Network Sentinel demo
Find out what an unrecognised device is doing on your network
Identify a device nobody recognises, see everything it has contacted, and decide whether it belongs.
The challenge
A device appears on the Wi-Fi that nobody in the household or office can name, and the router's client list shows only a MAC address.
The scenario
An unclassified device joins at night, probes other addresses on the LAN, and opens a file-sharing session to the NAS.
What goes in
- Sensor telemetry
- DHCP, mDNS and connection logs from Zeek; Suricata alerts.
What you can ask
Illustrative prompts. Results depend on your own data and are not deterministic.
- “What is this new device and when did it first appear?”
- “Which other devices did it try to reach?”
- “Should I block it or move it to the guest network?”
How Clearception approaches it
How the work is structured. Each step shows what its output is grounded in.
Identify the device
ObservedCombine hardware vendor, DHCP details and services into an identity with a confidence.
Group its activity
ObservedCollect the new-device, scanning and internal-connection findings into one investigation.
Show the evidence
SourceOpen the exact connections and IDS events behind each finding.
Decide
Human-verifiedClassify the device, or block it through a confirmed firewall action.
What you get
The shape of what comes back — not a promised result.
Investigation timeline
ObservedArrival, LAN probing and the NAS connection in order, each linked to its telemetry.
Why it matters
- A name for every device
- Unknown devices are surfaced with what is known about them, not just an address.
Related demos
Network Sentinel
Investigate an unusual upload without sending your traffic anywhere
See how far an upload departs from a device's normal, where it went, and which program sent it.
5 minute walkthrough
- Behavioral Baselines
- Risk Scoring
- Privacy-First AI Routing
Network Sentinel
Spot an IoT device reaching for your computers
Notice when a TV, camera or speaker opens a connection to a workstation or NAS it has never talked to before.
3 minute walkthrough
- Device Discovery
- Behavioral Baselines
- Risk Scoring
Lawgorithm
Take in and organise a discovery set
Deduplicate, classify and index discovery material on arrival, with provenance recorded.
4 minute walkthrough
- Document Intelligence
- Chain of Custody
- Evidence Trail
Want to try this with your own work?
Open Network Sentinel and bring your own data. No signup is needed to read these demos.