Anonymized Infrastructure Now Touches 94% of Incidents, and Most SOCs Are Still Playing Catch-Up
Survey data points to a persistent gap between IP enrichment volume and the analyst's ability to answer a simple question: who's actually on the other end?

Key points
- 94% of surveyed SOC analysts, incident responders, and threat hunters reported anonymized infrastructure featured in investigations.
- Commercial VPNs, residential proxies, Tor exits, and proxyware bundled into consumer apps are now baseline tradecraft across threat actor tiers.
- Most respondents described their triage workflow as reactive: enrich after the alert fires, decide whether to block, move on.
- Analysts rated confidence in IP context as one of their lowest-scoring data points, behind malware family attribution and behavioral analytics.
- A corporate VPN concentrator and a proxyware-infected smart TV look similar at the netflow level but carry very different investigative weight.
How bad is the enrichment problem really?
Analysts have never been short on IP data. Enrichment feeds, geolocation, reputation scores, passive DNS, telemetry from multiple vendors: the pipes are full. The question is whether any of it gets you closer to attribution.
New survey numbers suggest the answer is often no. In responses gathered from incident responders and analysts across SOC functions, 94% reported that anonymized infrastructure featured in incidents they investigated. Residential proxy networks have become baseline tradecraft for everyone from credential-stuffing operators to state-aligned intrusion sets. The capability is commodity now. Intent is the only variable.
Should you worry about how feeds classify IP ranges?
Reputation feeds disagree constantly on whether a given address block is residential, hosting, or VPN egress, and a single mislabel cascades into false positives or missed activity. Analysts surveyed rated confidence in IP context as one of their lowest-scoring data points, behind malware family attribution and behavioral analytics.
Tooling is part of the problem. Data quality is another. Our June reporting on Bright Data's iOS SDK, which showed how consumer apps relay traffic through always-on devices like smart TVs, illustrates why the classification gap is widening: the infrastructure defenders are trying to label keeps shapeshifting.
There's also a definitional problem. A corporate VPN concentrator and a proxyware-infected smart TV look similar at the netflow level but mean very different things for an investigation. Conflating them is how good leads die.
What should analysts actually do differently?
Proactive hunting against anonymization infrastructure, fingerprinting proxy networks, tracking ASN churn, identifying residential ranges before they hit the SIEM, remains the exception. The survey's more uncomfortable finding is that most respondents described a purely reactive workflow: flag after the alert, enrich, block or ignore, repeat.
Treat IP reputation as a starting hypothesis, not a verdict. Cross-reference with passive DNS, JA3/JA4, and timing. Build internal ground truth where you can: known-good VPN ranges from your own workforce are the cheapest ASN labels you'll ever get.
None of this is novel to seasoned hunters. But the survey is a useful reminder that the gap between data volume and analytical confidence keeps widening. More feeds haven't fixed it. Better questions might.
Attribution, as ever, is held at medium confidence on a good day. The number worth watching here isn't 94%: it's whatever percentage of those incidents actually produced a confident attribution call, and the survey doesn't give us that. That's the gap worth closing.



