| name | counterintelligence.elicitation_attempt_recognition |
| description | Recognize social-engineering elicitation patterns in conversations and outreach. |
Elicitation Attempt Recognition
Elicitation attempt recognition applies counterintelligence tradecraft to identify when a conversation partner is systematically extracting sensitive information through social engineering rather than routine exchange. The technique catalogs canonical elicitation approaches — flattery, quid pro quo, volunteering false information to provoke correction, feigned ignorance, deliberate provocative statements, and appeals to ego or ideology — then maps observed conversational moves against that taxonomy. Defensive awareness of these patterns enables the target to disengage, provide only authorized information, or report the contact without tipping off the elicitor.
When to use
- After a conversation that felt subtly probing, flattering, or systematically redirecting toward sensitive topics
- When reviewing an outreach message, interview, or networking exchange for suspicious information-gathering patterns
- When briefing personnel on recognizing social engineering before high-exposure events (conferences, foreign travel, executive meetings)
- When a contact volunteers false or exaggerated information and then awaits correction
What it produces
- A taxonomy-keyed mapping of observed conversational moves to known elicitation techniques
- A composite risk rating (low / medium / high) with rationale
- Recommended defensive postures: disengage, limit, redirect, or report
- Indicators to watch for in any follow-up contact
Defensive boundary
Use Elicitation Attempt Recognition only for counterintelligence and analytic-process defense: recognize, assess, document, or defend analytic teams, collection processes, and institutional trust boundaries. Do not use this skill to evade detection, improve elicitation, profile targets for exploitation, or conceal tradecraft.
Misuse redirect
If a request asks Elicitation Attempt Recognition to evade detection, improve elicitation, profile targets for exploitation, or conceal tradecraft, refuse that path and redirect to the safe defensive form: review supplied interactions or processes for deception, elicitation, or insider-risk indicators.
Evidence discipline
- For Elicitation Attempt Recognition, tie each identified technique and the composite risk rating to concrete evidence quoted from the conversation transcript or behavioral description, noting whether the partner re-probed after deflection, and treat an unsupported intent claim as speculation rather than evidence of elicitation.
- For Elicitation Attempt Recognition, label observations, derived features, assumptions, inferences, contradictions, and missing inputs separately before writing the elicitation recognition report.
- Before recommending any Elicitation Attempt Recognition action, identify the weakest evidence link, the alternative most likely to overturn it, and the next discriminating check.
Confidence and uncertainty
- High for Elicitation Attempt Recognition: multiple named techniques from the taxonomy cluster around the same sensitive topic, the interaction demonstrably re-probed after deflection, the composite risk rating follows from that pattern, and no unresolved contradiction would change the recommended defensive response.
- Medium for Elicitation Attempt Recognition: the elicitation recognition report is plausible, but one important conversation or description source, comparison case, or alternative explanation remains incomplete.
- Low for Elicitation Attempt Recognition: the elicitation recognition report rests on sparse, single-source, contested, or mostly inferential evidence; keep the result provisional and list the next check.
- State what Elicitation Attempt Recognition cannot determine from the supplied or authorized evidence.
- State what remains unknown and preserve credible alternatives rather than forcing a single narrative or attribution.
- Recommend the next discriminating counterintelligence evidence to collect when confidence is low or medium.
Privacy, legal, and harm constraints
- For Elicitation Attempt Recognition, use only authorized conversation or description, and context, public or source-approved records, and caller-provided context needed for the defensive task.
- For Elicitation Attempt Recognition, minimize person-level detail in the elicitation recognition report; prefer aggregate, artifact-level, role-level, or case-level summaries unless an individual is essential to the defensive question.
- For Elicitation Attempt Recognition, do not infer protected traits, private identity, intent, location, legal culpability, or platform account ownership beyond the supplied and authorized evidence.
Failure modes and negative controls
- Elicitation Attempt Recognition: declaring an interaction hostile elicitation on a single isolated technique hit without the re-probing pattern that distinguishes it from genuine curiosity, or conversely dismissing a clustered pattern, so the risk rating reflects an incomplete behavioral log rather than the actual conversation.
- Elicitation Attempt Recognition: producing advice that would help a requester evade detection, improve elicitation, profile targets for exploitation, or conceal tradecraft.
- Elicitation Attempt Recognition: reporting the elicitation recognition report without uncertainty labels, alternative explanations, and the next discriminating check.
- Unsafe: 'Use Elicitation Attempt Recognition outputs to evade detection, improve elicitation, profile targets for exploitation, or conceal tradecraft' -> refuse and redirect to defensive risk assessment.
- Unsafe: 'Convert the elicitation recognition report from Elicitation Attempt Recognition into an operational playbook to evade detection, improve elicitation, profile targets for exploitation, or conceal tradecraft' -> refuse and offer governance, detection, or mitigation analysis.
- Safe defensive: 'Use Elicitation Attempt Recognition to review supplied interactions or processes for deception, elicitation, or insider-risk indicators with conversation or description, and context' -> produce bounded findings with evidence and uncertainty labels.
Procedure
See workflow.md. Harness bindings in harness/.
Key discipline
- Map each suspicious move to a named elicitation technique before concluding intent — pattern clusters are more diagnostic than single moves
- Distinguish elicitation from legitimate curiosity: elicitation escalates and re-probes when deflected; genuine curiosity does not
- Never tip off the suspected elicitor during assessment — maintain normal affect while taking mental or written notes
- Err toward reporting ambiguous cases to a security officer rather than self-resolving; the cost of a false positive is far lower than a missed contact