Anonymized Infrastructure Now Touches 94% of Incidents, and Most SOCs Are Still Playing Catch-Up

Survey data points to a persistent gap between IP enrichment volume and the analyst's ability to answer a simple question: who's actually on the other end?

ThreatVectr Newsdesk· 2 min read
Anonymized Infrastructure Now Touches 94% of Incidents, and Most SOCs Are Still Playing Catch-Up
Share

Analysts have never been short on IP data. Enrichment feeds, geolocation, reputation scores, passive DNS, telemetry from half a dozen vendors — the pipes are full. The question is whether any of it gets you closer to attribution.

New survey numbers suggest the answer is often no.

In responses gathered from SOC analysts, threat hunters, and incident responders, 94% reported that anonymized infrastructure — commercial VPNs, residential proxies, Tor exits, and increasingly proxyware bundled into consumer apps — featured in incidents they investigated. That number tracks with what most CTI teams already suspect. Residential proxy networks have become baseline tradecraft for everyone from credential-stuffing operators to state-aligned intrusion sets.

A few clusters illustrate the shift. Activity tracked by Microsoft as Storm-1575 and adjacent phishing-as-a-service operators routinely fronts authentication traffic through residential IP space to defeat impossible-travel rules. North Korea-nexus activity that overlaps with what vendors variously call Kimsuky, APT43, or Emerald Sleet has shown similar behavior, with operators rotating through proxy pools to mask originating ASN. Iranian access brokers do the same. The capability is now commodity. Intent is the only variable.

The survey's more uncomfortable finding: most respondents described their workflow as reactive. Analysts flag an IP after it shows up in an alert, enrich it, decide if it's worth blocking, and move on. Proactive hunting against anonymization infrastructure — fingerprinting proxy networks, tracking ASN churn, identifying residential ranges before they hit the SIEM — remains the exception.

Part of that is tooling. Part of it is data quality. Reputation feeds disagree constantly on whether a given /24 is residential, hosting, or VPN egress, and a single mislabel cascades into either false positives or missed activity. Analysts surveyed cited confidence in IP context as one of their lowest-rated data points, behind malware family attribution and behavioral analytics.

There's also a definitional problem. "Anonymized" covers a lot of ground. A corporate VPN concentrator and a proxyware-infected smart TV look similar at the netflow level but mean very different things for an investigation. Conflating them is how good leads die.

A few practical takeaways from the data:

  • Treat IP reputation as a starting hypothesis, not a verdict. Cross-reference with passive DNS, JA3/JA4, and timing.
  • Build internal ground truth where you can. Known-good VPN ranges from your own workforce are the cheapest ASN labels you'll ever get.

None of this is novel to seasoned hunters. But the survey is a useful reminder that the gap between data volume and analytical confidence keeps widening. More feeds haven't fixed it. Better questions might.

Attribution, as ever, is held at medium confidence on a good day.

© 2026 Threat Vectr