Skip to content

Sender Profiles & Brand Assets: Identity & Impersonation Management

Platform Features: Sender Profiles, Brand Assets
UI Locations:
Threat Forge > Sender Profiles (/sender-profiles)
Threat Forge > Brand Assets (/brand-assets)
Associated Engines: PhishStrike (/phishstrike), Live Threat Watch > Brand Monitoring (/brand-monitoring)


1. Executive Summary & Value Proposition

Realistic phishing simulations require authentic identity spoofing and visual fidelity. If a simulation displays a generic sender address or broken logos, employees dismiss it as unrealistic. Conversely, managing corporate brand assets ensures security teams can safely emulate familiar company internal communication styles while actively monitoring for external brand spoofing.

The Sender Profiles & Brand Assets studio allows security teams to manage spoofed sender identities, customize display names, and catalog corporate visual assets for seamless insertion across all simulation scenarios.


2. Core Capabilities

1. Sender Profiles (/sender-profiles)

  • Custom Display Names: Define convincing sender display names (e.g., "Microsoft 365 Support", "Internal IT Helpdesk", "HR Benefits Team").
  • Spoofed Envelope Senders: Configure realistic sender email addresses paired with authorized simulation routing domains.
  • Custom Reply-To Routing: Direct employee email replies to the SimuPhish reply-tracking engine to measure whether employees engage in conversational dialogue with attackers.

2. Brand Assets Library (/brand-assets)

  • Central Visual Repository: Store high-resolution company logos, subsidiary icons, portal backgrounds, and executive signatures.
  • 1-Click Template Injection: Automatically inject official corporate branding into email scenarios and mock landing pages.
  • Brand Protection Integration: Connects directly with Brand Monitoring to track external typosquatting and impersonation domains leveraging your registered visual assets.

3. Business Value

  • High-Fidelity Social Engineering: Accurately replicates the visual cues employees encounter in real-world targeted spear-phishing attacks.
  • Centralized Identity Governance: Maintain approved, legally vetted sender identities across all enterprise simulation campaigns.