Network Sentinel demo
Investigate an unusual upload without sending your traffic anywhere
See how far an upload departs from a device's normal, where it went, and which program sent it.
The challenge
A computer sends gigabytes in the middle of the night, and nothing on the network says whether it was a backup or something else.
The scenario
A studio workstation that normally uploads under 150 MB an hour sends 5 GB to a destination it has never contacted.
What goes in
- Flow and TLS metadata
- Volumes, destinations and handshakes; no payloads.
- Endpoint agent
- The process behind each connection, when an agent is enrolled.
What you can ask
Illustrative prompts. Results depend on your own data and are not deterministic.
- “How unusual is this upload for this device?”
- “Which process made these connections?”
- “What should I check before calling this a problem?”
How Clearception approaches it
How the work is structured. Each step shows what its output is grounded in.
Compare with the baseline
ObservedPut the hour's upload next to the device's typical range and history.
Score the deviation
ObservedAdd each factor — new destination, new network, unusual hour, volume — into an explained score.
Attribute the process
SourceLink the connections to the program the endpoint agent observed.
Interpret locally
AI-inferredA local model separates what was observed from its interpretation, citing evidence.
What you get
The shape of what comes back — not a promised result.
Explained finding
ObservedObserved facts, baseline deviation, threat intelligence, IDS detections, interpretation and next steps, kept separate.
Why it matters
- Context before conclusions
- Volume alone never becomes a verdict; the finding says what to verify next.
Related demos
Network Sentinel
Find out what an unrecognised device is doing on your network
Identify a device nobody recognises, see everything it has contacted, and decide whether it belongs.
4 minute walkthrough
- Device Discovery
- Behavioral Baselines
- Evidence Trail
Network Sentinel
Spot an IoT device reaching for your computers
Notice when a TV, camera or speaker opens a connection to a workstation or NAS it has never talked to before.
3 minute walkthrough
- Device Discovery
- Behavioral Baselines
- Risk Scoring
Lawgorithm
Take in and organise a discovery set
Deduplicate, classify and index discovery material on arrival, with provenance recorded.
4 minute walkthrough
- Document Intelligence
- Chain of Custody
- Evidence Trail
Want to try this with your own work?
Open Network Sentinel and bring your own data. No signup is needed to read these demos.