Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is automated offender activity?

Automated offender activity is unauthorised or harmful action performed by software, scripts or services after limited human input. One instruction can produce thousands of scans, login attempts, messages, deployments or transactions.

The repeated events show the automation's output. They do not each represent a separate human decision.

Separate decision, mechanism and output

Automation may run on a schedule, respond to an event or accept later tasking. A successful login, incoming message or newly created account can trigger a workflow without a person acting at that moment.

A useful reconstruction distinguishes:

  • who or what configured or launched the mechanism;
  • scripts, services, accounts and credentials it used;
  • targets, schedules, thresholds and exclusions;
  • events or commands that triggered it;
  • repeated jobs, requests or transactions it produced; and
  • results returned to a controller or stored for later use.

Human-selected parameters can be more revealing than repetitive output. Target lists, timing rules and success thresholds may support conclusions about objective and control.

Automation can outlast active control

Scheduled jobs and event-driven workflows may continue after an operator disconnects or loses access. A long series of events does not necessarily show continuous human involvement, while a later change to configuration may reveal renewed tasking.

Preserve scripts, configuration, scheduler or workflow records, API keys and result logs where available. Attribute human conduct from evidence of configuration, launch and control - not simply from the number of automated events.

Key takeaway

Report the human decision, automated mechanism and resulting events as separate layers; scale and repetition do not prove repeated human intent.

Reference: CIM-272Cyber Incidents & Offender Methods