What evidence may show automation rather than manual activity?¶
Automation may be shown by repetition, timing, scale, configuration and consistent execution patterns.
Evidential caution: that regular or high-volume activity automatically proves a bot.
What this means¶
Useful indicators may include:
very short intervals;
identical request structure;
large target lists;
consistent errors;
scheduled execution;
API use;
script or tool artefacts;
parallel activity;
machine-generated identifiers;
tasking or configuration files.
A person can also copy and paste repeated commands.
A bot can deliberately vary timing and content.
No single pattern is decisive.
Automation may leave consistent process, API or scheduler identifiers even when timing is deliberately varied. Correlate those technical markers with output and target selection. Behavioural regularity alone is weaker than direct evidence of the mechanism.
Legitimate schedulers, monitoring systems and integration platforms can generate highly regular activity. Compare service accounts, approved workflows, target lists and business purpose before treating mechanical consistency as malicious automation.
================================================================================
What to check or do next¶
- Investigators should compare the activity with legitimate automation used by the organisation or provider.
- Preserve the mechanism where possible, including scripts, scheduler entries, process activity, API keys, service accounts and output files.
- Record the evidential limitation explicitly. The operational takeaway is:
- Use timing, repetition, scale and tool evidence together to support automation, and distinguish the automated mechanism from the person who configured or benefited from it.
Evidential limits¶
It may not.
Where only external records exist, report the conclusion as supported rather than certain if the underlying tool cannot be identified.
Where the mechanism cannot be recovered, state that limitation and avoid presenting patterned activity as conclusive proof of automation.