1. Collect
Public profile metadata and recent posts/replies from supported platforms (X, Bluesky).
Methodology
A transparent pipeline: collect public data, extract behavioural features, score against published rules, and explain every flag with evidence.
Public profile metadata and recent posts/replies from supported platforms (X, Bluesky).
Behavioural features: posting rhythm, engagement asymmetry, content reuse, thread shape.
Rule engine combines signals into a 0–100 likelihood score with tier and confidence.
Each flag shows the underlying posts, metrics, and rule rationale in plain language.
Sample report
Same report surface as a live scan — score, findings, charts, and plain-language evidence. Synthetic data; try a real handle with a free scan.
Almost nothing they post is original — the account mainly exists to boost other people's content. That's the classic shape of a narrative spreader or political spam network.
Also resembles: Reply farm, 24/7 poster, Grift / promo account
We found 40 warning signs, and they fit together: this account posts and engages like a broadcast or farm operation, not someone casually scrolling and tweeting.
The posting habits, the way they engage, and the kind of content they share all tell the same story — this doesn't read like someone using the app for themselves.
Coordination Watch
“Breaking narratives | alpha drops | DM for promo rates https://t.co/grift”
Low reciprocity means the follow graph isn't mutual social life — often follow-spam or purchased networks.
The strongest of the 46 signals below.
Active in 22 different hours over the last week with no 4-hour quiet stretch — and the pattern doesn't sit cleanly in any one timezone. That's what we'd expect from automation or someone posting without a real day/night rhythm.
Only about 5% of what we sampled is original. That's the shape of an amplifier — little personal voice, mostly boosting other people's posts.
This is the way. Everyone needs to see this. #crypto #alpha This is the way. Everyone needs to see this. #crypto #alphaView post →
Don't sleep on this opportunity #cryptoView post →
The bio has money-making keywords or dodgy short links — the kind of setup scammers and promo bots use to look legit.
About 60% of replies we could check looked off-topic — common with auto-reply tools and spam bots.
They replied
So true!!
To this post
Our peer-reviewed paper on Arctic ice loss is out — full methodology in the thread.View reply →
They replied
Great post
To this post
City council voted 7–2 to expand the library budget for after-school programs.View reply →
One-way megaphones — lots of outbound, almost no inbound — are a hallmark of engagement farms, not social use.
So true!!View post →
Great postView post →
Repeating spam templates is how low-effort farms scale. Real marketers still vary the pitch.
Facts. Share this everywhere.View post →
Facts. Share this everywhere.View post →
Accounts created after the platform changed hands arrived in a wave of inauthentic sign-ups. Timing alone is weak — stronger when other flags stack.
Aggressive follow-spamming with almost no follow-back is a growth-hack pattern, not mutual discovery.
They push content and replies outward far more than they ever come back to conversations on their own posts — more megaphone than participant.
So true!!View post →
Great postView post →
50 followers and 2,500 following. They follow huge numbers of people while far fewer follow back — a common growth-hack pattern.
Real people cluster in waking hours. A flat skyline with no quiet stretch often means automation or shift workers running the account.
Quiet for weeks, then a sudden flood, often means the account was switched on for a campaign — not someone casually checking in more.
Normal users mix originals and replies. Feeds that are almost only replies or reposts often exist to amplify someone else's message.
We bucket posts by the words they use most. A feed glued to crypto, promo, or bait language looks different from mixed everyday interests.
Real people swing between moods. Feeds stuck at one emotional extreme often exist to provoke, sell, or push a single narrative.
Full list — items already shown above are collapsed.
A month of heavy output is a stronger tell than a busy day — real lives rarely sustain that pace without help.
Fresh accounts usually start quiet. Huge history this early often means scripts, purchased history, or a recycled farm handle.
People sleep, work, and take breaks. Day-after-day volume at this level is hard to sustain by hand — automation or a farm shift is the usual explanation.
Natural posting is messy. Near-metronome gaps are a classic timer or scheduler signature.
Genuine accounts usually get some replies back. Near-zero inbound suggests nobody is treating this as a real person.
So true!!View post →
Great postView post →
Empty praise ('great post', 'so true') is cheap to template. Lots of it usually means engagement farming, not a point of view.
So true!!View post →
Great postView post →
Three months of sustained firehose activity is rarely casual use; it usually needs tooling or a team.
Engagement bait exists to farm likes and replies. Heavy use is a growth tactic, not conversation.
Only 0 tweets stored locally. The more profiles you run, the better copy-paste detection gets.
We haven't tracked this account before. Run it again in a week or two to see if followers spike unnaturally.
Prefer a dedicated page? Open the full sample report →
BotShark is not a black box. Every report is built from observable public behaviour — posting cadence, who an account engages with, how replies cluster, whether phrasing repeats across threads, and whether activity fits human sleep/wake patterns.
We deliberately separate the score from a verdict. A high tier means multiple independent signals align with automation or coordination heuristics — not that an account is guilty of anything. You get the evidence; you decide what it means in context.
Deep mode optionally expands thread analysis for reply-network sampling. Follower audits sample public follower cohorts for creation-cluster and coordination cues. Both modes show their work in the report.
Scoring thresholds are not guesses. We test them against a labelled set of known bot and human accounts, measure precision and recall at each score cutoff, and revise the rules when the data says a threshold is wrong — the same discipline you would expect from a published research method, not a vendor black box.
That evaluation runs continuously as the rule set changes. Current methodology and calibration results are published on the methodology page.