SentinelOne is the Official Cybersecurity Partner of the Aston Martin Cognizant Formula One™ Team! Drive with us!
SentinelOne is the Official Cybersecurity Partner of the Aston Martin Cognizant Formula One™ Team!
Experiencing a Breach?
  • 1-855-868-3733
  • Contact
  • Blog
en
  • English
  • 日本語
  • Deutsch
  • Español
  • Français
  • Italiano
  • Dutch
  • 한국어
Get a Demo
  • Platform
    The SentinelOne platform delivers the defenses you need to prevent, detect, and undo—known and unknown—threats.
    Platform OverviewPlatform PackagesSentinelOne vs CrowdStrike
    Platform Products
    • SingularitySingularity CompleteThe Future's Enterprise Security Platform
    • SingularitySingularity ControlSecurity with Suite Features
    • SingularitySingularity CoreCloud-Native NGAV
    • SingularitySingularity Ranger IoTNetwork Visibility & Control
    • SingularitySingularity CloudContainer & Cloud Workload Security
    Platform Verticals
    • Energy
    • Finance
    • Healthcare
    • Higher Education
    • Retail
  • Our Customers
  • Services
    Augment leading technology with trusted expertise, and get set up for success with hands-on support and training.
    Services OverviewGet Help Now
    Global Support & Services
    • Vigilance Respond Pro MDR + DFIRVigilance Respond Pro MDR + DFIR 24x7 MDR with Full-Scale
      Investigation and Response
    • Vigilance Respond MDRVigilance Respond MDR Dedicated SOC Expertise and Analysis
    • WatchTowerWatchTower Intelligence-Driven Threat Hunting
    • ReadinessReadiness Best-Practice Deployment and
      Quarterly Health Checks
    • Support ServicesSupport Services Tiered Support Options
      for Every Organisation
    • Technical Account ManagementTechnical Account Management Customer Success with
      Personalised Service
    • SentinelOne UniversitySentinelOne University Live and On-Demand Training
  • Partners
    See how SentinelOne works with trusted names worldwide to enhance programs, process, and technology.
    Program Overview
    OUR NETWORK
    • SingularitySingularity MarketplaceExtend the Power of S1 Technology
    • TechnologyTechnology Alliances See Integrated, Enterprise-Scale Solutions
    • ChannelChannel PartnersDeliver the Right Solutions. Together
    • Cyber RiskCyber Risk PartnersEnlist Pro Response and Advisory Terms
  • Resources
    • eBooks
    • White Papers
    • Datasheets
    • Case Studies
    • Webinars
    • Videos
    • Reports
    • Events
  • Company
    • Blog
    • Labs
    • Hack Chat
    • Press
    • News
    • FAQ
    • About Us
    • Careers
Back
  • Platform
    The SentinelOne platform delivers the defenses you need to prevent, detect, and undo—known and unknown—threats.
    Platform OverviewPlatform PackagesSentinelOne vs CrowdStrike
    Platform Products
    • SingularitySingularity CompleteThe Future's Enterprise Security Platform
    • SingularitySingularity ControlSecurity with Suite Features
    • SingularitySingularity CoreCloud-Native NGAV
    • SingularitySingularity Ranger IoTNetwork Visibility & Control
    • SingularitySingularity CloudContainer & Cloud Workload Security
    Platform Verticals
    • Energy
    • Finance
    • Healthcare
    • Higher Education
    • Retail
  • Our Customers
  • Services
    Augment leading technology with trusted expertise, and get set up for success with hands-on support and training.
    Services OverviewGet Help Now
    Global Support & Services
    • Vigilance Respond Pro MDR + DFIRVigilance Respond Pro MDR + DFIR 24x7 MDR with Full-Scale
      Investigation and Response
    • Vigilance Respond MDRVigilance Respond MDR Dedicated SOC Expertise and Analysis
    • WatchTowerWatchTower Intelligence-Driven Threat Hunting
    • ReadinessReadiness Best-Practice Deployment and
      Quarterly Health Checks
    • Support ServicesSupport Services Tiered Support Options
      for Every Organisation
    • Technical Account ManagementTechnical Account Management Customer Success with
      Personalised Service
    • SentinelOne UniversitySentinelOne University Live and On-Demand Training
  • Partners
    See how SentinelOne works with trusted names worldwide to enhance programs, process, and technology.
    Program Overview
    OUR NETWORK
    • SingularitySingularity MarketplaceExtend the Power of S1 Technology
    • TechnologyTechnology Alliances See Integrated, Enterprise-Scale Solutions
    • ChannelChannel PartnersDeliver the Right Solutions. Together
    • Cyber RiskCyber Risk PartnersEnlist Pro Response and Advisory Terms
  • Resources
    • eBooks
    • White Papers
    • Datasheets
    • Case Studies
    • Webinars
    • Videos
    • Reports
    • Events
  • Company
    • Blog
    • Labs
    • Hack Chat
    • Press
    • News
    • FAQ
    • About Us
    • Careers
  • 1-855-868-3733
  • Contact
  • Blog
Experiencing a Breach?
Get a Demo
Ranger® IoT: Network Visibility & Control. A cloud
delivered, software-defined network discovery
solution designed to add global network visibility
and control with minimal friction.
Get a Demo

