BADS Forensic
Publicly-traded micro-cap, US-listed
Nov 2025 — 3-week engagement
Bot-network forensic on a US micro-cap stock during a promotional pump cycle
What we did
Applied the BADS (Bot Activity Detection System) methodology to social-media chatter around a US-listed micro-cap during an active promotional cycle. Cross-referenced social-media intelligence collection across X, Reddit, and Telegram with public trading-volume and account-behavior signals, then ran network-graph analysis to identify coordinated clusters versus organic retail conversation.
What we found
- 27+ inauthentic accounts identified across two distinct coordination clusters, with shared posting cadence and near-identical narrative templates.
- Two separate coordination networks — one focused on price-target narratives, the second on rebuttal-of-critics activity — sharing infrastructure signatures.
- Approximately 72% decline in cluster posting activity in the two weeks after the report was delivered, consistent with either detection-avoidance or budget exhaustion.
- Composite Mark Score bands assigned to each account with documented false-positive expectations at each threshold.
Outcome
Client used the deliverable — forensic timeline, tagged account list with Mark Scores, and narrative-cluster diagram — to inform an internal legal and communications response. Findings were preserved in a format suitable for regulatory referral at the client's discretion.
Brand Protection
Fortune-500 entertainment client (NDA)
Feb 2026 — 48-hour turnaround
Distinguishing organic backlash from bot-amplified defense during a reputational event
What we did
During a fast-moving reputational event, the client needed to know within 48 hours whether the negative conversation on X and Instagram was organic public sentiment or a coordinated amplification operation — and whether the defensive counter-narrative was organic support or paid-inauthentic activity. Ran a 50,000+ post collection across the two platforms, then applied the same behavioral-heuristics and network-graph stack used in BADS forensic work, tuned for brand-signal rather than market-manipulation signal.
What we found
- Approximately 2,400 inauthentic accounts identified across 12 coordination clusters, distributed across both the attack narrative and the defensive counter-narrative.
- Organic sentiment isolated and re-scored after removing inauthentic amplification — with the organic baseline meaningfully different from the raw platform metrics.
- Two of the twelve clusters exhibited infrastructure overlap with clusters previously observed in unrelated engagements — suggesting a reusable operator, not a bespoke campaign.
- Delivered inside the 48-hour SLA window from initial brief.
Outcome
Client used the report to shape its public response strategy — separating the questions of "what does the real public think" from "what is being manufactured" — and to inform legal preservation of the identified inauthentic activity.
Recon Business Intelligence
Regional SMB, hospitality vertical
Aug 2026 — 4-hour Recon Standard delivery
Competitive intelligence and narrative audit for an independent specialty coffee roaster
What we did
Standard 4-hour Recon delivery on an independent specialty coffee roaster preparing for a wholesale-expansion decision. Full 6-tab dashboard: competitive intelligence via audience-overlap and search-result-adjacency signal collection, narrative and brand intelligence with per-platform footprint scoring, live sales-intelligence lead extraction from the last 14 days of conversation, gap analysis with severity heatmap, and a 30-day social-media game plan.
What we found
- Three real market competitors identified — none of which the client had named on their internal shortlist — surfaced through audience-overlap and search-result-adjacency signals rather than category tags.
- Two live narrative themes trending in the specialty-coffee vertical with strong subject-fit scores — actionable within the 30-day content plan.
- Eight active engagement leads pulled from the last 14 days: prospects publicly asking wholesale-supplier questions the client's service directly answers.
- Ten ranked gaps, two flagged as critical severity, each tied to observed demand signals and shipped with per-gap remediation recommendations.
Outcome
Client used the report to reshape the wholesale outreach shortlist and to reprioritize the 30-day content calendar around the two identified narrative themes. This is representative of the deliverable structure — the full redacted walkthrough for a comparable subject is available at /sample-report.html.
How we count
Every number on this page was documented with its methodology at the time of client delivery. Each engagement ships with the raw heuristics used, the threshold bands assigned, the collection window covered, and the false-positive expectation at each threshold.
Clients receive the methodology alongside every finding — not as an appendix, but as an in-line audit trail on the finding itself. If a Mark Score, a cluster count, or a lead count appears in a Cyberharpoon deliverable, the client can see exactly how it was derived and what would move the number.
We report findings, not marketing metrics. If a number appears above, it was defensible at the time of client delivery and is subject to independent scrutiny.