Network Sentinel demo

Find out what an unrecognised device is doing on your network

Identify a device nobody recognises, see everything it has contacted, and decide whether it belongs.

Try Network Sentinel
4 minute walkthrough

The challenge

A device appears on the Wi-Fi that nobody in the household or office can name, and the router's client list shows only a MAC address.

The scenario

An unclassified device joins at night, probes other addresses on the LAN, and opens a file-sharing session to the NAS.

What goes in

Sensor telemetry
DHCP, mDNS and connection logs from Zeek; Suricata alerts.

What you can ask

Illustrative prompts. Results depend on your own data and are not deterministic.

  • “What is this new device and when did it first appear?”
  • “Which other devices did it try to reach?”
  • “Should I block it or move it to the guest network?”

How Clearception approaches it

How the work is structured. Each step shows what its output is grounded in.

  1. Identify the device

    Observed

    Combine hardware vendor, DHCP details and services into an identity with a confidence.

  2. Group its activity

    Observed

    Collect the new-device, scanning and internal-connection findings into one investigation.

  3. Show the evidence

    Source

    Open the exact connections and IDS events behind each finding.

  4. Decide

    Human-verified

    Classify the device, or block it through a confirmed firewall action.

What you get

The shape of what comes back — not a promised result.

  • Investigation timeline

    Observed

    Arrival, LAN probing and the NAS connection in order, each linked to its telemetry.

Why it matters

A name for every device
Unknown devices are surfaced with what is known about them, not just an address.

Network Sentinel

Spot an IoT device reaching for your computers

Notice when a TV, camera or speaker opens a connection to a workstation or NAS it has never talked to before.

3 minute walkthrough

  • Device Discovery
  • Behavioral Baselines
  • Risk Scoring

Lawgorithm

Take in and organise a discovery set

Deduplicate, classify and index discovery material on arrival, with provenance recorded.

4 minute walkthrough

  • Document Intelligence
  • Chain of Custody
  • Evidence Trail

Want to try this with your own work?

Open Network Sentinel and bring your own data. No signup is needed to read these demos.