What’s on your network?

Ranger IoT extends Sentinel agent function by reporting what it sees on networks and enables blocking of unauthorized devices.

Network Visibility

Ranger learns the network in a controlled manner with one click. Customizable scanning policies help avoid violating privacy statutes in a frictionless, transparent manner.

Network Control

When unauthorized devices appear on sensitive networks, Ranger protects managed assets from unauthorized communications with one click.

No New Software or Hardware

Sentinels intelligently elect which agents perform the cloud delivered distributed learning. Ranger does not require added hardware or network changes.

Easy Implementation

  • No new software required. Ranger is part of the SentinelOne agent code base.
  • No network changes required. No network SPAN or TAP ports.
  • Build a policy and toggle it on. Admins can specify a different policy for each network and subnet if needed.
  • Policies provide control over scan intervals and what should be scanned and what must never be scanned.
  • Choose between auto-enabled scanning or require explicit permission if more control is needed over the environment.
Get a Demo

Unparalleled Visibility

  • Ranger is network efficient by intelligently electing a few Sentinel agents per subnet to participate in network mapping missions.
  • Elected “Rangers” passively listen for network broadcast data including ARP, DHCP, and other network observances.
  • Admins may customize active scan policies and specify multiple IP protocols for learning including ICMP, SNMP, UDP, TCP, SMB, and more.
  • Rangers correlate all learned information within the backend to fingerprint known and unknown devices.
  • Ranger reveals vital information about IP-enabled devices and produces inventories in seconds across your region or the globe.

Granular Control

  • Ranger device inventories reveal what is connected where and the protocols these devices listen on.
  • Get easy access to known device information via data collected by Rangers.
  • Learn which devices can take a Sentinel agent but do not yet have the agent.
  • Via Deep Visibility ActiveEDR®, see how unknown IoT devices are communicating with managed hosts.
  • Isolate unknown devices by preventing their interaction with SentinelOne devices.

SentinelOne Singularity Ranger FAQ

Can I prevent Ranger from scanning home, coffee shop, and customer networks when my employees are on the road?

Absolutely yes! Ranger policies have several settings to maintain administrative control over what is and is not scanned. A few examples…. You can set a minimum number of Sentinel agents that must be on a subnet before the system event considers it as a possibility. If you set the number at, say 5, small home networks and coffee shops are unlikely to be scanned because you probably will never have 5 work computers on those networks at any one time. Further, administrators can require an explicit “yes, scan this network” from within the SentinelOne Singularity console to further control what is analyzed.

Rogues vs. Ranger. What’s the difference?

Rogues and Ranger are both built into the agent. The capabilities differ based on the purchased license level. Rogues is a free feature included in the Singularity Complete and Singularity Control product bundles and informs administrators which devices on the network still require a Sentinel agent. Ranger is a full featured add-on product with multiple added network visibility and control capabilities that report on all IP-enabled device types.

I am concerned about harming Operational Technology (OT) equipment in factories, power plants, or other industrial settings all of which may run TCP/IP, SCADA, Modbus or other protocols. Or, I simply run sensitive IP-enabled equipment like healthcare modalities (blood pumps, ventilators, and others). I do not want to disrupt the network operation of this critical equipment. Can I use Ranger on these networks?

