What is a bot?¶
A bot is software or an automated account designed to perform actions without continuous human control.
Evidential caution: that every bot is malicious.
What this means¶
Bots may be used legitimately for:
monitoring;
customer service;
indexing;
testing;
administration;
data processing;
security;
notifications.
Malicious or abusive bots may perform:
credential attacks;
scraping;
fraud;
spam;
scanning;
denial of service;
account creation;
content manipulation;
malware tasking.
which software or account acted;
who controlled it;
what instructions or configuration applied;
which targets were selected;
whether the activity was authorised;
what outcome followed.
A bot account may use ordinary web or API functions.
The individual requests may look valid even where the scale or purpose is abusive.
The account may be rented, compromised or controlled through a service.
Bots may also operate through legitimate automation platforms or browser tools. The underlying service may be neutral, while the customer’s configuration is abusive. Preserve platform account, workflow and execution records separately from the visible bot account.
A bot may maintain several accounts, identities or sessions and may hand tasks to other services. Account count should not be treated as bot count or operator count. Link control through shared configuration, tokens, infrastructure and execution records.
Also distinguish the bot software from the account, service and operator controlling it.
Assess bots from controller, configuration, target, scale and purpose, and distinguish legitimate automation from unauthorised or harmful use.
================================================================================
What to check or do next¶
- Investigators should establish:
- Record both separately. The operational takeaway is:
Evidential limits¶
Do not assume the bot account holder is the final beneficiary or operator.