Detecting social engineering threats
Embodiments detect social engineering threats by analyzing telephony and messaging communications to identify deceptive manipulation tactics. The system employs non-agentic threat evaluation using natural language processing, pattern matching, and statistical analysis to collect social engineering indicators and generate preliminary threat confidence scores. Candidate threats undergo agentic threat evaluation using generative artificial intelligence agents that analyze prompts containing telephony and messaging activity information. The system establishes baseline communication patterns from historical data, then identifies deviations and anomalies exceeding threshold values. Multi-vector threat assessments correlate suspicious activities across communication channels using timestamps to detect coordinated campaigns. The system identifies communications demonstrating personal knowledge references, false authority claims, trust-building attempts, and coordinated manipulation strategies. Validation checks cross-reference telephone numbers against databases of known fraudulent sources and disposable communication services.
1 . A method for monitoring network traffic for threats to network security in a computing environment using one or more network monitoring computers having one or more processors to execute instructions that are configured to cause the one or more networking computers to perform actions, comprising:
obtaining one or more candidate threats based on a non-agentic preliminary threat evaluation of one or more of telephony activity information, messaging activity information, or other user communication activity that is monitored in the network traffic, wherein the non-agentic preliminary threat evaluation employs a criteria including one or more of an urgent request for information, an authority impersonation language pattern, a personal information reference, a timing pattern for communication activity with multiple users, a request to bypass security procedure, knowledge of a non-public project, or a correlation between the telephone activity information and the messaging activity information;
obtaining an agentic threat evaluation of the one or more candidate threats based on one or more prompts that include one or more of the telephony activity information or the messaging activity information, wherein the one or more prompts are used with one or more agents to evaluate the one or more candidate threats and investigate the one or more correlations;
collecting one or more social engineering threats from the agentic threat evaluation, wherein each social engineering threat is associated with one or more deceptive tactics to manipulate one or more behaviors of one or more users, and wherein the one or more social engineering threats are included in a report; and
obtaining a user interface that includes one or more display panels for content that includes the report, other information associated with the one or more social engineering threats and one or more portions of the monitored network traffic, wherein the content is dynamically transformed and arranged for display to a user based on one or more of user interaction telemetry, user feedback or telemetry metrics.
2 . The method of claim 1 , further comprising:
collecting one or more baseline communication patterns for the one or more users based on one or more of previous telephony activity, previous messaging activity, or user communication activity over one or more time periods;
obtaining one or more deviation metrics based on current communication behavior and the one or more baseline communication patterns; and
obtaining one or more anomaly indicators associated with the one or more deviation metrics that exceed one or more threshold values.
3 . The method of claim 1 , further comprising:
obtaining one or more correlations based on one or more timestamps between one or more of a suspicious telephony activity, a suspicious messaging activity, or a suspicious user communication activity over time; and
obtaining one or more multi-vector threat assessments based on the one or more correlations.
4 . The method of claim 1 , wherein the non-agentic threat evaluation further comprises:
using one or more of a natural language processing algorithm, a pattern matching filter, a statistical analysis method, a rule-based detection system, a keyword detection operation, a validation of caller identification, a communication frequency analysis, or a signature matching technique to collect one or more social engineering indicators; and
obtaining one or more preliminary threat confidence scores based on the one or more social engineering indicators.
5 . The method of claim 1 , wherein the telephony activity information further comprises:
one or more of a call history record, a voice conversation transcript, a caller identification result, a call duration measurement, or a communication frequency pattern associated with the one or more users.
6 . The method of claim 1 , wherein the messaging activity information further comprises:
one or more of an email message header, an instant message content record, a sender reputation score, a message authentication result, a video conference metric, content from a video conference, a video call metric, content from a video call, an augmented reality or virtual reality session metric, content from an augmented reality or virtual reality session, or a communication timing pattern associated with messaging exchanges.
7 . The method of claim 1 , further comprising:
modifying the one or more prompts to include one or more of a conversation transcript, a call metadata record with validation results, a caller identification, a target user identification, a message content analysis summary, a historical communication baseline comparison, a sender reputation score, a message authentication result, an email, an email header, an instant message, or a threat intelligence context element.
8 . The method of claim 1 , further comprising:
collecting one or more communications that demonstrate one or more of a personal knowledge reference, a false claim of organizational authority, a systematic trust-building attempt, or a coordinated manipulation strategy across multiple communication channels.
9 . The method of claim 1 , further comprising:
obtaining one or more validation checks that cross-reference telephone numbers against one or more of a database of known fraudulent sources, a disposable communication service, or a previous social engineering threat.
