IT Forensics · OSINT

Identifying botnets using OSINT – Forensically detecting coordinated, automated accounts

Automated accounts, known as ‘bots’, are sometimes used deliberately to influence public opinion or artificially increase reach.

Enquire without obligation

In the context of existing reputation or security incidents, we carry out a structured investigation to determine whether publicly observable characteristics point to a coordinated botnet.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

Our OSINT investigations are always carried out as a complementary component to existing IT forensic, legal or internal corporate enquiries. Every step of the investigation and every piece of digital evidence found is documented and, where technically possible, archived to ensure traceability even if the original online content is subsequently altered or deleted.

Our services

We investigate publicly available characteristics of the accounts involved for signs of automated, coordinated behaviour and document the results in a manner that is forensically verifiable.

Typical areas of application

Identification of coordinated automated accounts
Supplementing disinformation and reputation investigations
Guidance on assessing artificially inflated reach
Documentation for disputes relating to press law
Judicial and non-judicial expert reports
Collaboration with communications departments

This is how botnet identification works

Using Maltego, the accounts in question are analysed for publicly identifiable characteristics such as creation date, activity patterns and links to other accounts; any discernible patterns of coordination are documented.

Why is botnet identification relevant from a forensic perspective?

Evidence of a coordinated bot network can provide important clues for understanding the nature of what appears to be widespread public opposition.

A documented analysis also helps to ensure objective communication with the press and the public.

Frequently Asked Questions

Can an account be identified beyond doubt as a bot?+
Only to a limited extent based on publicly observable characteristics; we communicate any existing limitations on our investigations transparently.
Is the platform itself contacted?+
No, our research is limited to publicly available information; it is up to the client to contact the platform.
Will this analysis be combined with the analysis of disinformation campaigns?+
Yes, the two methods often complement each other as part of a comprehensive examination.

LanCologne – IT Forensics OSINT Cologne

Do you require professional OSINT research on „Identifying botnets using OSINT"? LanCologne can assist you with the transparent, documented analysis of publicly available digital sources to complement your IT forensic, legal or in-house investigations.

Get in touch now