Resources Docs Free Blog Contact
Log in Get started

Research13 articles · updated Aug 2026

Detection research

What we see when we put a tool on the bench. Antidetect browsers signal by signal, headless and automation frameworks, TLS fingerprinting, and the proxy networks underneath all of it.

Articles

SIG-949Detection research

AI Agent Traffic: Telling Assistants From Attackers

Browser-using AI agents trip every legacy bot control. How to separate declared crawlers, user-driven agents, and attackers wearing agent clothing.

Kaspar Tomson6 min
SIG-421Detection research

JA3, JA4, and TLS Fingerprinting for Fraud Teams

What a TLS fingerprint actually captures, why JA3 broke, what JA4 fixed, and the one thing TLS fingerprints are genuinely good at in fraud detection.

Kaspar Tomson5 min
SIG-253Detection research

Octo Browser and the Second Tier of Antidetect Tools

Octo, MoreLogin, VMLogin, Hidemyacc and the rest of the second tier share one structural weakness — and it is not the fingerprint they spoof.

Kaspar Tomson5 min
SIG-727Detection research

Device Fingerprinting vs IP Intelligence for Fraud

Why clean residential IPs still hide fraud: how device fingerprinting and IP intelligence differ, where each breaks, and why strong fraud stacks use both.

Kaspar Tomson7 min
SIG-716Detection research

Browser Tampering Detection Tools: 2026 Guide

What browser tampering detection tools measure — runtime integrity, fingerprint coherence, automation signals — and how to evaluate them against real attacks.

Kaspar Tomson7 min
SIG-853Detection research

How to Detect Puppeteer & Playwright in 2026

Puppeteer and Playwright ship with stealth plugins that defeat every classic check. The signals that still detect CDP-driven automation in 2026, with code.

Kaspar Tomson6 min
SIG-916Detection research

Linken Sphere Detection: Catching Antidetect Browsers

Why Linken Sphere slips past IP reputation and velocity rules, and how layered device, browser, and network signals catch it at signup, login, and checkout.

Kaspar Tomson7 min
SIG-246Detection research

Multilogin Field Notes: What Fired and What Missed in 2026

How to detect Multilogin and other antidetect browsers: the device, network, and behavioral signals that expose one operator posing as hundreds of users.

Kaspar Tomson7 min
SIG-077Detection research

GoLogin Under Test: Which Signals Survived Our 2026 Lab Run

GoLogin makes browser identities portable and disposable. The signals that still expose it in production, and how to deploy detection without false positives.

Kaspar Tomson7 min
SIG-862Detection research

Kameleo & Undetectable Live Test: Both Flagged at Risk Score 100

Fresh Kameleo 4.5.0 and Undetectable installs vs Maskbreak's live scanner. Both flagged at risk score 100, with screenshots of what gave them away.

Kaspar Tomson5 min
SIG-981Detection research

CAPTCHA Farm Economics: How $0.001 per Solve Killed Bot Detection

CAPTCHA farms charge $0.0005–$0.002 per solve and process millions daily. Why CAPTCHA is dead as a bot defense — and what actually works instead.

Kaspar Tomson10 min
SIG-949Detection research

Headless Browser Detection in 2026: What Still Works

navigator.webdriver was solved years ago and stealth plugins kill the next 20 checks. What actually catches headless Chrome and CDP-driven browsers in 2026.

Kaspar Tomson7 min
SIG-967Detection research

Detecting Antidetect Browsers in 2026

Two live scans and an eleven-spoof ablation: the antidetect flag fired on both commercial profiles we ran, and the tampering score never moved.

Kaspar Tomson15 min
Fraud BriefOnce a month · no spam

The VPN, proxy and bot patterns we saw this month

One email a month with what changed in the traffic we check — new VPN and proxy networks, new bot tooling, what our lab runs turned up. Written for engineers. Unsubscribe in one click.