1. Collect
Public profile metadata and recent posts/replies from supported platforms (X, Bluesky).
Methodology
A transparent pipeline: collect public data, extract behavioural features, score against published rules, and explain every flag with evidence.
Public profile metadata and recent posts/replies from supported platforms (X, Bluesky).
Behavioural features: posting rhythm, engagement asymmetry, content reuse, thread shape.
Rule engine combines signals into a 0–100 likelihood score with tier and confidence.
Each flag shows the underlying posts, metrics, and rule rationale in plain language.
Sample report
Same report surface as a live scan — score, findings, charts, and plain-language evidence. Synthetic data; try a real handle with a free scan.
Almost nothing they post is original — the account mainly exists to boost other people's content. That's the classic shape of a narrative spreader or political spam network.
Also resembles: Reply farm, 24/7 poster, Grift / promo account
It talks at people a lot (80 replies) and barely gets talked to (2). Also, around 35 tweets daily — tough for one person to sustain. One post: “This is the way. Everyone needs to see this. #crypto #alpha This is the way. Everyone needs to see this. #crypto #alpha” The pattern fits a retweet amplifier.
Don't amplify this account — treat it as a broadcast, not a person to argue with.
Coordination Watch
“Breaking narratives | alpha drops | DM for promo rates https://t.co/grift”
Active in 22 different hours over the last week with no 4-hour quiet stretch — and the pattern doesn't sit cleanly in any one timezone. That's what we'd expect from automation or someone posting without a real day/night rhythm.
Only about 5% of what we sampled is original. That's the shape of an amplifier — little personal voice, mostly boosting other people's posts.
This is the way. Everyone needs to see this. #crypto #alpha This is the way. Everyone needs to see this. #crypto #alphaView post →
Don't sleep on this opportunity #cryptoView post →
The bio has money-making keywords or dodgy short links — the kind of setup scammers and promo bots use to look legit.
Replies versus originals — this is the one-way pattern.
One-way megaphones — lots of outbound, almost no inbound — are a hallmark of engagement farms, not social use.
So true!!View post →
Great postView post →
40 posts a day for 30 days is one post roughly every 36 minutes. A month at that pace is a stronger tell than a busy day — real lives rarely sustain it without help.
Fresh accounts usually start quiet. Huge history this early often means scripts, purchased history, or a recycled farm handle.
Off-topic replies often come from scripts that ignore context — a strong automation tell when it repeats.
They replied
So true!!
To this post
Our peer-reviewed paper on Arctic ice loss is out — full methodology in the thread.View reply →
They replied
Great post
To this post
City council voted 7–2 to expand the library budget for after-school programs.View reply →
So true!!View post →
Great postView post →
Aggressive follow-spamming with almost no follow-back is a growth-hack pattern, not mutual discovery.
Repeating spam templates is how low-effort farms scale. Real marketers still vary the pitch.
Facts. Share this everywhere.View post →
Facts. Share this everywhere.View post →
35 posts a day for 14 days is one post roughly every 41 minutes. People sleep, work, and take breaks — automation or a farm shift is the usual explanation.
Natural posting is messy. Near-metronome gaps are a classic timer or scheduler signature.
Genuine accounts usually get some replies back. Near-zero inbound suggests nobody is treating this as a real person.
So true!!View post →
Great postView post →
Empty praise ('great post', 'so true') is cheap to template. Lots of it usually means engagement farming, not a point of view.
So true!!View post →
Great postView post →
35 posts a day over 90 days is one post roughly every 41 minutes. A quarter at that pace is rarely casual use.
Engagement bait exists to farm likes and replies. Heavy use is a growth tactic, not conversation.
Near-identical replies across posts are hard to write by accident — templates or copy-paste scripts are the usual cause.
So true!!View post →
Great postView post →
Several mismatched replies stack the case: this looks more like a reply bot than someone reading the thread.
They replied
So true!!
To this post
Our peer-reviewed paper on Arctic ice loss is out — full methodology in the thread.View reply →
They replied
Great post
To this post
City council voted 7–2 to expand the library budget for after-school programs.View reply →
So true!!View post →
Great postView post →
Finished-looking profile plus same-voice replies is a common AI-assisted or templated persona kit.
Long digit suffixes are common on auto-generated handles. Weak alone; useful when stacked with other tells.
Repeating the same lines saves time for scripts and farms. Real people rarely paste themselves this often.
Facts. Share this everywhere.View post →
Facts. Share this everywhere.View post →
Near-constant links usually mean the account exists to push traffic — affiliate, scam, or campaign landing pages.
Salesy language is fine occasionally; wall-to-wall promo tone is how funnel bots talk.
Quote-tweet farming rides popular posts for reach. It looks different from occasional genuine commentary.
Vague, reusable lines travel well across topics — useful for bots that don't actually know the conversation.
Real people change tone. Emotion stuck on one setting across replies often means generated or scripted text.
Same reading level every time can mean one model or template voice, not many human moods.
We looked closely at 2 of their posts and the replies underneath. They wrote back to only about 7% of the people who commented — they post, but they don't stick around to talk. That's more like broadcasting into the void than having a conversation.
So true!!View post →
This is the way. Everyone needs to see this. #crypto #alphaView post →
A sudden jump often means the account was switched on for a campaign, not someone casually getting more active.
Weekends normally look different from weekdays. A flat calendar often means the account isn't tied to one person's life.
Default avatars are common on mass-created accounts. Alone it's weak; with other flags it adds up.
Hashtag stuffing is a discovery and spam tactic. Everyday posters use tags sparingly.
Phone-typed replies usually have texture. Uniform polish is a tell for templates or AI assistance.
Humans pause between posts. Tight clusters of many posts in minutes look like a queue firing, not typing.
Reply spam is how farms boost other posts. High outbound volume without real conversation is a common bot job.
Brand-new yet fully dressed profiles often come from farms that prep accounts before they go live.
Messy human typing (typos, slang, asides) usually shows up somewhere. Wall-to-wall polish with none of that can mean AI or templates.
Also checked 40 replies, about 14 days, deep-thread pass.
Inbound conversation on their own posts would weaken this.
Prefer a dedicated page? Open the full sample report →
BotShark is not a black box. Every report is built from observable public behaviour — posting cadence, who an account engages with, how replies cluster, whether phrasing repeats across threads, and whether activity fits human sleep/wake patterns.
We deliberately separate the score from a verdict. A high tier means multiple independent signals align with automation or coordination heuristics — not that an account is guilty of anything. You get the evidence; you decide what it means in context.
Deep mode optionally expands thread analysis for reply-network sampling. Follower audits sample public follower cohorts for creation-cluster and coordination cues. Both modes show their work in the report.
Scoring thresholds are not guesses. We test them against a labelled set of known bot and human accounts, measure precision and recall at each score cutoff, and revise the rules when the data says a threshold is wrong — the same discipline you would expect from a published research method, not a vendor black box.
That evaluation runs continuously as the rule set changes. Current methodology and calibration results are published on the methodology page.