Origin
HACT grew out of a book: HACT — Human Adversarial Cognitive Tactics: Fighting Social Engineering, written by Aurélien T. Working through the material, one absence became obvious — the field had rich technical taxonomies but nothing that let defenders name and map a manipulation the way they name and map an intrusion. HACT is the attempt to fill that space, and this site is its living, operational form.
Design rationale
Why a matrix?
Because defenders already think in matrices. Borrowing the ATT&CK grid (tactics as columns, techniques as cells) makes HACT immediately legible to anyone who has used a threat framework — and turns a diffuse subject into something you can point at.
Why thirteen tactics?
They are the recurring objectives an operator pursues against a person — from reconnaissance and pretexting to pressure, extraction and cover. Thirteen is not a magic number; it is the set that covered the documented behaviour without collapsing distinct intents into one bucket.
Why IoH?
Because detection needed a unit. The Indicator of HUMINT Operation is the human echo of the IoC — weak, contextual, and only meaningful in convergence. It is arguably HACT's most original contribution. Read the IoH page.
Why the name?
Human Adversarial Cognitive Tactics states the object plainly: adversarial tactics that operate on human cognition. The acronym HACT keeps it short and framework-like.
Why now?
Because generative AI has industrialised social engineering — deepfake voice, cloned faces, mass-personalised pretexts. The human attack surface is scaling faster than the vocabulary defenders have to describe it.
Status & versioning
HACT is an open proposal, currently maintained by a single author. It is published openly so that practitioners can use, test and challenge it — not to imply an institution or a community that does not yet exist. That honesty is deliberate: a framework about manipulation should not oversell itself.
| Version | Date | Content |
|---|---|---|
| v2 (current) | 2026 | 13 tactics, 57 techniques, HVE, IoH and the rule of three, countermeasure catalogue, AI-augmented threats, documented cases, regulatory mapping (GDPR / NIS2), and this interactive site. |
Contribute
Feedback is genuinely welcome — corrections, a missing technique, a real case, a sharper IoH. The most useful contributions right now are challenges to the taxonomy itself. Reach the author at Livre_OSINT@proton.me or through the GitHub repository.
License & use
The HACT framework and the content of this website are licensed under Creative Commons Attribution 4.0 International (CC BY 4.0): you may share and adapt them, including commercially, provided you credit "Aurélien T. — HACT framework" with a link to this site and indicate any changes. The book HACT — Human Adversarial Cognitive Tactics: Fighting Social Engineering is not covered by that license and remains © Aurélien T., all rights reserved.
This material is published strictly for educational and defensive purposes; the author accepts no liability for any use made of it. HACT is an independent work, neither affiliated with nor endorsed by MITRE.
How to cite
A persistent archival identifier (DOI) can be added later via a repository such as Zenodo; until then, please cite the version and URL above.
Links
GitHub repository · License (CC BY 4.0) · The Matrix · Why HACT? · IoH · Contact: Livre_OSINT@proton.me