Contact

VPN Detection

Cybersecurity for complex IT and OT environments

Senior specialists, strengthened by AI

01
Introduction
Use case and scope
02
Test data
Sample and validation
03
Integration
API and SIEM connection
04
Live detection
Real-time enrichment
05
Monitoring
Insight and optimisation
06
Continuous improvement
Daily updates

Identify the infrastructure behind anonymous internet traffic

An IP address does not always provide a reliable view of the user or the true origin of a connection. Attackers, fraudsters and automated services use commercial VPNs, residential proxies and other anonymisation infrastructure to make traffic resemble legitimate user activity and bypass existing detection controls.

DeepBlue maintains a database of IP addresses associated with commercial VPN providers, residential proxy networks and other forms of anonymisation infrastructure. The data is updated daily because providers continuously activate new addresses, rotate infrastructure and move capacity between networks and countries.

The dataset can enrich authentication events, transactions, API traffic and other online activity with additional context. It shows whether a connection originates from infrastructure capable of obscuring the actual source of the traffic. Security, fraud and investigation teams can use this signal within their own detection rules, risk models and investigative workflows.

VPN and proxy detection should not be treated as a standalone judgement about a user or session. The data is most effective when combined with other signals, such as identity, behaviour, location, device information and previous activity. This supports a more informed assessment without automatically classifying legitimate use of privacy or security services as suspicious.

DeepBlue is a member of Cyberveilig Nederland

Continuously updated intelligence on anonymisation networks

Anonymisation infrastructure changes continuously. Commercial VPN providers add and remove exit nodes, residential proxy networks rotate addresses between devices and hosting providers reassign infrastructure across regions. Static blocklists therefore lose value quickly and can produce both missed detections and outdated classifications.

DeepBlue continuously collects, validates and classifies IP addresses associated with commercial VPN services, residential proxy networks and other infrastructure used to obscure the origin of internet traffic. The dataset is updated daily and includes both newly identified addresses and changes to previously classified infrastructure.

Classification is based on the observed role of the infrastructure rather than the reputation of an individual user. An address can therefore indicate that traffic is routed through a VPN, proxy or anonymisation service without determining whether the activity itself is malicious. This distinction is important because the same infrastructure can be used for legitimate privacy, remote access, fraud or intrusion activity.

The data is delivered in a structured format and can be integrated into existing security, fraud and analytics environments. Historical and current classifications provide context for both real-time decisions and retrospective analysis. This allows teams to determine not only whether an address is currently associated with anonymisation infrastructure, but also how that classification has changed over time.

vpn-detect/stream
VPN-detect · database
140+
Providers
3M+
Records
90+
Dagen
$ tail -f matches
185.245.31.214Provider ABCVPN
104.200.142.88Provider XYZVPN
91.247.55.102Provider 14BPROXY
217.138.219.43Provider DEFVPN
45.83.220.17Provider 15ZVPN
156.59.42.198Provider 22QPROXY
194.62.169.250Provider GHIVPN
37.120.193.66Provider JKLVPN
185.245.31.214Provider ABCVPN
104.200.142.88Provider XYZVPN
91.247.55.102Provider 14BPROXY
217.138.219.43Provider DEFVPN
45.83.220.17Provider 15ZVPN
156.59.42.198Provider 22QPROXY
194.62.169.250Provider GHIVPN
37.120.193.66Provider JKLVPN

Built for operational detection and investigation

The dataset is designed for integration into existing security, fraud and analytical processes. It provides a high-confidence signal that can be applied during authentication, transaction monitoring, threat detection and retrospective investigation. Customers retain control over how the classification affects scoring, alerting or access decisions.

DeepBlue does not expand the dataset through unverified aggregation, inferred network ranges or third-party reputation feeds by default. Each listed IP address has been directly identified and validated as commercial VPN, residential proxy or other anonymisation infrastructure. Broader enrichment or aggregation can be supplied when specifically required, but remains separate from the confirmed dataset.

Dagelijkse updates

Authentication and access monitoring

VPN and proxy intelligence can enrich sign-in events with context about the infrastructure behind a connection. This helps identify sessions in which geolocation, impossible travel or unfamiliar devices may provide an incomplete picture because the apparent source has been deliberately obscured.

Hoge nauwkeurigheid

Fraud and abuse detection

Residential proxies and VPN services are frequently used to distribute automated activity across legitimate-looking consumer connections. The dataset can support risk scoring for account creation, transactions, scraping, credential abuse and other forms of platform misuse without treating the IP classification as a standalone decision.

Uitgebreide dekking

Threat detection and investigation

Security teams can correlate the data with SIEM, EDR, firewall, identity and application logs. This provides additional context during alert triage, threat hunting and incident response, particularly when an actor has used rotating infrastructure to reduce the value of conventional IP reputation.

Eenvoudige integratie

Validated, non-aggregated data

The standard dataset contains only IP addresses that DeepBlue has directly identified and validated. Unconfirmed addresses, inferred subnets and aggregated third-party feeds are excluded. Within this defined classification model, every delivered entry is a confirmed match to the stated infrastructure type.

Frequently asked questions about VPN detection

How is the dataset delivered?

The data can be supplied through an API or as a structured export, depending on the required integration model. Delivery can be adapted to existing SIEM, fraud detection, identity, analytics or case management environments.

How often is the data updated?

The dataset is refreshed daily. This is necessary because VPN providers, residential proxy networks and other anonymisation services continuously rotate, replace and reassign infrastructure.

Does an IP match mean that the activity is malicious?

No. A match indicates that the connection is associated with infrastructure capable of obscuring its origin. The activity itself must still be assessed using additional context such as identity, behaviour, device information, transaction data and previous activity.

Can the data be used for historical investigations?

Yes. Historical classifications can support retrospective analysis of authentication events, transactions, alerts and incidents. This makes it possible to determine whether infrastructure used in an earlier event was associated with a VPN, residential proxy or other anonymisation service at that time.

Can the dataset be tailored to a specific use case?

Yes. Customers can select the relevant infrastructure categories, delivery method and enrichment level. Broader aggregation, additional metadata or use-case-specific output can be provided separately where this supports the intended detection or investigation process.

What is the difference between this dataset and a traditional IP reputation feed?

Traditional reputation feeds often focus on addresses previously associated with malicious activity. VPN and proxy intelligence classifies the function of the infrastructure itself. This can reveal attempts to obscure origin even when the address has no known history of abuse.

You are in good company

Direct access to senior cybersecurity expertise

Discuss a security requirement, active risk or complex IT or OT environment with one of our senior specialists. The initial conversation focuses on the technical context, operational constraints and the most appropriate course of action.

  • No mailing lists or automated sales follow-up
  • Information is handled confidentially

Urgent assistance required?

Call +31 (0) 70 290 6 290
or email  info@deepbluesecurity.nl

Thank you. The message has been received and will be reviewed by one of our specialists.
The form could not be submitted. Please try again or contact info@deepbluesecurity.nl.

Latest technical insights

Technical analysis, field observations and sector-specific perspectives across IT, OT and cyber resilience.