Protect · Trust
Network Sentinel
Know every device. Understand every connection. Keep your network private.
Local-first network detection and investigation: every device identified, every connection explained, and no traffic sent to the cloud.
What is Network Sentinel?
Network Sentinel runs on hardware you own and watches your network through sensors you control — Zeek, Suricata, your firewall and your DNS server — plus an optional endpoint agent that names the process behind each connection. It builds an inventory of every device from several signals at once, learns what each one normally does, and reports what changed: a new device, a destination never contacted before, an upload far outside a device's usual range, an IoT device reaching for a workstation. Every risk score is the sum of listed reasons, every finding links to the telemetry that produced it, and packet data never leaves the machine. An optional investigator explains findings using a local model by default; a cloud model is used only if you allow it, and only on redacted, structured findings.
Problems it solves
- Find out which devices are on the network, including ones nobody recognises
- See what each device communicates with, and which process made the connection
- Notice when a device behaves differently from its own history
- Investigate an unusual upload with volume, destination and timing side by side
- Keep packet data and browsing history on hardware you own
Key capabilities
- Device Discovery
- Identify every device on a network from several signals at once — hardware address, DHCP, mDNS, services and behaviour — with a stated confidence.
- Behavioral Baselines
- Learn what each device normally does, and report deviations against that device's own history rather than a generic rule.
- Risk Scoring
- Score a change, a lot or a habitat on a published rubric you can read component by component.
- Evidence Trail
- Every figure carries the record it came from, so a reader can check the answer instead of trusting it.
- Timeline Construction
- Assemble dated events into a timeline, each entry linked to its source.
- Privacy-First AI Routing
- Prefer models that run locally, and let only redacted, structured findings reach a cloud model when policy explicitly allows it.
- Agentic Investigation
- Specialist agents pursue a question through several controlled steps rather than answering in one pass.
How it is built
- Multi-signal device identity
- Hardware address, DHCP, mDNS, services and behaviour combined, with a stated confidence — private MAC rotation included.
- Per-device baselines
- Destinations, ASNs, countries, ports, hours and volumes learned for each device over 24 hours to 90 days.
- Explainable risk
- Every score is the sum of listed factors, and every factor points at the telemetry behind it.
- Investigations with timelines
- Related findings grouped into a case with a clickable timeline from DNS lookup to process attribution.
- Local AI first
- Explanations from a local model by default; cloud models only by explicit choice, after redaction, with every request logged.
How it works
How the work is structured, and what each step's output rests on.
Connect sensors
SourcePoint Sentinel at Zeek, Suricata, your firewall or DNS server, and optionally enrol endpoints.
Identify devices
ObservedBuild the inventory from DHCP, mDNS, services and traffic, each with a confidence.
Learn normal
ObservedEstablish each device's baseline over the first day, week and month.
Explain deviations
ObservedScore findings from listed factors and link each to its evidence.
Investigate
AI-inferredGroup related findings into a timeline; add a local-model interpretation if wanted.
Decide
Human-verifiedMark activity expected, or contain it through a confirmed, audited firewall action.
Example use cases
Each example has its own page you can read and share.
Network Sentinel
Find out what an unrecognised device is doing on your network
Identify a device nobody recognises, see everything it has contacted, and decide whether it belongs.
4 minute walkthrough
- Device Discovery
- Behavioral Baselines
- Evidence Trail
Network Sentinel
Investigate an unusual upload without sending your traffic anywhere
See how far an upload departs from a device's normal, where it went, and which program sent it.
5 minute walkthrough
- Behavioral Baselines
- Risk Scoring
- Privacy-First AI Routing
Network Sentinel
Spot an IoT device reaching for your computers
Notice when a TV, camera or speaker opens a connection to a workstation or NAS it has never talked to before.
3 minute walkthrough
- Device Discovery
- Behavioral Baselines
- Risk Scoring
Ask Network Sentinel
Illustrative examples. Results depend on your own data.
- “Which devices on my network are new this week?”
- “Why was this upload flagged, and what does the device normally send?”
- “Which process on the studio PC made this connection?”
- “Is anything on the IoT devices talking to my computers?”
Security, governance and human control
Where the software deliberately limits itself.
Security
- Packet payload capture disabled by default; never transmitted
- Passkeys, TOTP and role-based access; every security action audited
Governance
- Risk scores decomposed factor by factor
- AI output separated from observed facts and cited to evidence
Questions
- Does my network traffic leave my network?
- No. Packets are analysed on the machine running Sentinel and packet payloads are never transmitted. Cloud AI is off by default; if you enable it, only redacted, structured findings are sent, and each request is recorded with its exact content.
- Do I need a Clearception subscription?
- No. Detection, baselines, investigations and local AI run without one. Sentinel works without an internet connection.
- Will it tell me I have been hacked?
- It reports behaviour — a new destination, an unusual upload, an IDS signature match — with the evidence and a suggested next step. It does not claim a compromise the evidence does not establish.
Related applications
Teams using Network Sentinel often want these too.
Cortex Grid
Evidence before conclusions.
Capabilities
- Chain of Custody
- Entity Resolution
- Timeline Construction
- Media Authenticity
Pipeline
One delivery plane from commit to production.
Capabilities
- Delivery Traceability
- Deterministic Policy Engine
- Risk Scoring
- Agentic Investigation
DeepQuery
Ask your databases a question, in words.
Capabilities
- Natural-Language Query
- Cross-Source Intelligence
- Evidence Trail
- Agentic Investigation
Start with Network Sentinel
Protect is one of 9 categories, each its own subscription; Clearception One includes them all.