We understand this concern and have built in per-network policy controls so that you can use every type of scan technique on some networks but then selectively use only certain network learning methods on others. For example, you can turn off active scan probes altogether and just rely on passive network listening on an OT network. Or, you might use passive listening plus ICMP and SNMP active scanning probes but NOT use TCP connect scans because you are worried about destabilizing certain types of control units that use IP and the SCADA protocol. These are just examples. The point is, administrators can mix and match a wide variety of scanning and passive listening techniques on a per network basis to discover what is connected where and how it is communicating.

Does Ranger support the gathering of asset inventories?

Yes! Ranger will build out an asset inventory for every scanned network and let you export the data.

How does Ranger block unknown devices?

When an administrator chooses to block a device, that device is effectively isolated from all SentinelOne managed Windows, Mac, and Linux hosts. This is accomplished using local network control firewall rules as enforced by the Sentinel agent on those devices. SentinelOne continues to build out the Ranger instrumentation to provide additional network access controls in the future.

How will I know if a new, unknown device joins a network I consider to be sensitive?

Ranger combines capabilities with Deep Visibility ActiveEDR and our Storyline Active Response Engine (STAR) to alert you when a new device without a Sentinel agent has connected to the networks of your choice. You may then take the response of your choosing including block communications from the unknown device.

Related Resources

DATA SHEET

Singularity EPP + EDR

Learn More >
DATA SHEET

Vigilance MDR

Learn More >
DATA SHEET

Endpoint Protection Bundles

Learn More >
DATA SHEET

SentinelOne Ranger IoT

Learn More >

The World’s Leading and Largest Enterprises Trust SentinelOne

Including 3 of the Fortune 10 and hundreds of the global 2000

Market Recognition

See what others say about SentinelOne

MITRE ATT&CK

Fewest misses, most correlations, best data enrichment coverage. SentinelOne proves its ability to connect the dots more effectively than the competition.

Disruptor50

SentinelOne is the only cybersecurity company among 50 private businesses at the epicenter of a changing world, all poised as the next generation of billion-dollar organizations.

Forbes AI 50

SentinelOne is ranked #14 among America’s most promising AI companies using techniques including machine learning as a core part of their business model.

Deloitte Fast 500

SentinelOne is ranked the 7th fastest growing company in North America, the fastest-growing company in the Bay Area, and the only cybersecurity company in the top 10.

Explore the Full Power of Singularity

Simplifying container and VM security, no matter their location, for maximum agility, security, and compliance.

Learn More >

Endpoint security bedrock for organizations replacing legacy AV or NGAV with an effective EPP that is easy to deploy and manage.

Learn More >

Made for organizations seeking the best-of-breed cybersecurity with additional security suite features.

Learn More >

Made for organizations seeking enterprise-grade prevention, detection, response and hunting across endpoint, cloud, and IoT.

Learn More >

Purpose Built to Prevent Tomorrow’s Threats.

Today.

Your most sensitive data lives on the endpoint and in the cloud. Protect what matters most from cyberattacks. Fortify every edge of the network with realtime autonomous protection.
Get a Demo
Company
  • Our Customers
  • Why SentinelOne
  • Platform
  • About
  • Partners
  • Support
  • Careers
  • Legal & Compliance
  • Security & Compliance
  • Contact Us
Resources
  • Blog
  • Labs
  • Hack Chat
  • Press
  • News
  • FAQ
  • Resources
Global Headquarters

444 Castro Street
Suite 400
Mountain View, CA 94041

+1-855-868-3733

sales@sentinelone.com

Sign Up For Our Newsletter
Thank you! You will now receive our weekly newsletter with all recent blog posts. See you soon!
English
  • English
  • 日本語
  • Deutsch
  • Español
  • Français
  • Italiano
  • Dutch
  • 한국어
Privacy Policy Terms of Service
©2021 SentinelOne, All Rights Reserved.
SentinelOne and its service providers use browser cookies or similar technologies as specified in the SentinelOne Privacy Policy. You can consent to the use of such technologies and browse the SentinelOne website by clicking the Accept button.
Accept Reject