CustomersFSEC
FSEC uses Proxynet to detect web technologies
Nuri BaşSenior QA Engineer
“To see what an application behind a CDN and WAF actually shows a real user, you need a real user IP. Proxynet's Residential pool does that quietly and without interruption.”
Challenge
FSEC's discovery engine has to find every internet-facing asset of an organization and detect which services, software and technologies each one runs. That means looking at the asset from where the internet sees it. Requests from a single source, though, gave an incomplete or region-dependent picture because of CDNs, WAFs and rate limits.
Solution
The data collection of the discovery and technology-detection stage runs through Proxynet. High-volume inventory scans go through Datacenter proxies, detections that need a real-user view of protected assets go through Residential proxies, and the regular re-checks of the same assets over time go through ISP proxies.
Results
Internet-facing assets are inventoried completely, viewed from different countries and networks
Service and technology detection is done on what the asset actually shows a real user
Content and configurations that vary by region are seen separately
Regular re-checks come from fixed IPs, so results stay comparable over time
About FSEC
FSEC is a security platform that automatically inventories an organization's internet-facing and internal assets, services, technologies and cloud, IoT and OT systems. It detects which services and software each asset runs, and correlates vulnerabilities, misconfigurations and other weaknesses across assets, technologies, risks and attack paths to surface the risks that are actually exploitable.
The platform does not stop there. It tests web applications, APIs and modern AI applications the way a real attacker would, chains vulnerabilities together to validate attack scenarios and produces reproducible evidence. It analyzes source code, dependencies, SBOMs, CI/CD pipelines and production artifacts to secure the software supply chain. It prioritizes the risks it finds, starts the remediation process and verifies that a fix really removed the risk. A continuous security loop from discovery to attack simulation, from risk management to remediation.
Everything starts with discovery
The first link in that loop is discovery. An organization's internet-facing assets have to be found, and for each one the web server, application framework, library and cloud service behind it have to be identified. If the inventory is incomplete, every later step is incomplete too: an asset that was not detected is not tested, and a newly published threat is not seen to affect it.
The problem is that an asset does not look the same from everywhere. CDN and WAF layers treat requests from datacenter IPs differently, some services serve different content or configuration by region, and a single source that sends frequent requests is rate-limited within minutes. The FSEC team noticed early that discovery from a single vantage point left gaps in the picture.
"To identify an asset correctly you have to look at it from where the internet sees it," says the FSEC team. "What we saw from our own infrastructure was not always what our customer's user saw."
Proxynet's role
FSEC runs the data collection of its discovery and technology-detection stage through Proxynet. Three products, three separate jobs.
Datacenter proxies carry the high-volume inventory scans. Sufficient and economical for listing thousands of assets quickly and collecting basic service information.
Residential proxies step in on protected assets. What an application behind a CDN and WAF shows a real user, which technologies can be detected from outside and what changes by region is seen through real user IPs from different countries and cities.
ISP proxies are used for the monitoring jobs where the same assets are re-checked regularly over time. Because the IP does not change, today's result can be compared with yesterday's; a technology change or a newly opened service becomes visible. A fixed IP is also preferred for checks that have to be allow-listed on the customer's side.
"For us a proxy is a matter of vantage point. Looking at the same asset from Frankfurt, Istanbul and London and seeing the difference is what makes the inventory correct."
How the collected data is correlated, which risks count as exploitable and how attack scenarios are validated is the job of FSEC's own engine. Proxynet is only in the first link of that chain: looking at the asset correctly from the outside.
Outcome
FSEC's inventory is no longer built from a single point but from different corners of the internet. Technology detection is done on what the asset shows a real user, region-dependent differences are not missed, regular checks continue from fixed IPs in a comparable way, and the three products are managed from one panel. Trusting that the discovery side is complete, the team focuses on its real work: validating and closing risks.
"If the discovery layer is right, the rest works right. Proxynet is the quiet part of that layer."