It is now learning to detect human compromise. That is the mission of HACT.
The gap HACT fills
For years, defenders built shared references to describe attacks against machines. MITRE ATT&CK, the Cyber Kill Chain and the Diamond Model gave analysts a common language: any technical intrusion can be named, mapped and communicated the same way from one team to another.
Social engineering never had an equivalent taxonomy. Manipulation was documented case by case, in narrative form, without a structured vocabulary shared between defenders. The most exploited attack surface — the human decision — remained essentially un-mapped.
HACT proposes a structured approach to close that gap. A two-level matrix (tactics → techniques) names the adversary's cognitive maneuvers, the human vulnerabilities they exploit (HVE), the observable signals they leave (IoH) and the countermeasures that answer them. The goal is not a new theory of persuasion, but an operational reference a defender can actually use during an attack.
Framework first — the book is its reference guide
HACT is the framework. The book HACT — Human Adversarial Cognitive Tactics is its official reference guide: it explains the reasoning, the underlying psychology and the documented cases in depth. This site is the operational surface of the same framework — meant to be searched, mapped and consulted, including in the middle of a suspicious request.
The division of labour is simple: understand with the book, act with the framework. One explains; the other is used every day.
The intellectual family
HACT does not appear from nowhere. It deliberately borrows the structure of the reference frameworks that shaped modern threat analysis, and transposes their logic from machines to human decisions.
HACT transposes these principles to the detection of human-manipulation operations. It enters the same intellectual family — not as a copy, but as the missing piece: the one that describes the attack when its target is a person rather than a system.