandler (Maths Student) and John Grinder (Linguistics Professor) came up with a process called “Neuro Linguistic Programming”. This process was derived from studying, and duplicating the work they observed of great communicators and therapists (Erickson, Perls, and Satir). Essentially what this means is they looked and listened, and they replicated what they observed, and tweaked and modified neuro and linguistic components to amazing results in many cases.

Notice I didn’t mention the word science. The reason for this is, the work done to establish NLP wasn’t a science, its a process or art. There is lots of debate on this subject, and if NLP is or isn’t effective. I am not an NLP Practitioner, I just utilise the techniques both in my work and with myself, and find it interesting. If it makes sense and works for you, fantastic,  if not acknowledge what it is and form your own opinion and move on.

So what happens with NLP, what is the art / process involved.

NLP came out of viewing what a therapist is doing, the stance, the words, the process. Then essentially just replication, and testing in a similar way. Then when a process worked, it was documented as to how it was believed to have occurred, and then a pattern was derived. These patterns could then be retested, and tweaked etc etc. These patterns grew overtime, and were improved and expanded based on further observation, experience and testing.

So how do these patterns work. Personally I see alot of similarities here with hypnosis. The patterns, are a structure of words, its how they are delivered, the rapport that is built up, the confidence of the practitioner, and belief of the subject. It important also to understand NLP can be used on yourself or on someone else. So in its simplest form, NLP is about using a structure and language that makes sense and builds credibility, and from this creating a frame to work and build upon. I see it as associating positive thoughts and feelings, and creating association, replace / removing the negative frame.

This may sound confusing, or it may sound strangely simple. Let me put this to you. If someone was to constantly tell you multiple times a day you are bad at something, your terrible, you cant do anything right, etc etc. It wont take long for this association to stick. You will feel bad about yourself, you will fail, as you believe this to be true. If the opposite where to happen, you would feel good about yourself, confident, look to succeed and expect nothing else. Pop Idol and X-Factor shows are a perfect example, some of these people really do suck, but someone has been telling they can sing all their life, and regardless of the facts, they believe they can. :)

The important thing is not to stop questioning. Curiosity has its own reason for existing. One cannot help but be in awe when he contemplates the mysteries of eternity, of life, of the marvellous structure of reality. It is enough if one tries merely to comprehend a little o f this mystery every day. Never lose a holy curiosity.”
-    Albert Einstein

As with the other topics discussed so far, there is alot of material available to read and view. These posts are just aimed as a brief introduction, to give a basic understanding of the theme and principles. They are of course my thoughts and opinions, I encourage people to question, comment, and give them view to make the information available here even more valuable.

Welcome and thanks for visiting the Head Hacker website.

The goal of this site is to discuss the benefits, process, theories and qualities associated with social engineering, and what I consider to be linked skills, products and theories.

So obviously we are going are going to discuss social engineer and the spy and tech tools that we can use once we are in, but we are also going to discuss other skills that you should be aware of, and you can add to your brain toolkit to increase chances of success and take tests further. We will look at Neuro Linguistic Programming, Hypnosis, Influencing and Manipulation skills, methods of Misdirection, Mentalism, Cold Reading and more. I will also mention some possible Magic that may come in handy as part of recon, and relationship building.

The content is going to be based on my experiances, research, thoughts, theories and discussions with other practioners in the various industries.

Feel free to add comments to topics, ask questions and make requests.

I hope you enjoy the content as it develops and grows over time.

Thanks

Dale