BotShark

Methodology

How BotShark works

A transparent pipeline: collect public data, extract behavioural features, score against published rules, and explain every flag with evidence.

  1. 01Collect
  2. 02Extract
  3. 03Score
  4. 04Explain

1. Collect

Public profile metadata and recent posts/replies from supported platforms (X, Bluesky).

2. Extract

Behavioural features: posting rhythm, engagement asymmetry, content reuse, thread shape.

3. Score

Rule engine combines signals into a 0–100 likelihood score with tier and confidence.

4. Explain

Each flag shows the underlying posts, metrics, and rule rationale in plain language.

Sample report

What a finished analysis looks like

Same report surface as a live scan — score, findings, charts, and plain-language evidence. Synthetic data; try a real handle with a free scan.

Full sample reportSynthetic demo data
BotShark reportScraped 15 Jun 2026, 14:30 UTC

@coordination_watch

Retweet amplifier

Almost nothing they post is original — the account mainly exists to boost other people's content. That's the classic shape of a narrative spreader or political spam network.

Also resembles: Reply farm, 24/7 poster, Grift / promo account

100/ 100
Very high likelihood95% confident (95% of the data we wanted was available).Deep thread pass

We found 40 warning signs, and they fit together: this account posts and engages like a broadcast or farm operation, not someone casually scrolling and tweeting.

The posting habits, the way they engage, and the kind of content they share all tell the same story — this doesn't read like someone using the app for themselves.

Profile snapshot

Coordination Watch

Joined 2 Nov 2024 — 1.6 years ago

Claims: Worldwide

Breaking narratives | alpha drops | DM for promo rates https://t.co/grift

Bio reads like a promo funnel

Network & coordination

Very few follow-backs from who they follow

Worth noting

Low reciprocity means the follow graph isn't mutual social life — often follow-spam or purchased networks.

Top signals · 8 of 46

The strongest of the 46 signals below.

Posts around the clock with no normal break

Major red flag

Active in 22 different hours over the last week with no 4-hour quiet stretch — and the pattern doesn't sit cleanly in any one timezone. That's what we'd expect from automation or someone posting without a real day/night rhythm.

Almost everything is retweets and quotes

Major red flag

Only about 5% of what we sampled is original. That's the shape of an amplifier — little personal voice, mostly boosting other people's posts.

This is the way. Everyone needs to see this. #crypto #alpha This is the way. Everyone needs to see this. #crypto #alpha
View post →
Don't sleep on this opportunity #crypto
View post →

Bio smells like a grift or promo funnel

Major red flag

The bio has money-making keywords or dodgy short links — the kind of setup scammers and promo bots use to look legit.

Some replies don't match what they're replying to

Major red flag

About 60% of replies we could check looked off-topic — common with auto-reply tools and spam bots.

They replied

So true!!

To this post

Our peer-reviewed paper on Arctic ice loss is out — full methodology in the thread.
View reply →

They replied

Great post

To this post

City council voted 7–2 to expand the library budget for after-school programs.
View reply →

Replies out constantly, gets almost nothing back

Major red flag

One-way megaphones — lots of outbound, almost no inbound — are a hallmark of engagement farms, not social use.

So true!!
View post →
Great post
View post →

Same spammy templates over and over

Major red flag

Repeating spam templates is how low-effort farms scale. Real marketers still vary the pitch.

Facts. Share this everywhere.
View post →
Facts. Share this everywhere.
View post →

Created after the platform changed hands

Major red flag

Accounts created after the platform changed hands arrived in a wave of inauthentic sign-ups. Timing alone is weak — stronger when other flags stack.

Follows many, followed by few

Major red flag

Aggressive follow-spamming with almost no follow-back is a growth-hack pattern, not mutual discovery.

Engagement is mostly one-way broadcasting

They push content and replies outward far more than they ever come back to conversations on their own posts — more megaphone than participant.

So true!!
View post →
Great post
View post →

Follower numbers look lopsided

50 followers and 2,500 following. They follow huge numbers of people while far fewer follow back — a common growth-hack pattern.

