Skip to content

Assets

The Assets module gives you a unified inventory of every device and identity that SenseOn is aware of across your environment. It is the authoritative source for endpoint health, software inventory, and identity activity within the platform.


What Assets Shows

Assets is split into two primary views, Devices and Identities. Users with Active Response access also see Device Sessions, and Admins with that access also see Device Session History, described below.

Devices

A complete list of endpoints that have the SenseOn Universal Sensor installed or that have been observed by network sensors. Each device record includes:

  • Hostname and IP address (internal and external where detected)
  • Operating system and version
  • Online/offline status and last seen timestamp
  • Sensor version installed on the device
  • Segment membership (device segments control Active Response and other feature access)
  • Installed software tracked by the endpoint agent
  • