Use case · Saas & software
Credential Stuffing & DDoS Source Detection
Automated attacks against authentication endpoints are constant for any platform of size. Credential stuffing in particular is high-volume, distributed, and routed through residential proxies specifically to defeat rate limiting and plain IP reputation.
Why this defeats rate limiting
Quick answer
Credential stuffing spreads volume across large numbers of residential-proxy IPs specifically to stay under any single-address rate limit. The signal that survives that distribution is infrastructure category, not per-IP request count — which is why supplementary IP intelligence, not more rate limiting, is what actually catches it.
Rate limiting was designed for a concentrated attack: many requests from one place. Residential-proxy-routed credential stuffing is the opposite by design — few requests from each of many places, each address looking like an ordinary home connection with no individual history of abuse.
What doesn't change with distribution is the category of infrastructure being used. A residential proxy network is identifiable as such regardless of how many individual addresses it rotates through.
How IP Raccoon helps
At the edge
WAF & CDN rules
Supplementary IP intelligence loaded as files and evaluated with zero added latency, pulled from a permalink that does not change between releases — complementing whatever reputation lists your WAF already ships with.
In your stack
SIEM & log enrichment
File download for log enrichment: automation and proxy infrastructure context alongside your existing threat sources, so alerts are easier to triage and classify.
Log ingestion is priced by volume in every major SIEM and observability platform — filtering or tagging a meaningful share of bot traffic before ingestion is a measurable, direct cost saving on top of the security benefit.
What to look for in a supplementary threat feed
- Independence from your platform's built-in reputation lists — a complement, not a duplicate
- Residential proxy coverage specifically, since that's the infrastructure built to defeat IP reputation
- Both a file format for edge/SIEM ingestion and an API for real-time checks, since attacks show up in both places
- Releases that keep pace with rotating proxy pools, reaching your stack through a permalink instead of a re-integration each time
$ curl -o anonymizers.csv \ "https://files.ipraccoon.com/download/anonymizers?authorization=$IP_RACCOON_TOKEN&format=csv_plus" slugs: reputation · anonymizers · detected_bots · known_bots formats: csv (subnet) · csv_plus (subnet + subcategory) · mmdb use: SIEM ingestion, WAF rules, log enrichment
See the infrastructure behind your login attempts
Enrich your logs or edge rules with IP Raccoon and find the residential-proxy traffic your current tools are missing.
FAQ