Platform · Asset Intelligence

Know the device behind the address.

An IP address tells you where something is, not what it is. WireTrace builds the inventory from the evidence devices put on the wire: their own identity records, the names they announce, the certificates they present and the way they behave.

EVIDENCE OBSERVEDDevice-stated identity recordDHCP options · hostnameSNMP system descriptionTLS certificate · SSH host keyLLDP / CDP neighbourProtocol behaviourENTITYControllervendor · model · firmwarerole · Purdue levelconfidence · sourcefirst / last seenDRIVESRiskexposure · CVEsDetectionbaselinesPolicyintent
Durable identity

Identity that survives IP changes.

WireTrace keeps one durable identity per physical device, even when its IP address changes or it is seen on several interfaces or by several sensors. Address changes are tracked as transitions, not conflicts, and stale bindings expire safely, so history, risk and alerts stay attached to the device rather than to an address.

  • First seen, last seen and still valid, for every piece of identity evidence
  • Where the evidence proves it, several addresses or interfaces are recognised as one device
  • When two devices present the same supposedly unique value, WireTrace refuses to merge them blindly and records the contradiction
ADDRESS OVER TIMEMon10.20.4.17DHCP leaseWed10.20.4.88re-addressedFri10.20.9.12moved VLANONE DURABLE IDENTITYPackaging-line controlleranchored on device-stated hardware identityaddress changes tracked as transitionshistory, risk and alerts stay attachedstale bindings expire safelyILLUSTRATIVE ADDRESSES
What it derives

Vendor, model, firmware and role, where the evidence supports it.

WireTrace derives vendor, model, firmware and role where supported by available evidence. Many industrial controllers, IoT and network devices state their model, firmware or serial number on the network, and WireTrace records each value with its source.

Credentialed collection and read-only switch polling add these details for IT and network equipment. Devices that state nothing keep an honest, lower-confidence identity rather than a guessed one.

VendorModelFirmwareSerialOperating systemRolePurdue level
Classification

Devices classified, with their reasons.

Domain, type and role

IT, OT, IoT, medical and network, by device type and role, using 600+ built-in classification rules and a hierarchical device taxonomy. Unclassified devices stay unknown, never guessed.

Purdue level

Each device is placed on a Purdue level with a stated confidence and a one-line reason.

Your own rules

Administrators write their own classification rules in a no-code editor, with a preview before anything is applied.

Beyond the device

Context that makes the inventory useful.

Communications

For each device: who it talks to, over which protocols and ports, its top peers and its connection history.

Applications

Recognises 150+ cloud, SaaS, vendor-cloud and infrastructure applications that devices use, with confidence.

Visibility assurance

For each device, WireTrace states which kinds of evidence are present, missing or stale. An empty result is never presented as a clean one.

Explainable

Evidence, not a label.

Every identity value shows where it came from and how fresh it is. Every identity carries an evidence-weighted confidence, and the full explanation is available through the API. Before any automated action, WireTrace checks the target is identified well enough, and recently enough, to act on safely.

ITservers · endpoints · identityOTcontrollers · HMIs · engineeringIoTcameras · building systemsIoMTclinical devices · imagingONE INVENTORY · ONE RISK MODEL · ONE POLICY LAYER

Find out what is really on your network.

A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.