BotScope
anti-agent defenses for any website
Last verified:
What is BotScope?
BotScope is a comprehensive platform for auditing and detecting anti-agent and anti-bot defenses on any website. It performs passive reconnaissance scans to identify security measures like challenge-based verification (reCAPTCHA, hCAPTCHA, Cloudflare Turnstile), behavior patterning (Cloudflare Bot Management, Akamai Bot Manager, FingerprintJS Pro), network-level controls (WAF, rate limits, TLS policy), honeypots (Cloudflare AI Labyrinth, decoy anchors), and machine-readable policies (robots.txt, security.txt, llms.txt, ai.txt).
The tool uses advanced heuristics to detect anti-bot and anti-agent measures with precision, providing security leaders with an anti-bot inventory across domains. It offers a full catalog of detectable defenses, allows scanning of websites you don't own since it uses passive reconnaissance, and includes an MCP server for agents to authenticate, generate API keys, start scans, wait for completion, and retrieve results.
BotScope is designed for security teams, security leaders, and developers who need to assess their website's automated-access posture or审计 competitors' bot defenses. It provides observable evidence linking detected artifacts to specific anti-bot/anti-agent solutions, making it valuable for defensive assessment and reporting rather than intrusive testing.
BotScope pricing
Pricing model: Freemium
BotScope offers three workspace plans: Starter, Growth, and Enterprise. The plans cover scans, monitored URLs, API access, MCP server connectivity, and webhooks. A free trial is available with 5 queries against 5 models requiring no credit card. Starter plan includes essential features for smaller teams, Growth plan adds more scans and monitored URLs, and Enterprise plan provides full access with advanced features for security teams.
BotScope pros
- Detects 5 categories of anti-agent defenses comprehensively
- Supports challenge-based verification detection (reCAPTCHA, hCAPTCHA, Cloudflare Turnstile)
- Identifies behavior patterning tools (Cloudflare Bot Management, Akamai Bot Manager, FingerprintJS Pro)
- Detects network-level controls including WAF and rate limits
- Identifies honeypot mechanisms like Cloudflare AI Labyrinth
- Detects machine-readable policies (robots.txt, llms.txt, ai.txt)
- No need to own websites you scan - passive reconnaissance only
- Advanced heuristics for precise detection
- Full catalog of detectable anti-bot artifacts available
- MCP server integration for agent authentication and API workflows
- Provides observable evidence linking defenses to specific tools
- Designed for defensive assessment, not intrusive testing
- Monitors automated-access posture across domains
- API access for automated workflows
- Webhook support for notifications
BotScope cons
- Passive scanning only - cannot test defense effectiveness actively
- Only detects publicly observable signals
- May miss custom or proprietary anti-bot implementations
- Limited to public web URLs only
- No destructive or intrusive testing capabilities
- Detection depends on visible security headers and content
- May not detect recently deployed defenses not yet in catalog
- Enterprise plan required for advanced features
Frequently asked questions about BotScope
Do I need to own a website to scan it with BotScope?
No, you don't need to own websites that you scan with BotScope. All tooling is considered passive reconnaissance, meaning BotScope requests the same data normally sent by a website in a typical request, which is legal for any public URL.
What types of anti-agent defenses can BotScope detect?
BotScope detects 5 categories: Challenge-Based Verification (reCAPTCHA, hCAPTCHA, Cloudflare Turnstile), Behavior Patterning (Cloudflare Bot Management, Akamai Bot Manager, FingerprintJS Pro), Network-Level Control (WAF, Rate-Limits, TLS policy), Honeypot (Cloudflare AI Labyrinth, Decoy anchors, Tar Pits), and Machine-Readable Policy (robots.txt, security.txt, llms.txt, ai.txt).
Is BotScope invasive or intrusive testing?
No, BotScope is designed for defensive assessment and reporting only. It performs outside-in, passive scans of public web URLs, collecting observable signals like HTTP responses, headers, and page content within product limits. It is not for intrusive or destructive testing.
What is the ABAAM catalog?
The ABAAM (Anti-Bot and Anti-Agent Artifacts Map) catalog defines anti-bot and anti-agent artifacts that BotScope can detect and connects to observable evidence. It serves as the comprehensive reference for all detectable security measures.
How does the MCP server work?
The MCP server allows you to connect an MCP client to BotScope so agents can authenticate, generate API keys, start scans, wait for completion, and retrieve results programmatically.
What data does BotScope collect during scans?
BotScope collects observable signals including HTTP responses, headers, and page content loaded in a controlled browser session. This data documents anti-bot and anti-agent posture without intrusive testing.
What are the differences between Starter, Growth, and Enterprise plans?
The three workspace plans differ in the number of scans allowed, monitored URLs, API access limits, MCP connectivity features, and webhook support. Starter is for basic needs, Growth adds more capacity, and Enterprise provides full features for security teams.
Can BotScope detect custom anti-bot implementations?
BotScope uses advanced heuristics to detect anti-bot and anti-agent measures with precision, but it primarily detects visible signals in its ABAAM catalog. Custom or proprietary implementations without observable signals may not be detected.
How do I get support for BotScope?
For privacy questions, data requests, or support, use Help & feedback in your account workspace at /account/support. If you don't have an account yet, create one to reach the same channel. You can also email [email protected].
What is BotScope's primary use case?
BotScope is built for security leaders and teams who need an anti-bot inventory across domains. It provides visibility into visible anti-bot, WAF, CDN, challenge, AI crawler, and anti-agent signals for defensive assessment and automated-access posture reporting.