InterviewWatch includes a built-in applicant tracking system: post jobs and track candidates. Explore our ATS →
Interview fraud guide

How To Catch Interview Cheating Tools.

You catch a candidate using AI tools in an interview through two kinds of signal. Behavioral tells, a short delay before answering, a scripted or generic tone, or answers that hold up until a pointed follow-up, are weak on their own. Technical signals are far more reliable: clipboard paste bursts during a live answer, a second display or virtual camera driver, remote-access software running in the background, or a hidden overlay window that stays invisible during screen share. Screen sharing alone will not surface tools like Cluely or Interview Coder, which are built to evade it. The dependable approach is correlation, several independent signals lining up in time and reviewed by a human, not watching a candidate's face.

AI assistantHigh
Hidden overlayCritical
Remote controlCritical
Virtual deviceReview
Clipboard burstReview
Cheating tool categories

What hiring teams should watch for.

The names change quickly. The underlying methods are more stable: external answer generation, hidden presentation, remote operation, environment manipulation, and pasted or injected answers.

AI answer assistants

ChatGPT, Claude, Gemini, Perplexity, local LLM runners, coding assistants, and purpose-built interview AI tools can generate answers while the candidate stays on the call.

Hidden overlays

Overlay tools display answers on the candidate's screen while hiding from screen share or video recording.

Remote-control help

AnyDesk, TeamViewer, RDP, Chrome Remote Desktop, and similar tools can allow another person to control the candidate machine.

Proxy interview setups

A stand-in may take the interview, guide the candidate, or complete the technical work remotely.

Virtual camera/audio

Virtual webcams, audio routers, and voice tools can alter the meeting environment or hide who is really participating.

Clipboard activity

Large or structured pastes, especially from an AI source, can indicate outside assistance.

Detection signal map

Match each cheating method to machine-level evidence.

AI assistants

Known AI process, AI browser title, AI DNS trace, focus change, suspicious answer timing.

Hidden overlays

Capture-excluded windows, transparent overlays, known overlay process, suspicious window activity.

Remote-control and proxy help

Remote-access host process, viewer tool, and unusual focus changes.

Virtual devices

Virtual camera, audio router, voice-manipulation engine, camera/audio device changes during the interview.

Clipboard-assisted answers

Large paste bursts, structured answer blocks, paste timing after questions, and nearby AI or focus signals.

Typing and timing anomalies

Uniform keystroke rhythm, injected input patterns, and pause-then-burst answer behavior.

Second-screen assistance

Monitor added or removed mid-interview, baseline display context, and correlated focus changes.

External knowledge sources

Search engines, Stack Overflow, GitHub, docs pages, and coding challenge sites during live rounds.

Practical workflow

Do not rely on a single red flag.

The strongest reviews combine independent signals. A clipboard event alone may be harmless. A clipboard event immediately after an AI assistant appears and a hidden overlay is present is a different story.

hard question ยท 14:22:05 AI tool+2s focus change+4s overlay+5s large paste+7s Highconfidence

Four independent signals inside a seven-second window turn a set of maybe-innocent events into one high-confidence finding a reviewer can act on.

01BaselineRecord normal devices, displays, and relevant tools.
02DetectWatch AI, overlays, remote tools, focus, clipboard, and timing.
03CorrelateCombine events by time, severity, and interview context.
04ScoreSeparate candidate fit from integrity risk.
05ReviewGive humans evidence and next-step context.

What not to do

Do not build your process around eye tracking, body movement, nervous behavior, or gut feel. Those signals create bias and noise, especially in technical interviews.

What InterviewWatch does

InterviewWatch checks integrity metadata: process activity, window state, focus, clipboard size/source, device changes, and display changes. It does not record screens, audio, video, keyboard input, or keystroke content.

FAQ

Catching cheating tools, answered.

How can you tell if a candidate is using ChatGPT during an interview?
Behavioral tells like a delay before answering, unnaturally polished phrasing, or answers that fall apart under a specific follow-up are only weak hints. More reliable is machine-level evidence: an AI process or browser title, clipboard paste bursts during a live answer, a second display, or a hidden overlay window running during the call. Screen sharing alone does not surface tools built to evade it.
Can screen sharing alone catch a candidate using AI in an interview?
No. Tools like Cluely and Interview Coder are built specifically to stay invisible during screen share, so screen sharing alone will not surface them. Detecting overlay windows, clipboard activity, and AI processes at the machine level is what catches them.
Can you catch interview cheating without recording the candidate's screen?
Yes. InterviewWatch works from integrity metadata, process activity, window state, focus changes, clipboard size and source, device and display changes, and timing, not screen, audio, video, or keystroke recording. The evidence comes from how the machine behaves, not from watching the person.
Why isn't a single red flag enough to fail a candidate?
Any one signal can be innocent, a paste during coding, a second monitor, a brief focus change. The reliable approach is correlation: several independent signals lining up in time, such as an AI tool appearing, a pause, a focus change, and a large paste within seconds of the hardest question.
Do candidates need to install anything, and does it invade privacy?
A lightweight agent runs during the interview and reports metadata only. It does not capture what is on screen, what is typed, or what is said. Every event is timestamped and included in a report a human reviews, the goal is evidence, not surveillance.
What about brand-new cheating tools that don't exist yet?
Tool names change constantly, but the underlying methods are stable: external answer generation, hidden presentation, remote operation, environment manipulation, and pasted or injected answers. InterviewWatch detects the method and behaviour, so a new AI overlay or remote tool still trips the same class of signal.