Anti-detect browser detection

Read the machineunder the rewrite.

An anti-detect browser rewrites what the page reports. One verify call returns what the hardware underneath still renders, and whether the two hold together.

Read on load, no interaction
What it says it isdevice

platform
screen
timezone
Coherencerisk
--/ 100
trust score
What it rendersdevice.hardware
gpu_renderer
gpu_vendor
cpu_cores
Findingsintegrity
tampered
anti_detect_browser
runtime_patched
platform_mismatch
Readingsintegrity
privacy_tooling
virtual_machine
rendering_anomaly
automation
Reading this browser
01The rewrite

Rewriting one surface leaves the rest to argue with it

A profile controls what the page reports, never what the GPU draws.

A recorded anti-detect session
platformWin32, Windows 11Darwin, arm64
screen.resolution1920x1080 @1xholds
timezoneEurope/Warsawholds
hardware.gpu_rendererNVIDIA GeForce RTX 3060SwiftShader, software
font_count41holds
canvas readbackstable hashnew hash per read
4of 8 surfaces where the measurement overruled the profile
risk
runtime_patched+34
platform_mismatch+26
rendering_anomaly+19
privacy_tooling+9
12/ 100REWRITTEN
trust score
02Findings

Two of these findings accuse nobody

A rewritten environment and a randomised one raise different fields, so a careful visitor does not read as an attacker.

A build nobody has catalogued still reports

Wrapping the reads leaves an interception pattern behind, and the field reports the pattern.

integrity.tamperedthis browser
Step the session up

The engine itself is named

A known engine is identified before any surface it rewrote is read.

integrity.anti_detect_browserthis browser
Treat as adversarial

An ordinary setup raises both

Randomised readbackintegrity.privacy_tooling

A privacy browser as often as an attacker.

Bind the sessionthis browser
No physical GPUintegrity.virtual_machine

A hosted desktop renders the same way.

Weigh with the networkthis browser
03Your session

The same sweep, on the browser reading this

--of 23 flags raised on this session
  • anti_detect_browser
  • tampered_environment
  • runtime_patched
  • platform_mismatch
  • rendering_anomaly
  • spoofed_device
  • privacy_tooling
  • virtual_machine
  • bot
  • automation
  • incognito
  • vpn
  • tor
  • datacenter
  • mobile_network
  • synthetic_behavior
  • automated_mouse
  • challenge_failed
  • high_velocity
  • bad_reputation
  • outdated_client
  • token_problem
  • new_device
Open every field this scan returnedin the playground
04Wiring

The findings reach your own signup handler

signup.tsxCLIENT
import { useTrustSig } from "@trustsig/react";

const { getResponse } = useTrustSig();
const { token } = await getResponse();
signup.jsSERVER
import { TrustSig } from '@trustsig/server';

const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY });

app.post('/signup', async (req, res) => {
  const token = req.headers['x-trustsig-response'];
  const result = await ts.verifyRemote(token);

  // is_bot is true once the session crossed the block threshold.
  if (result.is_bot) {
    return res.status(403).json({ error: 'Access denied.' });
  }

  const { anti_detect_browser, tampered, privacy_tooling, virtual_machine } =
    result.integrity;

  // A named engine, or the interception pattern one leaves behind.
  if (anti_detect_browser || tampered) {
    return requireSecondFactor(result.identity.device_id);
  }

  // Randomised readback on its own is a privacy browser as often as an
  // attacker. Bind the account to the device instead of turning them away.
  if (privacy_tooling) {
    return completeSignup(req, res, { pin: result.identity.device_id });
  }

  // A software renderer is ordinary on a corporate desktop and is not on a
  // hosting network. The pair is the finding, neither half alone.
  if (virtual_machine && result.network.datacenter) {
    return res.status(403).json({ error: 'Access denied.' });
  }

  return completeSignup(req, res);
});
05Limits

What the block does not claim

A privacy browser is not an attackerintegrity.privacy_tooling
Randomised readback raises this field and nothing else.
A virtual machine is somebody's work laptopintegrity.virtual_machine
Hosted desktops, remote workers and QA fleets all render through software.
A fresh profile is a fresh device ididentity.device_id
Reset the profile and the id moves with it. The integrity findings survive the reset.
The probe list stays unpublishedintegrity.tampered
The response reports that the interception pattern is present, never which probe saw it, because a published probe gets patched.
06 Answers

Anti-detect browsers, answered

A known engine is named outright. Everything else is caught by the interception pattern a rewritten environment leaves behind, so a build TrustSig has never seen still reports as tampered. The probes that fired are not published, because publishing them is how they get patched.

No. Randomised canvas and WebGL readback sets integrity.privacy_tooling, separately from integrity.tampered and integrity.anti_detect_browser, so a privacy browser and an anti-detect build never arrive looking the same.

A new profile produces a new identity.device_id, but the integrity findings survive the reset: an anti-detect build rewrites the same surfaces on the second run as on the first, and reports the same way. Linking the two profiles back to one machine is TrustSig Pro.

No. /verify returns action, the risk grade and the evidence behind it, and the branch is yours. An anti-detect browser on a signup route and the same browser on a support page are not the same problem, so a fixed answer would be wrong on one of them.

integrity.virtual_machine covers virtual machines, emulators and software renderers, so a corporate VDI desktop and a remote worker on a hosted image both raise it. It arrives as one finding in a response that also carries network.datacenter, which is what separates a hosting fleet from an office build.

One script tag and one server call. The integrity block is filled by the same scan that produces the token, so there is no second request, no puzzle and nothing for the visitor to complete. See the response schema for every field it returns.

Put the reading behind your own gate.

One script tag, one server call, and the integrity block is in the first response.