Detection research
What we see when we put a tool on the bench. Antidetect browsers signal by signal, headless and automation frameworks, TLS fingerprinting, and the proxy networks underneath all of it.
About the lab reports. Lab reports here come from our own harness: a browser profile with its JavaScript-visible identity rewritten, pointed at our own detector, with the tool and version named and the run dated. The harness sees nothing below JavaScript and is not the commercial tool itself, so each report says what it measured and what it cannot show.
Articles
Residential proxy botnets: where ‘clean’ home IPs really come from
Residential proxy botnets run on infected TV boxes, old routers and free VPNs. What the 2024–2026 takedowns show, and what your signup form still sees.
Proxy SDKs and proxyware: how apps turn their users into residential proxies
Proxy SDKs pay app makers per download or per gigabyte to route strangers’ traffic through users’ phones, PCs and TVs. How they work and what they risk.
AI Agent Traffic: Telling Assistants From Attackers
Browser-using AI agents trip every legacy bot control. How to separate declared crawlers, user-driven agents, and attackers wearing agent clothing.
JA3, JA4, and TLS Fingerprinting for Fraud Teams
What a TLS fingerprint actually captures, why JA3 broke, what JA4 fixed, and the one thing TLS fingerprints are genuinely good at in fraud detection.
Octo Browser and the Second Tier of Antidetect Tools
Octo, MoreLogin, VMLogin, Hidemyacc and the rest of the second tier share one structural weakness — and it is not the fingerprint they spoof.
Device Fingerprinting vs IP Intelligence for Fraud
Why clean residential IPs still hide fraud: how device fingerprinting and IP intelligence differ, where each breaks, and why strong fraud stacks use both.
Browser Tampering Detection Tools: 2026 Guide
What browser tampering detection tools measure — runtime integrity, fingerprint coherence, automation signals — and how to evaluate them against real attacks.
How to Detect Puppeteer & Playwright in 2026
Puppeteer and Playwright ship with stealth plugins that defeat every classic check. The signals that still detect CDP-driven automation in 2026, with code.
Linken Sphere Detection: Catching Antidetect Browsers
Why Linken Sphere slips past IP reputation and velocity rules, and how layered device, browser, and network signals catch it at signup, login, and checkout.
Multilogin Field Notes: What Fired and What Missed in 2026
How to detect Multilogin and other antidetect browsers: the device, network, and behavioral signals that expose one operator posing as hundreds of users.
GoLogin Under Test: Which Signals Survived Our 2026 Lab Run
GoLogin makes browser identities portable and disposable. The signals that still expose it in production, and how to deploy detection without false positives.
Kameleo & Undetectable Live Test: Both Flagged at Risk Score 100
Fresh Kameleo 4.5.0 and Undetectable installs vs Maskbreak's live scanner. Both flagged at risk score 100, with screenshots of what gave them away.
CAPTCHA Farm Economics: How $0.001 per Solve Killed Bot Detection
CAPTCHA farms charge $0.0005–$0.002 per solve and process millions daily. Why CAPTCHA is dead as a bot defense — and what actually works instead.
Headless Browser Detection in 2026: What Still Works
navigator.webdriver was solved years ago and stealth plugins kill the next 20 checks. What actually catches headless Chrome and CDP-driven browsers in 2026.
Detecting Antidetect Browsers in 2026
Two live scans and an eleven-spoof ablation: the antidetect flag fired on both commercial profiles we ran, and the tampering score never moved.
The VPN, proxy and bot patterns we saw this month
One email a month with what changed in the traffic we check — new VPN and proxy networks, new bot tooling, what our lab runs turned up. Written for engineers. Unsubscribe in one click.