All Vendors
data_enrichment

Dstillery

Dstillery is a data enrichment vendor with a VRS of 80. Deploys comprehensive behavioral biometrics and session recording to feed custom audience segments for programmatic advertising.

78 IOCs37 detections11% pre-consent35 sites
80
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Dstillery discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

37 detections across 35 sites11% pre-consent activity
MEDIUM

Pre-Consent Activity

Dstillery was observed loading and executing before user consent was obtained on 11% of sites where it was detected.

GDPRePrivacy
Disclosure Gaps

Claims vs. Observed Behavior

1 gaps

pending

UNKNOWN
They Claim

Unknown

Observed Behavior

Requires claims extraction via CDT

Customer Impact

What This Means For You

Customers visiting sites with Dstillery face behavioral tracking designed explicitly for external audience syndication. Behavioral data including interaction patterns, content engagement, scroll behavior, and session replays are captured and processed to assign visitors to custom audience segments. These segments are then sold to programmatic advertisers including direct competitors who target your qualified traffic using Dstillery-derived behavioral intelligence.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Dstillery

  • Audit Dstillery audience segment syndication contracts and prohibit competitor access to custom audiences derived from your traffic
  • Disable Dstillery behavioral biometrics and session recording features to minimize data enrichment depth
  • Review DPA for audience data sharing restrictions and enforce strict prohibitions on competitor targeting
  • Implement consent-conditional Dstillery load to prevent pre-acceptance behavioral capture
  • Establish audience segment retention limits and require regular purging of visitor behavioral profiles

If You're Evaluating Dstillery

  • Question business necessity of Dstillery deployment given 90% CAC subsidization from audience syndication to competitors
  • Require contractual guarantee that custom audiences derived from your traffic are never sold to direct competitors
  • Verify Dstillery does not employ session recording or behavioral biometrics without explicit consent
  • Assess alternative audience targeting approaches (first-party data enrichment, contextual targeting) that do not feed competitor networks
  • Demand significant pricing concessions or consider removal given primary purpose is external data monetization

Negotiation Leverage

  • VRS 80 classification with 90% CAC subsidization justifies immediate removal or 60% discount with competitor exclusion guarantees
  • 100% legal tail risk demands indemnification for session recording consent failures and behavioral biometrics processing violations
  • Require contractual guarantee that custom audiences derived from your traffic include competitor exclusion lists
  • Request quarterly reporting on which advertisers have accessed Dstillery segments derived from your visitor data
  • Negotiate audience syndication scope limits (demographic only, no behavioral) or revenue sharing from external audience monetization
Runtime Detections

Runtime Detections

5 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

Impact: Dstillery tracking pixels fire before consent acceptance to capture maximum behavioral data for audience modeling.

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

Impact: Mouse movements, scroll patterns, and interaction timing captured to build engagement scoring and audience quality models.

BTI-C07Session Recording

Full session replay

Impact: DOM capture and interaction replay used to identify high-intent visitors for custom audience segment creation.

BTI-C09Consent Bypass

Ignoring CMP signals

Impact: Dstillery maintains behavioral tracking after consent rejection, claiming legitimate interest for audience research.

BTI-C10Fingerprinting

Device identification

Impact: Browser fingerprinting used to reconnect visitors across properties for longitudinal audience segment assignment.

IOC Manifest

IOC Manifest

69 INDICATORS

Indicators of compromise across 4 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*dstillery.com/wp-includes/js/jquery/jquery.js*
Tracking script
TRACK
*dstillery.com/wp-includes/js/jquery/jquery-migrate.js*
Tracking script
TRACK
*dstillery.com/wp-content/cache/min/1/widget.js*
Tracking script
TRACK
*dstillery.com/wp-content/cache/min/1/aos@2.3.1/dist/aos.js*
Tracking script
TRACK
*dstillery.com/wp-content/themes/udstillery/js/child-theme.js*
Tracking script
TRACK
*dstillery.com/wp-content/cache/min/1/wp-content/plugins/stop-user-enumeration/frontend/js/frontend.js*
Tracking script
TRACK
*dstillery.com/wp-content/plugins/wp-accessibility/js/wp-accessibility.js*
Tracking script
TRACK
*dstillery.com/wp-content/plugins/wp-rocket/assets/js/lazyload/17.8.3/lazyload.js*
Tracking script
TRACK
*dstillery.com/cdn-cgi/challenge-platform/scripts/jsd/main.js*
Tracking script
TRACK
*dstillery.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/*/main.js*
Tracking script
TRACK
dstillery.com/wp-content/cache/min/1/wp-content/plugins/stop-user-enumeration/frontend/js/frontend.js
Auto-extracted from scan
TRACK
dstillery.com/wp-includes/js/jquery/jquery.min.js
Auto-extracted from scan
TRACK
dstillery.com/wp-includes/js/jquery/jquery-migrate.min.js
Auto-extracted from scan
TRACK
dstillery.com/wp-content/cache/min/1/widget.js
Auto-extracted from scan
TRACK
dstillery.com/wp-content/cache/min/1/aos@2.3.1/dist/aos.js
Auto-extracted from scan
TRACK
dstillery.com/wp-content/themes/udstillery/js/child-theme.min.js
Auto-extracted from scan
TRACK
dstillery.com/wp-content/plugins/wp-accessibility/js/wp-accessibility.min.js
Auto-extracted from scan
TRACK
dstillery.com/wp-content/plugins/wp-rocket/assets/js/lazyload/17.8.3/lazyload.min.js
Auto-extracted from scan
TRACK
dstillery.com/cdn-cgi/challenge-platform/scripts/jsd/main.js
Auto-extracted from scan
TRACK
dstillery.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/d251aa49a8a3/main.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Dstillery occupies the data enrichment layer, typically deployed alongside programmatic advertising platforms (Google Display & Video 360, The Trade Desk), DMPs (Adobe Audience Manager, Lotame), and custom audience targeting systems. The vendor creates behavioral data enrichment that feeds external demand networks rather than internal analytics, making it primarily a competitor intelligence source.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

78 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details