Posting rhythm

061218

Real people cluster in waking hours. A flat skyline with no quiet stretch often means automation or shift workers running the account.

30d agotoday

Quiet for weeks, then a sudden flood, often means the account was switched on for a campaign — not someone casually checking in more.

How they spend posts

Originals30 · 19%Replies100 · 62%Reposts15 · 9%Quotes15 · 9%

Normal users mix originals and replies. Feeds that are almost only replies or reposts often exist to amplify someone else's message.

What they post about

Other62%Crypto & web319%Promo & sales9%Links & media9%

We bucket posts by the words they use most. A feed glued to crypto, promo, or bait language looks different from mixed everyday interests.

Sentiment spread

0+

Real people swing between moods. Feeds stuck at one emotional extreme often exist to provoke, sell, or push a single narrative.

All signals · 39

Full list — items already shown above are collapsed.

Heavy posting over the last month

Major red flag

A month of heavy output is a stronger tell than a busy day — real lives rarely sustain that pace without help.

Very new account, huge posting history already

Major red flag

Fresh accounts usually start quiet. Huge history this early often means scripts, purchased history, or a recycled farm handle.

Posts far more than a normal person would

Worth noting

People sleep, work, and take breaks. Day-after-day volume at this level is hard to sustain by hand — automation or a farm shift is the usual explanation.

Gaps between posts are oddly regular

Worth noting

Natural posting is messy. Near-metronome gaps are a classic timer or scheduler signature.

Hardly anyone replies on their posts

Worth noting

Genuine accounts usually get some replies back. Near-zero inbound suggests nobody is treating this as a real person.

So true!!
View post →
Great post
View post →

Lots of generic one-liner replies

Worth noting

Empty praise ('great post', 'so true') is cheap to template. Lots of it usually means engagement farming, not a point of view.

So true!!
View post →
Great post
View post →

Sustained heavy posting for months

Worth noting

Three months of sustained firehose activity is rarely casual use; it usually needs tooling or a team.

Lots of obvious engagement bait

Worth noting

Engagement bait exists to farm likes and replies. Heavy use is a growth tactic, not conversation.

More signals · 20Show allHide

Groups of near-identical replies

Worth noting

Near-identical replies across posts are hard to write by accident — templates or copy-paste scripts are the usual cause.

So true!!
View post →
Great post
View post →

Polished profile plus very uniform replies

Worth noting

Finished-looking profile plus same-voice replies is a common AI-assisted or templated persona kit.

Handle ends in a long run of digits

Worth noting

Long digit suffixes are common on auto-generated handles. Weak alone; useful when stacked with other tells.

Same text keeps showing up

Worth noting

Repeating the same lines saves time for scripts and farms. Real people rarely paste themselves this often.

Facts. Share this everywhere.
View post →
Facts. Share this everywhere.
View post →

Almost every post includes a link

Worth noting

Near-constant links usually mean the account exists to push traffic — affiliate, scam, or campaign landing pages.

Language is salesy or promotional

Worth noting

Salesy language is fine occasionally; wall-to-wall promo tone is how funnel bots talk.

Quote-tweeting looks like farming, not sharing

Worth noting

Quote-tweet farming rides popular posts for reach. It looks different from occasional genuine commentary.

Posts are vague and could apply to anything

Worth noting

Vague, reusable lines travel well across topics — useful for bots that don't actually know the conversation.

Replies all carry the same emotional tone

Worth noting

Real people change tone. Emotion stuck on one setting across replies often means generated or scripted text.

Replies all read at the same level

Worth noting

Same reading level every time can mean one model or template voice, not many human moods.

Rarely replies to people on their own posts

Worth noting

We looked closely at 2 of their posts and the replies underneath. They wrote back to only about 7% of the people who commented — they post, but they don't stick around to talk. That's more like broadcasting into the void than having a conversation.

So true!!
View post →
This is the way. Everyone needs to see this. #crypto #alpha
View post →

Posting picked up sharply this week

Minor signal

A sudden jump often means the account was switched on for a campaign, not someone casually getting more active.

