VPNs, proxies, residential-proxy exit nodes, proxyware, bots and tampered connections — caught by how they behave, not by a list of addresses that's stale the day it ships.
Free live check for anyone: whatami.me
A new residential-proxy provider or exit range is clean on every list until it's been abused enough to be reported. Behaviour is visible on the first connection.
A bandwidth-selling SDK isn't malware by signature — it's an app the user "agreed" to. EDR waves it through; its traffic shape gives it away.
Blocking ports and matching signatures misses tunnels that look like normal HTTPS. We judge the flow, not the port.
The same behavioural core, delivered where you need it — a tag for your website, an app for a device, or an on-prem deployment for a network you run.
A lightweight script returns a real-time risk verdict per visitor — VPN/proxy, automation, multi-accounting, connection tampering — before they act.
An app that inspects a device's own traffic behaviour to find proxyware, residential-proxy SDKs and VPN/relay apps running on it — often without the owner's knowledge.
Run the engine on your own infrastructure — data never leaves — with a central, self-learning feed of known relay gateways and proxy infrastructure.
All from behaviour and network signals — no client-supplied trust, no third-party API.
Traffic routed through someone else's home IP to look local.
Bandwidth-selling clients (honeygain-class) relaying on a device.
A device used AS a proxy — out ≫ in, pulling from many hosts.
Tunnelled clients, including ones hidden on standard ports.
Headless browsers, anti-detect stacks, non-human interaction shape.
One device behind many accounts, linked by hardware fingerprint.
Mismatched TLS/TCP, RTT gaps, spoofed network characteristics.
DGA / NXDOMAIN patterns and persistent phone-home channels.
Lists tell you where abuse has already happened. Behaviour tells you what's happening now.
Every confirmed relay teaches the system its gateways — exit IP, port and the owning app package — and how many independent networks have seen it. Not a static list we buy; one that compounds from what we actually observe.
gateway → package → networks
─────────────────────────────
80.96.x.x:9001 me.***.exit n=1
13.140.x.x:9443 · n=4
185.60.x.x:5222 (messenger) ok
─────────────────────────────
seen on ≥2 networks = known relayTry the free live check, or talk to us about the tag, the device monitor, or an on-prem deployment.