Part of the RST intelligence layer

bot-radar-icon

RST Bot Radar

Residential proxies and automation infrastructure — observed being abused in real traffic, not enumerated from provider lists.

volume is not signal
300,000,000+
addresses advertised as provider inventory
observed abusing
seen relaying automated abuse in real traffic
residential proxyheadless browsercredential stuffing
a signal for graduated response, not a blocklist

A residential address is shared — so shape traffic, rate-limit, or challenge. Do not blanket-block.

Trusted automation signal — the proxies actually being used against you.

Volume is not signal

A 300-million-address feed is not something you can operate on

Residential proxy networks advertise inventory in the hundreds of millions of addresses. You can subscribe to a RESIP provider, parse their list, and end up with a feed so large that nothing in your stack can reasonably use it — much of which has never been used against anyone.

Acting on that scale is indiscriminate. Ignoring it means missing real automated abuse. The problem is not access to proxy data; it is that raw inventory is not a signal.

We watch abuse, not inventory

Bot Radar does not enumerate what proxy providers are selling. It monitors real-world traffic and reports the proxies and automation infrastructure that are actually being abused.

That inverts the volume problem. Instead of three hundred million addresses that might theoretically proxy something one day, you get the far smaller set seen driving bot activity in the last hour — a population small enough to act on and recent enough to be worth acting on.

The practical difference~300M enumerated unusable in production  →  ~100k seen in the last hour a population you can actually make decisions with.

Reuse is measured, not assumed

We track how often a given residential address turns up in abuse, and over what span. One seen once last month and one seen hourly all week are not the same risk — and are not scored the same.

Every observation is scored

Nothing ships as a flat list. Each address carries a score built from how recently and how repeatedly it was seen, and from which sources saw it — so you set your own threshold instead of accepting ours.

Cross-referenced with our own scans

We scan for exposed proxy infrastructure directly — SOCKS, HTTP and other open relays — and correlate it against observed abuse. An address that both answers as an open proxy and is seen relaying abuse is a far stronger signal than either alone.

Confirmed against our honeypots

Our honeypot network absorbs the internet's background automation continuously, giving us a first-party view of which infrastructure drives scanning, crawling and credential abuse — not a list we bought from someone else.

How to use it

A signal for graduated response — not a blocklist

We do not recommend blocking on Bot Radar. A residential address is somebody’s home connection, and denying it outright risks the legitimate person sharing it. Automation abuse is better answered by degrees — make the expensive paths harder to reach, and let genuine users through.

Traffic shaping

Slow or deprioritise sessions arriving from known automation infrastructure instead of refusing them.

Request rate limiting

Cap request rates from these sources before they reach the expensive parts of your application.

Challenge the session

Redirect to an anti-bot CAPTCHA or a step-up check, so a real user can still continue.

Anti-fraud scoring

Feed it in as a weighted factor in fraud, abuse and account-takeover models rather than a hard verdict.

Scored, like everything else

The score picks the response

Every observation carries the same three dimensions as the rest of the layer — which is exactly what lets you choose a proportionate response instead of a binary one. A high-confidence address seen minutes ago is worth a challenge; a weak, stale one is a scoring factor at most. See how we score →

Source confidence

How much we trust the vantage point the observation came from.

Context score

What the address was actually doing — the kind of automation, and what it was aimed at.

Time relevance

How recently it was seen. An address active an hour ago is a different proposition from one last seen in spring.

Coverage

What Bot Radar reports

Residential proxies

RESIP nodes seen relaying automated abuse — the addresses that look like ordinary home connections.

Bots & browser automation

Infrastructure driving headless browsers and scripted sessions against real services.

Where it fits in the pipeline

Threat Feed tells you what is malicious. Noise Control tells you what is known-good. Bot Radar answers a third question that neither covers: is this traffic a human at all, or automation renting a residential address for the afternoon?

It is the same discipline as the rest of the layer — observed, recent, and small enough to be operational — pointed at automated abuse, and delivered as an input to your WAF, CDN and anti-fraud logic rather than a verdict imposed on them.

See what automation is hitting you.

The quickest way to judge the signal is against your own traffic. Request a demo and we will walk through what Bot Radar surfaces and how it feeds your WAF, CDN and anti-fraud stack.

Request a demo