secnostic sensor itself looks at your endpoints and networks, finds assets and how they connect, and reports what is actually there.

Instead of trusting your lists, secnostic sensor checks the real IT and OT environment and fills the gaps nobody maintains by hand.

sensor modules

Overview

Dashboard

Sensor health at a glance, with counts of assets, connections and findings, plus upload status.

Inventory

Hosts

Every discovered asset with its IP, vendor and detected protocols, seen actively or passively.

Paths

Connections

Every path of communication with endpoints, protocol, volume and service.

Findings

Findings

Detected devices and security facts such as a Siemens S7 identity, with category and reported version.

Sources

Collectors

Specialized collectors grouped by how gently they read: passive network, local endpoints, a scoped Active Directory read, opt-in OT, and cloud.

Safety

Safe by default

Read-only, opt-in and plan-only for OT, with a fail-closed scheduler and a per-protocol allow-list.

What is really running, not what the list says

Spreadsheets go stale the moment someone plugs in or rewires something. secnostic sensor checks for itself: on Windows and Linux, in Active Directory, on the network, read-only and gentle in OT, plus Microsoft 365, Intune, and Sophos Central. Every finding arrives with its source and a confidence level and flows straight into the secnostic inventory. So you see what is really there, what changed since the last run, and where a blind spot still remains.

From many observations to one reliable inventory

Specialized collectors gather evidence from IT, OT, identity, and cloud, grouped by how gently each is read. The sensor normalizes every finding with source and confidence into one stream and hands it to the secnostic inventory.

Protocols, practice, and a safe scope

Which protocols the sensor reads, how that looks in practice, and the explicitly approved scope active discovery runs in.

OT & industry
Modbus
Siemens S7
PROFINET
EtherNet/IP
OPC UA
BACnet
DNP3
EtherCAT
Network
TLS
HTTP
DNS
SMB
RDP
SSH
NetFlow
IPFIX
Identity & cloud
Active Directory
Microsoft 365
Intune
Sophos Central
SNMP

A look inside the sensor

Dashboard, hosts, graph, connections, and findings stay separate by task and share one observation stream.

FAQ

Key questions before a sensor rollout.

Does the sensor write to the devices it discovers?

No. The sensor is a pure collection probe. Passive network visibility sends no packet, and every active or OT probe only reads, is opt-in, and runs solely against an explicit allow-list. It even reports passively observed writes from other systems as a security fact.

Is it safe to run in OT environments?

Gentle probing is the sensor's job. The production baseline is plan-only, the target planner is fail-closed, concurrency can be limited to a single host, and every protocol family is approved individually. The shipped lab profile must be replaced with the safe baseline before touching a real network.

Where does the data go if the inventory is unreachable?

Each run is spooled locally first, then uploaded over HTTPS to the inventory API. If the API is unreachable, data stays local and the upload retries with growing back-off. Nothing leaves the host until upload is deliberately configured.

How sensitive is the data, and how is it protected?

Observations can reveal hosts, users, services, certificates, and communication paths, so they are treated as sensitive. Normalization is data-minimizing: usernames, principals, and secrets are hashed rather than stored, raw DNS and OT payloads are dropped, and raw evidence is off by default. The local diagnostics view is read-only and reachable only over loopback.

Start with a sensor scope that improves the data baseline

Together we clarify which sources can be used with low risk and which observations matter first for inventory, operations, and security.

Discuss sensor rollout