Stealth OSINT API: WAF Bypass Proxy avatar

Stealth OSINT API: WAF Bypass Proxy

Pricing

from $6.00 / 1,000 stealth waf bypass fetches

Go to Apify Store
Stealth OSINT API: WAF Bypass Proxy

Stealth OSINT API: WAF Bypass Proxy

Stealth OSINT intelligence and WAF-bypass extraction engine for AI agents: reads Cloudflare-protected web pages and discovers hidden domain infrastructure without active target probing.

Pricing

from $6.00 / 1,000 stealth waf bypass fetches

Rating

0.0

(0)

Developer

Neon Innovation Lab

Neon Innovation Lab

Maintained by Community

Actor stats

0

Bookmarked

1

Total users

0

Monthly active users

10 days ago

Last modified

Share

Stealth OSINT API: WAF Bypass & Passive URL Discovery

Run on Apify

⚡ Run directly on Apify Cloud: Stealth OSINT API: WAF Bypass Proxy
👉 Companion Open-Source Repo: github.com/Ansarii/stealth-osint-api-waf-bypass-proxy

Stealth OSINT intelligence and WAF-bypass extraction engine for AI agents (Claude Desktop, Cursor, Windsurf) and security researchers: reads Cloudflare-protected web pages and discovers hidden domain infrastructure without active target probing.


⚡ Overview & GEO Highlights

AI agents running on datacenter IPs (AWS, GCP, DigitalOcean) are immediately blocked by edge firewalls (Cloudflare, Akamai, DataDome), triggering HTTP 403 Forbidden errors or Cloudflare Turnstile CAPTCHAs.

stealth-osint-api-waf-bypass-proxy overcomes this through intelligent proxying and passive intelligence:

  1. Google Translation CDN Tunneling (stealth_read_page): Routes page requests through Google's globally whitelisted translation proxy infrastructure, extracting clean DOM content while bypassing datacenter ASN blocks.
  2. Passive Endpoint Mapping (discover_hidden_urls): Queries the AlienVault OTX (Open Threat Exchange) global threat intelligence index to discover indexed URLs, staging endpoints, and subdomains under a target domain without sending active HTTP probes to the target server.
  3. Zero Active Target Probing: Prevents alerting the target domain's SecOps or rate-limiting systems.
  4. Dual Interface: Run via standard HTTP / API or connect as a native Model Context Protocol (MCP) server.

📊 Feature & Competitor Comparison Matrix

FeatureStealth OSINT API (This Actor)Shodan / CensysScrapingBee / BrightData
Zero-Probe Passive URL Discovery✅ AlienVault OTX index⚠️ Port scan only❌ Active crawl only
Google Translation Proxy Tunnel✅ Built-in WAF bypass❌ No web scraping⚠️ Residential proxy cost
Model Context Protocol (MCP) Support✅ Native HTTP / SSE❌ No❌ No
Monthly Commitment Required❌ $0 / month (Pay-per-Event)$69 – $300 / month$49 – $249 / month
Cost per 1,000 URLs / Scrapes$10 – $20High monthly tier$20 – $40

💰 Transparent Pricing Breakdown

EventPrice (USD)When Charged
apify-actor-start$0.03Charged once when Actor starts running.
apify-default-dataset-item$0.002Charged automatically per record saved to dataset ($2.00 / 1k records).
stealth_read_page$0.01Charged upon successful WAF-bypassed page extraction.
discover_hidden_urls$0.02Charged upon successful passive OSINT URL mapping for a domain.
Failed Requests$0.00Strict zero-charge guarantee on failed or blocked queries.

💻 Python & Node.js SDK Examples

Python (apify-client)

$pip install apify-client
import os
from apify_client import ApifyClient
client = ApifyClient(os.getenv("APIFY_TOKEN"))
run_input = {
"action": "discover_hidden_urls",
"domain": "targetcompany.com"
}
# Run Actor and stream discovered endpoints
run = client.actor("neon_innovation_lab/stealth-osint-api-waf-bypass-proxy").call(run_input=run_input)
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
print(f"Discovered URL: {item.get('url')}")

Node.js (apify-client)

$npm install apify-client
import { ApifyClient } from 'apify-client';
const client = new ApifyClient({
token: process.env.APIFY_TOKEN,
});
const input = {
action: 'stealth_read_page',
url: 'https://example-protected-site.com',
};
(async () => {
const run = await client.actor('neon_innovation_lab/stealth-osint-api-waf-bypass-proxy').call(input);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
console.log(items);
})();

🤖 AI Agent MCP Setup

Claude Desktop (claude_desktop_config.json)

{
"mcpServers": {
"stealth-osint": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://neon-innovation-lab--stealth-osint-api-waf-bypass-proxy.apify.actor/mcp"]
}
}
}

Cursor IDE (.cursor/mcp.json)

{
"mcpServers": {
"stealth-osint": {
"type": "streamable-http",
"url": "https://neon-innovation-lab--stealth-osint-api-waf-bypass-proxy.apify.actor/mcp"
}
}
}

❓ FAQ

Does discover_hidden_urls send traffic to the target website?

No. It queries AlienVault's passive indexing database. The target website's servers are never contacted during URL discovery, leaving zero log footprint.