Cybersecurity for complex IT and OT environments
Senior specialists, strengthened by AI
An IP address does not always provide a reliable view of the user or the true origin of a connection. Attackers, fraudsters and automated services use commercial VPNs, residential proxies and other anonymisation infrastructure to make traffic resemble legitimate user activity and bypass existing detection controls.
DeepBlue maintains a database of IP addresses associated with commercial VPN providers, residential proxy networks and other forms of anonymisation infrastructure. The data is updated daily because providers continuously activate new addresses, rotate infrastructure and move capacity between networks and countries.
The dataset can enrich authentication events, transactions, API traffic and other online activity with additional context. It shows whether a connection originates from infrastructure capable of obscuring the actual source of the traffic. Security, fraud and investigation teams can use this signal within their own detection rules, risk models and investigative workflows.
VPN and proxy detection should not be treated as a standalone judgement about a user or session. The data is most effective when combined with other signals, such as identity, behaviour, location, device information and previous activity. This supports a more informed assessment without automatically classifying legitimate use of privacy or security services as suspicious.

DeepBlue is a member of Cyberveilig Nederland
Anonymisation infrastructure changes continuously. Commercial VPN providers add and remove exit nodes, residential proxy networks rotate addresses between devices and hosting providers reassign infrastructure across regions. Static blocklists therefore lose value quickly and can produce both missed detections and outdated classifications.
DeepBlue continuously collects, validates and classifies IP addresses associated with commercial VPN services, residential proxy networks and other infrastructure used to obscure the origin of internet traffic. The dataset is updated daily and includes both newly identified addresses and changes to previously classified infrastructure.
Classification is based on the observed role of the infrastructure rather than the reputation of an individual user. An address can therefore indicate that traffic is routed through a VPN, proxy or anonymisation service without determining whether the activity itself is malicious. This distinction is important because the same infrastructure can be used for legitimate privacy, remote access, fraud or intrusion activity.
The data is delivered in a structured format and can be integrated into existing security, fraud and analytics environments. Historical and current classifications provide context for both real-time decisions and retrospective analysis. This allows teams to determine not only whether an address is currently associated with anonymisation infrastructure, but also how that classification has changed over time.
The dataset is designed for integration into existing security, fraud and analytical processes. It provides a high-confidence signal that can be applied during authentication, transaction monitoring, threat detection and retrospective investigation. Customers retain control over how the classification affects scoring, alerting or access decisions.
DeepBlue does not expand the dataset through unverified aggregation, inferred network ranges or third-party reputation feeds by default. Each listed IP address has been directly identified and validated as commercial VPN, residential proxy or other anonymisation infrastructure. Broader enrichment or aggregation can be supplied when specifically required, but remains separate from the confirmed dataset.

VPN and proxy intelligence can enrich sign-in events with context about the infrastructure behind a connection. This helps identify sessions in which geolocation, impossible travel or unfamiliar devices may provide an incomplete picture because the apparent source has been deliberately obscured.

Residential proxies and VPN services are frequently used to distribute automated activity across legitimate-looking consumer connections. The dataset can support risk scoring for account creation, transactions, scraping, credential abuse and other forms of platform misuse without treating the IP classification as a standalone decision.

Security teams can correlate the data with SIEM, EDR, firewall, identity and application logs. This provides additional context during alert triage, threat hunting and incident response, particularly when an actor has used rotating infrastructure to reduce the value of conventional IP reputation.

The standard dataset contains only IP addresses that DeepBlue has directly identified and validated. Unconfirmed addresses, inferred subnets and aggregated third-party feeds are excluded. Within this defined classification model, every delivered entry is a confirmed match to the stated infrastructure type.
The data can be supplied through an API or as a structured export, depending on the required integration model. Delivery can be adapted to existing SIEM, fraud detection, identity, analytics or case management environments.
The dataset is refreshed daily. This is necessary because VPN providers, residential proxy networks and other anonymisation services continuously rotate, replace and reassign infrastructure.
No. A match indicates that the connection is associated with infrastructure capable of obscuring its origin. The activity itself must still be assessed using additional context such as identity, behaviour, device information, transaction data and previous activity.
Yes. Historical classifications can support retrospective analysis of authentication events, transactions, alerts and incidents. This makes it possible to determine whether infrastructure used in an earlier event was associated with a VPN, residential proxy or other anonymisation service at that time.
Yes. Customers can select the relevant infrastructure categories, delivery method and enrichment level. Broader aggregation, additional metadata or use-case-specific output can be provided separately where this supports the intended detection or investigation process.
Traditional reputation feeds often focus on addresses previously associated with malicious activity. VPN and proxy intelligence classifies the function of the infrastructure itself. This can reveal attempts to obscure origin even when the address has no known history of abuse.
Discuss a security requirement, active risk or complex IT or OT environment with one of our senior specialists. The initial conversation focuses on the technical context, operational constraints and the most appropriate course of action.
Urgent assistance required?
Call +31 (0) 70 290 6 290
or email info@deepbluesecurity.nl
Technical analysis, field observations and sector-specific perspectives across IT, OT and cyber resilience.