Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is a bot?

A bot is software or an automated account that performs tasks without continuous human control. Bots are not inherently malicious: search indexing, monitoring, customer support and system administration all rely on legitimate automation.

Whether a bot is abusive depends on its authority, configuration, targets and purpose - not simply on the fact that activity is automated.

A bot is not necessarily one account or one machine

Bot activity may use ordinary browser or API functions, so individual requests can appear valid. One controller may operate many accounts and sessions, while one automation platform may execute workflows for many unrelated customers. Account count, device count and operator count should not be treated as equivalent.

Evidence of a bot can include:

  • software, workflow or automation-platform records;
  • tokens, service accounts and session identifiers;
  • tasking, configuration and target lists;
  • repeated execution and result logs; and
  • shared infrastructure or command channels.

These features can connect visible activity to the mechanism that produced it.

Identify each control layer

Distinguish the bot software, the account through which it acts, any platform hosting the automation, and the person or service that configured it. A legitimate platform may neutrally execute an abusive customer's workflow; a visible bot account may be compromised or rented.

Linkage through common tokens, configuration or infrastructure can support shared control, but should be tested against the possibility of a shared service.

Key takeaway

Assess a bot through its mechanism, controller, configuration, targets and purpose, and do not infer one operator from one account - or from many apparently similar accounts.

Reference: CIM-273Cyber Incidents & Offender Methods