The model starts with a public bad-bot traffic baseline, then adjusts it by industry, geography, exposed endpoints and current defence maturity. Treat the output as a lead-generation estimate, not a forensic audit.
For a confirmed measurement, validate the estimate against perimeter and server-side request data over a 7–14 day observation window.