Protect · Trust

Network Sentinel

Know every device. Understand every connection. Keep your network private.

Local-first network detection and investigation: every device identified, every connection explained, and no traffic sent to the cloud.

What is Network Sentinel?

Network Sentinel runs on hardware you own and watches your network through sensors you control — Zeek, Suricata, your firewall and your DNS server — plus an optional endpoint agent that names the process behind each connection. It builds an inventory of every device from several signals at once, learns what each one normally does, and reports what changed: a new device, a destination never contacted before, an upload far outside a device's usual range, an IoT device reaching for a workstation. Every risk score is the sum of listed reasons, every finding links to the telemetry that produced it, and packet data never leaves the machine. An optional investigator explains findings using a local model by default; a cloud model is used only if you allow it, and only on redacted, structured findings.

Problems it solves

  • Find out which devices are on the network, including ones nobody recognises
  • See what each device communicates with, and which process made the connection
  • Notice when a device behaves differently from its own history
  • Investigate an unusual upload with volume, destination and timing side by side
  • Keep packet data and browsing history on hardware you own

Key capabilities

Device Discovery
Identify every device on a network from several signals at once — hardware address, DHCP, mDNS, services and behaviour — with a stated confidence.
Behavioral Baselines
Learn what each device normally does, and report deviations against that device's own history rather than a generic rule.
Risk Scoring
Score a change, a lot or a habitat on a published rubric you can read component by component.
Evidence Trail
Every figure carries the record it came from, so a reader can check the answer instead of trusting it.
Timeline Construction
Assemble dated events into a timeline, each entry linked to its source.
Privacy-First AI Routing
Prefer models that run locally, and let only redacted, structured findings reach a cloud model when policy explicitly allows it.
Agentic Investigation
Specialist agents pursue a question through several controlled steps rather than answering in one pass.

How it is built

Multi-signal device identity
Hardware address, DHCP, mDNS, services and behaviour combined, with a stated confidence — private MAC rotation included.
Per-device baselines
Destinations, ASNs, countries, ports, hours and volumes learned for each device over 24 hours to 90 days.
Explainable risk
Every score is the sum of listed factors, and every factor points at the telemetry behind it.
Investigations with timelines
Related findings grouped into a case with a clickable timeline from DNS lookup to process attribution.
Local AI first
Explanations from a local model by default; cloud models only by explicit choice, after redaction, with every request logged.

How it works

How the work is structured, and what each step's output rests on.

  1. Connect sensors

    Source

    Point Sentinel at Zeek, Suricata, your firewall or DNS server, and optionally enrol endpoints.

  2. Identify devices

    Observed

    Build the inventory from DHCP, mDNS, services and traffic, each with a confidence.

  3. Learn normal

    Observed

    Establish each device's baseline over the first day, week and month.

  4. Explain deviations

    Observed

    Score findings from listed factors and link each to its evidence.

  5. Investigate

    AI-inferred

    Group related findings into a timeline; add a local-model interpretation if wanted.

  6. Decide

    Human-verified

    Mark activity expected, or contain it through a confirmed, audited firewall action.

Example use cases

Each example has its own page you can read and share.

Network Sentinel

Spot an IoT device reaching for your computers

Notice when a TV, camera or speaker opens a connection to a workstation or NAS it has never talked to before.

3 minute walkthrough

  • Device Discovery
  • Behavioral Baselines
  • Risk Scoring

Ask Network Sentinel

Illustrative examples. Results depend on your own data.

  • “Which devices on my network are new this week?”
  • “Why was this upload flagged, and what does the device normally send?”
  • “Which process on the studio PC made this connection?”
  • “Is anything on the IoT devices talking to my computers?”

Security, governance and human control

Where the software deliberately limits itself.

Security

  • Packet payload capture disabled by default; never transmitted
  • Passkeys, TOTP and role-based access; every security action audited

Governance

  • Risk scores decomposed factor by factor
  • AI output separated from observed facts and cited to evidence

Questions

Does my network traffic leave my network?
No. Packets are analysed on the machine running Sentinel and packet payloads are never transmitted. Cloud AI is off by default; if you enable it, only redacted, structured findings are sent, and each request is recorded with its exact content.
Do I need a Clearception subscription?
No. Detection, baselines, investigations and local AI run without one. Sentinel works without an internet connection.
Will it tell me I have been hacked?
It reports behaviour — a new destination, an unusual upload, an IDS signature match — with the evidence and a suggested next step. It does not claim a compromise the evidence does not establish.

Teams using Network Sentinel often want these too.

Pipeline

One delivery plane from commit to production.

Capabilities

  • Delivery Traceability
  • Deterministic Policy Engine
  • Risk Scoring
  • Agentic Investigation

Start with Network Sentinel

Protect is one of 9 categories, each its own subscription; Clearception One includes them all.