10 . A network monitoring computer (NMC) for monitoring network traffic for threats to network security in a computing environment, comprising:
a network component that communicates over the network;
a memory that stores at least instructions; and
one or more processors that are configured to execute instructions to cause actions, including:
obtaining one or more candidate threats based on a non-agentic preliminary threat evaluation of one or more of telephony activity information, messaging activity information, or other user communication activity that is monitored in the network traffic, wherein the non-agentic preliminary threat evaluation employs a criteria including one or more of an urgent request for information, an authority impersonation language pattern, a personal information reference, a timing pattern for communication activity with multiple users, a request to bypass security procedure, knowledge of a non-public project, or a correlation between the telephone activity information and the messaging activity information;
obtaining an agentic threat evaluation of the one or more candidate threats based on one or more prompts that include one or more of the telephony activity information or the messaging activity information, wherein the one or more prompts are used with one or more agents to evaluate the one or more candidate threats and investigate the one or more correlations;
collecting one or more social engineering threats from the agentic threat evaluation, wherein each social engineering threat is associated with one or more deceptive tactics to manipulate one or more behaviors of one or more users, and wherein the one or more social engineering threats are included in a report; and
obtaining a user interface that includes one or more display panels for content that includes the report, other information associated with the one or more social engineering threats and one or more portions of the monitored network traffic, wherein the content is dynamically transformed and arranged for display to a user based on one or more of user interaction telemetry, user feedback or telemetry metrics.
11 . The NMC of claim 10 , wherein the one or more processors are configured to execute instructions to cause actions, further comprising:
collecting one or more baseline communication patterns for the one or more users based on one or more of previous telephony activity, previous messaging activity, or user communication activity over one or more time periods;
obtaining one or more deviation metrics based on current communication behavior and the one or more baseline communication patterns; and
obtaining one or more anomaly indicators associated with the one or more deviation metrics that exceed one or more threshold values.
12 . The NMC of claim 10 , wherein the one or more processors are configured to execute instructions to cause actions, further comprising:
obtaining one or more correlations based on one or more timestamps between one or more suspicious telephony activities and one or more suspicious messaging activities over time; and
obtaining one or more multi-vector threat assessments based on the one or more correlations.
13 . The NMC of claim 10 , wherein the non-agentic threat evaluation further comprises:
using one or more of a natural language processing algorithm, a pattern matching filter, a statistical analysis method, a rule-based detection system, a keyword detection operation, a validation of caller identification, a communication frequency analysis, or a signature matching technique to collect one or more social engineering indicators; and
obtaining one or more preliminary threat confidence scores based on the one or more social engineering indicators.
14 . The NMC of claim 10 , wherein the telephony activity information further comprises:
one or more of a call history record, a voice conversation transcript, a caller identification result, a call duration measurement, or a communication frequency pattern associated with the one or more users.
15 . The NMC of claim 10 , wherein the messaging activity information further comprises:
one or more of an email message header, an instant message content record, a sender reputation score, a message authentication result, or a communication timing pattern associated with messaging exchanges.
16 . The NMC of claim 10 , wherein the one or more processors are configured to execute instructions to cause actions, further comprising:
modifying the one or more prompts to include one or more of a conversation transcript, a call metadata record with validation results, a caller identification, a target user identification, a message content analysis summary, a historical communication baseline comparison, a sender reputation score, a message authentication result, an email, an email header, an instant message, or a threat intelligence context element.
17 . The NMC of claim 10 , wherein the one or more processors are configured to execute instructions to cause actions, further comprising:
collecting one or more communications that demonstrate one or more of a personal knowledge reference, a false claim of organizational authority, a systematic trust-building attempt, or a coordinated manipulation strategy across multiple communication channels.
18 . The NMC of claim 10 , wherein the one or more processors are configured to execute instructions to cause actions, further comprising:
obtaining one or more validation checks that cross-reference telephone numbers against one or more of a database of known fraudulent sources, a disposable communication service, or a previous social engineering threat.
19 . A processor readable non-transitory storage media that includes instructions for monitoring network traffic for threats to network security using one or more network monitoring computers, wherein execution of the instructions by the one or more networking monitoring computers perform the method comprising:
obtaining one or more candidate threats based on a non-agentic preliminary threat evaluation of one or more of telephony activity information, messaging activity information, or other user communication activity that is monitored in the network traffic, wherein the non-agentic preliminary threat evaluation employs a criteria including one or more of an urgent request for information, an authority impersonation language pattern, a personal information reference, a timing pattern for communication activity with multiple users, a request to bypass security procedure, knowledge of a non-public project, or a correlation between the telephone activity information and the messaging activity information;
obtaining an agentic threat evaluation of the one or more candidate threats based on one or more prompts that include one or more of the telephony activity information or the messaging activity information, wherein the one or more prompts are used with one or more agents to evaluate the one or more candidate threats and investigate the one or more correlations;
collecting one or more social engineering threats from the agentic threat evaluation, wherein each social engineering threat is associated with one or more deceptive tactics to manipulate one or more behaviors of one or more users, and wherein the one or more social engineering threats are included in a report; and
obtaining a user interface that includes one or more display panels for content that includes the report, other information associated with the one or more social engineering threats and one or more portions of the monitored network traffic, wherein the content is dynamically transformed and arranged for display to a user based on one or more of user interaction telemetry, user feedback or telemetry metrics.
20 . The media of claim 19 , further comprising:
obtaining one or more correlations based on one or more timestamps between one or more suspicious telephony activities and one or more suspicious messaging activities over time; and
obtaining one or more multi-vector threat assessments based on the one or more correlations.