**How to choose a Persona**
1. **Impersonation Personas (“Persona” in the app)**
Definition: In Breacher, a persona is a profile that the bot uses to impersonate someone during phishing simulations or social engineering engagements.
Each persona consists of:
Name (e.g., “Jason”)\
Language\
Job title\
Company affiliation\
Email, website, and LinkedIn/profile link\
Writing style, custom email signature\
Voice profile (using voice synthesis tools)
Purpose:
Personas can impersonate real individuals (e.g., a known colleague or supervisor), generic business contacts (like someone from Google or Microsoft), or use stock/generic synthetic identities. The persona is later integrated into the script or prompt of simulated phishing/social engineering attacks.
Types:
a. Real people from the company (with personal details and possibly social media integration)\
b. External or generic personas (e.g., Google employee, Microsoft support, etc.)—not necessarily linked to a real individual\
c. Stock/generated personas (using generic voices, especially when no consent or specific person is involved)
Visibility:
Personas are public (available to all users).
2. **User Roles (not personas for attack, but platform user types)**
Admins: Can view, edit, and delete everything, including personas, strategies, templates, etc.\
Basics: Can view personas, strategies, and templates, but cannot edit or add new ones.
3. **Targets**
Targets: These are the individuals (often employees) who are the focus of phishing or social engineering test campaigns. Their details (photo, work info, consent, etc.) are set up before a campaign. The target is not a “persona” as defined above, but the end recipient of the simulation.
4. **Contextual Use of Personas**
You can tailor the persona details (such as a birthday greeting from a supervisor) to make engagement messages highly personalized and convincing.\
The bot’s persona selection depends on the social engineering tactic and the proposed attack vector (e.g., phone call, meeting invite, email, etc.).