Weekends and weekdays look the same

Minor signal

Weekends normally look different from weekdays. A flat calendar often means the account isn't tied to one person's life.

Still on the default avatar

Minor signal

Default avatars are common on mass-created accounts. Alone it's weak; with other flags it adds up.

Heavy hashtag use on most posts

Minor signal

Hashtag stuffing is a discovery and spam tactic. Everyday posters use tags sparingly.

Replies sound too polished

Minor signal

Phone-typed replies usually have texture. Uniform polish is a tell for templates or AI assistance.

Bursts of many posts within minutes

Minor signal

Humans pause between posts. Tight clusters of many posts in minutes look like a queue firing, not typing.

Sends a large volume of replies

Minor signal

Reply spam is how farms boost other posts. High outbound volume without real conversation is a common bot job.

Brand-new but already polished

Minor signal

Brand-new yet fully dressed profiles often come from farms that prep accounts before they go live.

Posts read too clean — no casual human mess

Minor signal

Messy human typing (typos, slang, asides) usually shows up somewhere. Wall-to-wall polish with none of that can mean AI or templates.

↑ Already covered above — Replies out constantly, gets almost nothing back
↑ Already covered above — Content matches crypto or affiliate spam patterns
↑ Already covered above — Some replies don't match what they're replying to
↑ Already covered above — Shows up to post at almost all hours
↑ Already covered above — No normal overnight break in posting
↑ Already covered above — Follows many, followed by few
↑ Already covered above — Same spammy templates over and over
↑ Already covered above — Bio reads like a promo or scam
↑ Already covered above — Almost nothing is original — mostly retweets
↑ Already covered above — Multiple off-topic or copy-pasted replies
↑ Already covered above — Some days were nothing but retweets

Account history

↑ Already covered above — Created after the platform changed hands

What looks normal

Too few accounts scanned to spot coordination

Only 0 tweets stored locally. The more profiles you run, the better copy-paste detection gets.

First scan — no growth history yet

We haven't tracked this account before. Run it again in a week or two to see if followers spike unnaturally.

Key numbers

Followers
50
Following
2,500
Total tweets (profile count)
12,840
Average posts per day (lifetime)
35
Posts per day (last week)
45
Replies they sent to others
80
Replies others left on their posts
2
Outbound vs inbound replies
40
Posts that are their own words
5%
Engagement per follower
0%
Technical checks · 3ShowHide

Individual metric thresholds behind the signals above — for readers who want the raw numbers.

Created after Oct 2022

Phone-typed replies usually have texture. Uniform polish is a tell for templates or AI assistance.

Follows far more than follow back

Following far more than follow you back is a common growth-hack. Stacked with other flags, it supports a farm read.

Low follow-back rate

Low reciprocity means the follow graph isn't mutual social life — often follow-spam or purchased networks.

What this analysis can't tell you

  • Sample data for demonstration only — not a live scrape.
  • First time we've stored this account — run it again in a week to see whether followers jumped unnaturally.
  • Copy-paste detection only compares accounts you've already scanned on this install.
  • We couldn't pin down posting hours — common when someone posts around the clock.

Generated by BotShark · sample data for demonstration.

Prefer a dedicated page? Open the full sample report →

BotShark is not a black box. Every report is built from observable public behaviour — posting cadence, who an account engages with, how replies cluster, whether phrasing repeats across threads, and whether activity fits human sleep/wake patterns.

We deliberately separate the score from a verdict. A high tier means multiple independent signals align with automation or coordination heuristics — not that an account is guilty of anything. You get the evidence; you decide what it means in context.

Deep mode optionally expands thread analysis for reply-network sampling. Follower audits sample public follower cohorts for creation-cluster and coordination cues. Both modes show their work in the report.

Scoring thresholds are not guesses. We test them against a labelled set of known bot and human accounts, measure precision and recall at each score cutoff, and revise the rules when the data says a threshold is wrong — the same discipline you would expect from a published research method, not a vendor black box.

That evaluation runs continuously as the rule set changes. Current methodology and calibration results are published on the methodology page.