Detection research

What we see when we put a tool on the bench. Antidetect browsers signal by signal, headless and automation frameworks, TLS fingerprinting, and the proxy networks underneath all of it.

About the lab reports. Lab reports here come from our own harness: a browser profile with its JavaScript-visible identity rewritten, pointed at our own detector, with the tool and version named and the run dated. The harness sees nothing below JavaScript and is not the commercial tool itself, so each report says what it measured and what it cannot show.

15 articlesUpdated Sep 2026

Articles

Residential proxy botnets: where ‘clean’ home IPs really come from

Residential proxy botnets run on infected TV boxes, old routers and free VPNs. What the 2024–2026 takedowns show, and what your signup form still sees.

14 min

Proxy SDKs and proxyware: how apps turn their users into residential proxies

Proxy SDKs pay app makers per download or per gigabyte to route strangers’ traffic through users’ phones, PCs and TVs. How they work and what they risk.

14 min

AI Agent Traffic: Telling Assistants From Attackers

Browser-using AI agents trip every legacy bot control. How to separate declared crawlers, user-driven agents, and attackers wearing agent clothing.

6 min

JA3, JA4, and TLS Fingerprinting for Fraud Teams

What a TLS fingerprint actually captures, why JA3 broke, what JA4 fixed, and the one thing TLS fingerprints are genuinely good at in fraud detection.

5 min

Octo Browser and the Second Tier of Antidetect Tools

Octo, MoreLogin, VMLogin, Hidemyacc and the rest of the second tier share one structural weakness — and it is not the fingerprint they spoof.

5 min

Device Fingerprinting vs IP Intelligence for Fraud

Why clean residential IPs still hide fraud: how device fingerprinting and IP intelligence differ, where each breaks, and why strong fraud stacks use both.

7 min

Browser Tampering Detection Tools: 2026 Guide

What browser tampering detection tools measure — runtime integrity, fingerprint coherence, automation signals — and how to evaluate them against real attacks.

7 min

How to Detect Puppeteer & Playwright in 2026

Puppeteer and Playwright ship with stealth plugins that defeat every classic check. The signals that still detect CDP-driven automation in 2026, with code.

6 min

Linken Sphere Detection: Catching Antidetect Browsers

Why Linken Sphere slips past IP reputation and velocity rules, and how layered device, browser, and network signals catch it at signup, login, and checkout.

7 min

Multilogin Field Notes: What Fired and What Missed in 2026

How to detect Multilogin and other antidetect browsers: the device, network, and behavioral signals that expose one operator posing as hundreds of users.

7 min

GoLogin Under Test: Which Signals Survived Our 2026 Lab Run

GoLogin makes browser identities portable and disposable. The signals that still expose it in production, and how to deploy detection without false positives.

7 min

Kameleo & Undetectable Live Test: Both Flagged at Risk Score 100

Fresh Kameleo 4.5.0 and Undetectable installs vs Maskbreak's live scanner. Both flagged at risk score 100, with screenshots of what gave them away.

5 min

CAPTCHA Farm Economics: How $0.001 per Solve Killed Bot Detection

CAPTCHA farms charge $0.0005–$0.002 per solve and process millions daily. Why CAPTCHA is dead as a bot defense — and what actually works instead.

10 min

Headless Browser Detection in 2026: What Still Works

navigator.webdriver was solved years ago and stealth plugins kill the next 20 checks. What actually catches headless Chrome and CDP-driven browsers in 2026.

7 min

Detecting Antidetect Browsers in 2026

Two live scans and an eleven-spoof ablation: the antidetect flag fired on both commercial profiles we ran, and the tampering score never moved.

15 min
Fraud BriefOnce a month · no spam

The VPN, proxy and bot patterns we saw this month

One email a month with what changed in the traffic we check — new VPN and proxy networks, new bot tooling, what our lab runs turned up. Written for engineers. Unsubscribe in one click.