Security Wiki
Clear definitions of CAPTCHA, bot protection, online fraud, and web security terms from the CaptchaFox team.
A sniper bot places a winning bid or claim in the final instant of an auction or sale window, beating every human reaction time by design.
Read moreA synthetic account is built on a fabricated identity that blends real and invented data — designed to pass verification and age into a trusted profile.
Read moreA ticket bot is automation that buys event tickets in bulk the moment sales open, feeding a resale market at inflated prices — and it is widely outlawed.
Read moreA VPN routes traffic through an encrypted tunnel to a remote server, hiding the user's IP address — a privacy tool that complicates IP-based security.
Read moreA WAF inspects HTTP traffic and filters requests that match attack patterns like SQL injection and XSS — a distinct layer from bot management.
Read moreA web cookie is a small piece of data a website stores in the browser to remember state — the mechanism behind sessions, preferences, and tracking.
Read moreAccount takeover is a form of identity fraud in which an attacker gains control of a legitimate user account and exploits it for financial gain.
Read moreAd fraud is the practice of generating fake ad impressions, clicks, or conversions to steal advertising budgets — most of it executed by bots at scale.
Read moreAgentic fraud is online fraud executed by AI agents that plan and adapt across multi-step schemes — account creation, abuse, and monetization — autonomously.
Read moreAn AI agent is software that uses a language model to plan and carry out multi-step tasks on its own — including operating websites through a real browser.
Read moreAn anti-detect browser is a modified browser that spoofs fingerprints and manages many separate identities — a staple of fraud and multi-account abuse.
Read moreAn invisible CAPTCHA verifies that a visitor is human in the background, without a puzzle — a challenge only appears when signals indicate automation.
Read moreAn IP address is the numerical identifier that routes traffic to a device on a network — and one of the most used, and most overrated, security signals.
Read moreAn OTP bot is an automated calling or messaging tool that tricks victims into revealing one-time passcodes, letting attackers bypass two-factor authentication.
Read moreAPI abuse is the misuse of an application's programming interfaces by bots and attackers — bypassing the web frontend to attack the logic directly.
Read moreBehavioral analysis distinguishes humans from automation by how a session interacts — cursor movement, typing rhythm, scrolling — no user input required.
Read moreBot detection is the process of identifying automated traffic among human visitors by analyzing network, device, and behavioral signals per request.
Read moreBot management is the discipline of detecting, classifying, and responding to automated traffic — allowing good bots while blocking or challenging bad ones.
Read moreBot traffic is any website or API traffic generated by automated software instead of humans, and a large share of it is malicious.
Read moreBots-as-a-Service is the commercial rental of ready-made bot infrastructure — automation, proxies, and evasion tooling sold as a subscription.
Read moreFight bots and protect your users' data.
Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.