HACT — Human Adversarial Cognitive Tactics

The adversarial knowledge base for social engineering & human intelligence (HUMINT) operations — modeled on MITRE ATT&CK®. Every tactic, technique, indicator of operation (IoH) and countermeasure of the HACT anti-social-engineering framework.

A framework by Aurélien T. · Published for educational and defensive purposes only.

MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation. This work and the HACT (Human Adversarial Cognitive Tactics) framework it describes are neither affiliated with, endorsed by, nor sponsored by The MITRE Corporation. HACT draws on the conceptual structure of MITRE ATT&CK® — freely accessible and usable under its terms of use — but is an independent work. This material is published strictly for educational and defensive purposes; the author accepts no liability for any use made of it.

The HACT Matrix — tactics, techniques

Columns are tactics (the adversary's why); cells are techniques (the how). Click any cell for technique detail, or a column header for the full tactic. See also the Mind map, the Flowchart, the Response playbooks and the Arsenal (red-team methods by tactic).

High severity Medium AI-augmented technique

HACT vs MITRE ATT&CK®

ATT&CK describes technical actions against systems; HACT describes cognitive maneuvers against decisions. Same two-level structure (tactics → techniques), different object.

Architecture
CVE → HVE mapping
Persuasion principles

HVE (Human Vulnerabilities and Exploits) are the human equivalent of CVEs: not software bugs but exploitable cognitive biases and psychological needs. A CVE is patched; an HVE is compensated for with structured vigilance.

Detection — Indicators of HUMINT Operation (IoH)

Where cyber uses binary Indicators of Compromise (IoC), human signals are weak and contextual. HACT applies a threshold rule instead of concluding on a single signal.

The rule of three IoH.
Detection scoring
Most-targeted profiles

Source: Check Point / Dimensional Research, 2011, n=853 professionals, 6 countries. New employees should receive SE training within the first 30 days, before any access to sensitive systems.

Emerging AI-augmented threats

Generative AI industrializes social engineering. Click a card for the full indicator table and operational countermeasure.

Documented real-world cases

Each case is mapped to the HACT tactics it activated. Click a tactic tag to open it.


Defense — the five emergency reflexes

The whole framework condensed into five reflexes usable in under sixty seconds when facing any unusual request. See the decision-tree flowchart and the full Response playbooks.

Organizational maturity model

Most organizations sit between N1 and N2. The N2→N3 jump is the most impactful and the cheapest: a 2-hour annual training for at-risk populations plus written procedures for urgent requests. Recommended minimum target: N3.

Regulatory mapping (France / EU)

Implementing HACT countermeasures per tactic simultaneously satisfies several GDPR and NIS2 requirements.

Maximum sanctions

Selected bibliography