Know the device behind the address.
An IP address tells you where something is, not what it is. WireTrace builds the inventory from the evidence devices put on the wire: their own identity records, the names they announce, the certificates they present and the way they behave.
Identity that survives IP changes.
WireTrace keeps one durable identity per physical device, even when its IP address changes or it is seen on several interfaces or by several sensors. Address changes are tracked as transitions, not conflicts, and stale bindings expire safely, so history, risk and alerts stay attached to the device rather than to an address.
- First seen, last seen and still valid, for every piece of identity evidence
- Where the evidence proves it, several addresses or interfaces are recognised as one device
- When two devices present the same supposedly unique value, WireTrace refuses to merge them blindly and records the contradiction
Vendor, model, firmware and role, where the evidence supports it.
WireTrace derives vendor, model, firmware and role where supported by available evidence. Many industrial controllers, IoT and network devices state their model, firmware or serial number on the network, and WireTrace records each value with its source.
Credentialed collection and read-only switch polling add these details for IT and network equipment. Devices that state nothing keep an honest, lower-confidence identity rather than a guessed one.
Devices classified, with their reasons.
Domain, type and role
IT, OT, IoT, medical and network, by device type and role, using 600+ built-in classification rules and a hierarchical device taxonomy. Unclassified devices stay unknown, never guessed.
Purdue level
Each device is placed on a Purdue level with a stated confidence and a one-line reason.
Your own rules
Administrators write their own classification rules in a no-code editor, with a preview before anything is applied.
Context that makes the inventory useful.
Communications
For each device: who it talks to, over which protocols and ports, its top peers and its connection history.
Applications
Recognises 150+ cloud, SaaS, vendor-cloud and infrastructure applications that devices use, with confidence.
Visibility assurance
For each device, WireTrace states which kinds of evidence are present, missing or stale. An empty result is never presented as a clean one.
Evidence, not a label.
Every identity value shows where it came from and how fresh it is. Every identity carries an evidence-weighted confidence, and the full explanation is available through the API. Before any automated action, WireTrace checks the target is identified well enough, and recently enough, to act on safely.
Find out what is really on your network.
A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.