secnostic® sensor inspects endpoints and networks directly, finds assets and their connections, and reports what is actually there.

Instead of trusting your lists, secnostic® sensor checks the real IT and OT environment and fills the gaps nobody maintains by hand.

sensor modules

Overview

Dashboard

Sensor health at a glance, with counts of assets, connections and findings, plus upload status.

Inventory

Hosts

Every discovered asset with its IP, vendor and detected protocols, seen actively or passively.

Paths

Connections

Every path of communication with endpoints, protocol, volume and service.

Findings

Findings

Detected devices and security facts such as a Siemens S7 identity, with category and reported version.

Sources

Collectors

Specialized collectors grouped by how gently they read: passive network, local endpoints, a scoped Active Directory read, opt-in OT, and cloud.

Safety

Safe by default

Read-only, opt-in and plan-only for OT, with a fail-closed scheduler and a per-protocol allow-list.

What is really running, not what the list says

Spreadsheets go stale the moment someone plugs in or rewires something. secnostic® sensor checks for itself: on Windows and Linux, in Active Directory, on the network, read-only and gentle in OT, plus Microsoft 365, Intune, and Sophos Central. Every finding arrives with its source and a confidence level and is handed to secnostic® inventory directly or through a Fleet Manager. So you see what is really there, what changed since the last run, and where a blind spot still remains.

From many observations to one reliable inventory

Specialized collectors gather evidence from IT, OT, identity, and cloud, grouped by how gently each is read. The sensor normalizes every finding with source and confidence into one stream and hands it to secnostic® inventory directly or, in scaled environments, through a Fleet Manager.

Protocols, practice, and a safe scope

Which protocols the sensor reads, how that looks in practice, and the explicitly approved scope active discovery runs in.

OT & industry
Modbus
Siemens S7
PROFINET
EtherNet/IP
OPC UA
BACnet
DNP3
EtherCAT
Network
TLS
HTTP
DNS
SMB
RDP
SSH
NetFlow
IPFIX
Identity & cloud
Active Directory
Microsoft 365
Intune
Sophos Central
SNMP

A look inside the sensor

Dashboard, hosts, graph, connections, and findings stay separate by task and share one observation stream.

Related Solutions

The same product capabilities matter differently depending on the operating context. These solution pages show that context.

FAQ

Key questions before a sensor rollout.

Does the sensor write to the devices it discovers?

No. The sensor is a pure collection probe. Passive network visibility sends no packet, and every active or OT probe only reads, is opt-in, and runs solely against an explicit allow-list. It even reports passively observed writes from other systems as a security fact.

Is it safe to run in OT environments?

Gentle probing is the sensor's job. The production baseline is plan-only, the target planner is fail-closed, concurrency can be limited to a single host, and every protocol family is approved individually. The shipped lab profile must be replaced with the safe baseline before touching a real network.

Where does the data go if the inventory is unreachable?

Each run is spooled locally first. A single sensor can deliberately send directly to the Inventory API over HTTPS; in distributed or segmented environments, the optional Fleet Manager merges the changes and initiates an mTLS sync. If inventory is unreachable, data stays local and the transfer retries with growing back-off. Nothing leaves the host until synchronization is configured.

How sensitive is the data, and how is it protected?

Observations can reveal hosts, users, services, certificates, and communication paths, so they are treated as sensitive. Normalization is data-minimizing: usernames, principals, and secrets are hashed rather than stored, raw DNS and OT payloads are dropped, and raw evidence is off by default. The local diagnostics view is read-only and reachable only over loopback.

Start with a sensor scope that improves the data baseline

Together we clarify which sources can be used with low risk and which observations matter first for inventory, operations, and security.

Discuss sensor rollout