With a green deerstalker cap, a blue and green plaid shawl covering her shoulders and a pipe resting in her right hand right below her mouth, it was almost impossible to tell the difference between Sherlock Holmes and Elizabeth Rasnick. But that was the point— social engineering is all about deception.
Holmes was the original social engineer, argued Resnick, assistant professor at the University of West Florida’s Center for Cybersecurity and Artificial Intelligence (AI). During DEF CON 34, she drew parallels between current social engineering techniques and Holmes’s own playbook as described in the detective tales. Her session highlighted how important it is for organizations to continually prioritize the human element when it comes to social engineering and security awareness training, despite how difficult that’s proved historically.
Social engineering tactics used to trick users into handing over sensitive information have evolved dramatically with technology. And while AI has enabled threat actors to craft more realistic phishing emails and to scale their attacks, the underlying psychology behind them remains the same: Fear and curiosity still drive human behavior.
Trust is the “real attack surface,” Rasnick said. “Predictable behavior is what makes social engineering possible,” she added.
Same Playbook, Different Year
Threat actors all pull from the same social engineering playbook. They exploit user trust, create a sense of urgency, take advantage of human curiosity, and deploy distraction tactics. That mirrors Holmes playbook: know the target, become believable, create a reason to act, exploit emotion, observe behavior, and adapt, explains Rasnick.
Threat actors’ idea of impersonation today extends as far as using realistic deepfake videos to trick targets. In the detective tales, Holmes also took drastic measures and actually got engaged to a housemaid to collect information while under disguise, she explained.
During the “Know the target” stage, threat actors utilize open-source Intelligence, like scanning social media for details on where someone works. Information gathered before an attack determines how successful a social engineering campaign is, she said.
Once information is gathered, threat actors create a reason for their target to act. Manipulation tactics really play up emotion, making targets sad or scared, or offering the potential for an exciting opportunity.
“We know how people are going to react, and we plan for the reaction,” she said. “That’s what it’s all about.”
Rasnick also compared “Sherlock Holmes: The Red-Headed League,” a story where an organization pretends to be real, to current fake job posting scams where threat actors send phishing links to applicants once they’ve lured them into the trap.
Social engineering “didn’t start with the internet,” she said. “I know it feels like it.”
Holmes vs Moriarty, or Blue Hat vs Red Hat?
Rasnick went on to compare Holmes and his fictional archnemesis, James Moriarty, to modern day defensive and offensive security professionals, demonstrating the fine line between ethical hackers and cybercriminals.
In true professor fashion, Rasnick began the talk with a three-question “Is it Sherlock or is it Moriarty?” quiz. Everyone guessed wrong; Holmes did it all, from reconnaissance to manipulation. His Victorian villain counterpart, in this instance, was innocent.
She went on to explain how Holmes was essentially a modern-day penetration tester. Clients hired him to solve mysteries, and he drew from a six-rule playbook to achieve results. He conducted reconnaissance, built trust, created distractions, instilled urgency, analyzed reactions, and adapted his tactics when necessary. But it was all done by the book.
Moriarity, on the other hand, was a criminal, acting with nefarious intent. He even ran a secret criminal syndicate.
Ethical and non-ethical hackers are all using the same techniques, she said. While teaching ethical hacking to her students, she explains that the difference is paperwork. Blue hats hired to test systems draw up contracts and submit reports at the end of their engagement. Non-ethical hackers don’t have to worry about that.
“Does it make it better when Holmes does it?” Rasnick posed “The difference is intent and whether you have legitimacy.”


