Network Sentinel demo

Investigate an unusual upload without sending your traffic anywhere

See how far an upload departs from a device's normal, where it went, and which program sent it.

Try Network Sentinel
5 minute walkthrough

The challenge

A computer sends gigabytes in the middle of the night, and nothing on the network says whether it was a backup or something else.

The scenario

A studio workstation that normally uploads under 150 MB an hour sends 5 GB to a destination it has never contacted.

What goes in

Flow and TLS metadata
Volumes, destinations and handshakes; no payloads.
Endpoint agent
The process behind each connection, when an agent is enrolled.

What you can ask

Illustrative prompts. Results depend on your own data and are not deterministic.

  • “How unusual is this upload for this device?”
  • “Which process made these connections?”
  • “What should I check before calling this a problem?”

How Clearception approaches it

How the work is structured. Each step shows what its output is grounded in.

  1. Compare with the baseline

    Observed

    Put the hour's upload next to the device's typical range and history.

  2. Score the deviation

    Observed

    Add each factor — new destination, new network, unusual hour, volume — into an explained score.

  3. Attribute the process

    Source

    Link the connections to the program the endpoint agent observed.

  4. Interpret locally

    AI-inferred

    A local model separates what was observed from its interpretation, citing evidence.

What you get

The shape of what comes back — not a promised result.

  • Explained finding

    Observed

    Observed facts, baseline deviation, threat intelligence, IDS detections, interpretation and next steps, kept separate.

Why it matters

Context before conclusions
Volume alone never becomes a verdict; the finding says what to verify next.

Network Sentinel

Spot an IoT device reaching for your computers

Notice when a TV, camera or speaker opens a connection to a workstation or NAS it has never talked to before.

3 minute walkthrough

  • Device Discovery
  • Behavioral Baselines
  • Risk Scoring

Lawgorithm

Take in and organise a discovery set

Deduplicate, classify and index discovery material on arrival, with provenance recorded.

4 minute walkthrough

  • Document Intelligence
  • Chain of Custody
  • Evidence Trail

Want to try this with your own work?

Open Network Sentinel and bring your own data. No signup is needed to read these demos.