Industry Intelligence
Industry Intelligence provides comprehensive comparative analysis of threat intelligence bots from leading companies in the industry. We rank bots on key metrics to help you understand how your bot compares to competitors and identify areas for improvement.
How We Score Bots
We score bots on five key categories:
- URL Sources: Which places does the bot take URLs from? We test by seeding phish submission forms with unique honeypot URLs and observing which bots fetch our site. More sources mean better coverage of emerging threats.
- Connectivity: Does the bot connect from a plausible end-user network, and with plausible end-user configuration? We analyse IP addresses (datacenter vs residential), TLS certificate validation, same-origin policy enforcement, and network characteristics.
- Platforms: Does the bot impersonate a wide range of browser/OS platform combinations? More platform diversity makes it harder to cloak against and provides a view into niche content only presented to isolated platforms.
- Tooling: Does the bot have obvious automation tooling? We detect Puppeteer, Playwright, WebDriver, CefSharp, and other automation frameworks from the browser runtime environment.
- Interaction: Does the bot interact with the site in human-like ways? We measure interaction by asking bots to dismiss JavaScript alert() boxes and cookie modals, and by presenting login forms to see if bots speculatively fill them in.
The overall score is an average of the percentage score in each category.
What You Get
Our Industry Intelligence reports include:
- Rankings of bots on each metric with detailed scoring breakdowns
- Raw information for each bot we have observed, including URL sources, platforms, and behaviors
- Identification of which bots excel in which areas
- Analysis of best practices and common weaknesses across the industry
- Detailed analysis of bot characteristics and behaviors
Our Methodology
We run an instrumented honeypot site that analyses over 200 unique signals to classify client sessions. Based on clusters of signals, we identify fingerprints of individual bots and assign them names for tracking and analysis purposes.
Our reports cover 20+ bots observed across thousands of browser sessions on our honeypot site.
Everything in our reports is based on real behavior we have observed in the wild. Nothing is speculative unless explicitly noted.
Who Benefits
Industry Intelligence is valuable for:
- Threat intelligence companies wanting to understand how their bot compares to competitors
- Bot developers looking to identify best practices and areas for improvement
- Security researchers studying bot detection and cloaking techniques
- Organisations evaluating threat intelligence vendors