New Security Tool Targets Cyber Threats Hidden Behind VPNs and Proxies

Last updated: September 2, 2026 Reading time: 5 minutes
Disclosure
Share
Spur Launches Tool to Help Security Teams Detect Hidden VPN and Proxy Traffic
  • Hackers hide behind VPNs and proxies to look like normal, safe visitors.
  • Most security tools only check one part of a visit, not the whole picture.
  • A tool called Monocle adds missing details so security teams can catch more threats.

Website owners use many tools to stop hackers. But even with all these tools working together, some hackers still slip through. They hide inside traffic that looks just like real visitors.

This happens because each tool only checks one small piece of the puzzle. If a hacker uses a home internet address or a paid VPN, they can pass through several checks without setting off any alarms.

According to Spur, the real problem is that most tools don’t know enough about where the traffic is truly coming from.

Where Current Security Tools Fall Short

Website defense works in layers. Each layer answers a different question about visitors. Content delivery networks and web firewalls check requests closely. They block known threats and enforce rules. But they can’t always tell if a normal-looking visit is actually being routed through hidden infrastructure built to disguise where it came from.

Bot detection tools try to spot machines pretending to be humans. Yet not every dangerous visit comes from a bot. Hackers now mix automated tools with networks built to look like everyday, harmless traffic. That combination fools many detection systems.

Login and identity systems check if someone can prove who they say they are. But having the right username and password doesn’t always mean the real account owner is the one typing them in. Someone else could be using stolen details.

Device and browser checks look at the device sending the traffic. They build trust based on details like the browser type. Still, these checks don’t reveal anything about the network carrying that device’s traffic to the website.

Spur explains that each of these tools does its job well on its own. But hackers slip through the small gaps between them. They build sessions that look fine to any single tool, while hiding the true story of their network setup.

Researchers have long focused on closing security gaps. In 2016, Microsoft researchers Itai Grady and Tal Be’ery released SAMRi10, later evolved into NetCease, to help administrators protect enterprise networks from reconnaissance attacks and limit attackers’ ability to map networks after a compromise.

How Session Enrichment Fills the Gap

This gap creates a need for one more layer of information, real facts about the network behind each visit. A company called Spur built a tool named Monocle Session Enrichment to fill that gap.

Monocle checks every visitor session and adds real-time trust details. These include whether the visitor is hiding their identity, using a known VPN service, connecting from a home network, or linked to networks used by known attackers.

Spur states that this added context helps security and fraud teams make sharper choices at the point of entry. It aims to cut down on risky logins while making things easier for real, trustworthy users.

Monocle blends Spur’s map of internet networks with live details from each session. This builds what Spur calls a Session Trust Assessment. Rather than just marking an internet address as good or bad, it hands over specific details. Security teams then decide what to do with those details.

One sample assessment shared by Spur showed a blocked session. The system flagged the connection as hidden and tied it to a known VPN service, so the request got refused under the site’s rule against anonymous traffic.

Spur notes that this kind of report gives three main things: facts about what Monocle saw, a suggested action based on the company’s own rules, and record-keeping details so teams can trace every decision later.

Fields like whether a VPN or proxy was used tell teams about the connection itself. Newer fields also flag activity linked to AI tools, whether they’re acting like a person or simply crawling the site. Rather than leaving a website to guess what the data means, the report gives a clear yes-or-no answer and explains why.

In the sample case Spur shared, the reason given was that the site’s rules block all hidden connections. Other fields, such as timestamps and ID numbers, let a team trace any decision back to the exact moment it happened.

Spur says the whole point of this extra layer is to hand over network facts. Then, each company can decide what those facts mean for their own users, their own risk level, and their own rules.

Putting the Extra Context to Work

Picture a bank that sees a successful login from a normal-looking address inside the United States. By itself, that’s not alarming. But added context might show that the visitor is hiding their identity, connecting through a data center, and linked to a known VPN service. That extra detail helps the bank make a smarter, faster call.

In practice, a regular customer using their usual device through a VPN might get to continue as normal. But a login using new account details, an unknown device, and hidden network tools might trigger extra identity checks. A large money transfer from that same visit could need even more proof before it goes through.

Spur says this same idea works beyond just stopping stolen logins. During sign-up, network details can flag people trying to hide or repeatedly change their identity. For fake traffic and bot abuse, this extra layer works alongside bot detection tools by showing the network used to spread out the activity.

With location-based rules, companies can tell the difference between a visitor’s real location and one hidden behind a VPN. For AI-driven traffic, companies can add new AI-related flags to rules they already use for humans and bots.

Spur built Monocle to work alongside a company’s current tools, not replace them. Businesses using services like Cloudflare can add this session data straight into their existing rulebooks. Depending on the mix of details, a team might choose to let a session through, challenge it with extra checks, demand stronger proof of identity, block a risky action, send it for closer review, or stop it completely.

Share this article

About the Author

Farwa is an experienced InfoSec writer and cybersecurity journalist skilled in writing articles related to cybersecurity, AI, DevOps, Big Data, Cloud security, VPNs, IAM, and Cloud Computing. Also a contributor on Tripwire.com, Infosecurity Magazine, Security Boulevard, DevOps.com, and CPO Magazine.

More from Farwa Sajjad

Related Posts