Skip to main content
cloud_server_funnel_hero.jpg

Singularity™ Network Discovery

Singularity Network Discovery is a cloud delivered, software-defined network discovery solution designed to add global visibility and control with minimal friction.

What’s on Your Network?

Network Discovery Extends Sentinel Agent Function by Reporting What It Sees on Networks and Enables Blocking of Unauthorized Devices.

Network Visibility

Network Visibility

Network Discovery learns the network in a controlled manner with one click. Customizable scanning policies help avoid violating privacy statutes in a frictionless, transparent manner.
Network Control

Network Control

When unauthorized devices appear on sensitive networks, Network Discovery protects managed assets from unauthorized communications with one click.
No New Software or Hardware

No New Software or Hardware

Sentinels intelligently elect which agents perform the cloud delivered distributed learning. Network Discovery does not require added hardware or network changes.
Singularity_Network_Discovery-Implementation.png

Easy Implementation

 

  • No new software required. Network Discovery is part of the SentinelOne agent code base.
  • No network changes required. No network SPAN or TAP ports.
  • Build a policy and toggle it on. Admins can specify a different policy for each network and subnet if needed.
  • Policies provide control over scan intervals and what should be scanned and what must never be scanned.
  • Choose between auto-enabled scanning or require explicit permission if more control is needed over the environment.
Singularity_Network_Discovery-Visability.png

Unparalleled Visibility

 

  • Network Discovery is network efficient by intelligently electing a few Sentinel agents per subnet to participate in network mapping missions.
  • Elected agents passively listen for network broadcast data including ARP, DHCP, and other network observances.
  • Admins may customize active scan policies and specify multiple IP protocols for learning including ICMP, SNMP, UDP, TCP, SMB, and more.
  • Network Discovery correlate all learned information within the backend to fingerprint known and unknown devices.
  • Network Discovery reveals vital information about IP-enabled devices and produces inventories in seconds across your region or the globe.
Singularity_Network_Discovery-Control.png

Granular Control

 

  • Network Discovery device inventories reveal what is connected where and the protocols these devices listen on.
  • Get easy access to known device information via data collected by Network Discovery.
  • Find and close SentinelOne agent deployment gaps with peer-to-peer deployment.
  • Monitor how unknown devices communicate with managed hosts.
  • Isolate suspicious devices from managed devices with a click.

SentinelOne Singularity Network Discovery FAQ

Absolutely yes! Network Discovery policies have several settings to maintain administrative control over what is and is not scanned. A few examples…. You can set a minimum number of Sentinel agents that must be on a subnet before the system event considers it as a possibility. If you set the number at, say 5, small home networks and coffee shops are unlikely to be scanned because you probably will never have 5 managed devices on those networks at any one time. Further, administrators can require an explicit “yes, scan this network” from within the SentinelOne Singularity console to further control what is analyzed.

Unmanaged Assets and Network Discovery are both built into the agent. The capabilities differ based on the purchased license level. Unmanaged Assets is a free feature included in the Singularity Complete and Singularity Control products and informs administrators which devices on the network still require a SentinelOne agent. Network Discovery is a full-featured add-on product with multiple added network visibility, deployment and control capabilities that report on all IP-enabled device types.

SentinelOne understands this concern and has built in per-network policy controls so that you can use every type of scan technique on some networks but then selectively use only certain network learning methods on others. For example, you can turn off active scan probes altogether and just rely on passive network listening on an OT network. Or, you might use passive listening plus ICMP and SNMP active scanning probes but NOT use TCP connect scans because you are worried about destabilizing certain types of control units that use IP and the SCADA protocol. These are just examples. The point is, administrators can mix and match a wide variety of scanning and passive listening techniques on a per network basis to discover what is connected where and how it is communicating.

Yes! Singularity Network Discovery, formerly known as Singularity Ranger, will build out an asset inventory for every scanned network and let you visualize or export the data.

When an administrator chooses to block a device, that device is effectively isolated from all SentinelOne-managed Windows, Mac, and Linux hosts. This is accomplished using local network control firewall rules as enforced by the SentinelOne agent on those devices.

Singularity Network Discovery, formerly known as Singularity Ranger, combines capabilities with Singularity Data Lake and Storyline Active Response Engine (STAR) to alert you when a new device without a SentinelOne agent has connected to the networks of your choice. You may then take the response of your choosing including block communications from the unknown device.

Ready to Take a Look?

Experience cybersecurity that prevents threats at faster speed, greater scale, and higher accuracy.

The World’s Leading and Largest Enterprises Trust SentinelOne

Including four of the Fortune 10 and hundreds of the Global 2000.

Warner Bros
American Express
Motorola Solutions
Lowe's
Cisco
Abott
Lockheed Martin
Aramco
Applied Materials
AT&T
Apple
ACE Hardware
Norfolk Southern
S&P Global
Southern Company
Warner Bros
American Express
Motorola Solutions
Lowe's
Cisco
Abott
Lockheed Martin
Aramco
Applied Materials
AT&T
Apple
ACE Hardware
Norfolk Southern
S&P Global
Southern Company

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Prefooter - Demo Background

Connect with an Expert

Get a Demo
Get a Demo
Prefooter - Tour Background

Take a SentinelOne Product Tour

Take a Tour
Take a Tour