Research

Published case studies and analyses from the BotConduct behavioral observatory. Real data on how bots and AI agents behave on the open web.

May 12, 2026

The Layer Daybreak Doesn't Cover

OpenAI Daybreak and Anthropic Glasswing defend your code. Neither observes what your AI agents do after authentication. BotConduct covers that layer. The next era of cyber defense is a stack, not one product.

behavioral observation AI agents Daybreak Glasswing
April 29, 2026

45% of Hostile Bot Traffic Passes Your WAF. Here's Why.

We cross-referenced 240 hostile actors operating from 380 IPs against AbuseIPDB. 45% have scores below typical WAF thresholds. 18% have zero reports anywhere. The data on why reputation-based defense misses the careful operators.

April 28, 2026

Agent Role Predicts Adversarial Resistance Better Than Declared Governance

What 30 production agents revealed: executor-role agents failed cost induction at 74% rate. Reviewer-role agents failed at 0% (Fisher exact p < 0.001). Governance score showed no correlation with resistance.

May 8, 2026

When Scrapers Stop Forgetting: What Autobrowse Means for the Receiver Side

Browserbase open-sourced Autobrowse u2014 a browser agent that learns a target site and remembers. Scraper intelligence now compounds across sessions. Why receiver-side behavioral classification is the only defense that scales.

behavioral classification AI agents receiver-side
April 28, 2026

A Bot Spent 17 Days Studying My Site Before Attacking. Every WAF Would Have Cleared It as Legitimate.

A single actor visited the observatory for 17 consecutive days from 20+ cloud and ISP providers across four continents, progressively escalating from content reading to credential extraction. Memory score 70. Susceptibility 53. The pattern is invisible to every layer of standard defense.

reconnaissance infrastructure rotation credential probing cross-provider correlation
April 24, 2026

Alibaba Cloud and AWS Host the Anonymous Bot Harvesting Our Site.

A stealth bot operating from Alibaba Cloud infrastructure with identical TLS fingerprint across 107 connections. 13 fake browser identities. Zero ALPN. Never read robots.txt. Same fingerprint appeared on AWS us-east-1. Multi-cloud evasion documented with verifiable evidence.

stealth harvesting JA4 fingerprinting multi-cloud UA rotation
April 20, 2026

Two Generations of Agent Evaluation

Why static checklists fail and what second-generation adversarial evaluation looks like. The case for trajectory-based behavioral measurement over checkpoint scoring.

methodology adversarial evaluation DeepMind AI Agent Traps
April 18, 2026

Governance and Verification: Why the Agent Era Needs Both Layers

The distinction between what an agent promises and what it actually does. Why governance policies and behavioral verification are complementary, not interchangeable.

governance verification policy vs behavior
April 15, 2026

We Measured 145 Bots. 27% Were Hostile.

First results from the BotConduct observatory. 145 bots profiled by behavioral observation over two weeks. What the data looks like when you measure conduct instead of identity.

observatory data bot profiling behavioral measurement