JS APIs blocked or randomized (Canvas, WebGL, Fonts, Audio) Network-level protections (spoofed UA, anti-ETag, spoofed headers) CSP and DOM injection to block leaks Prevents WebRTC, Geolocation, ...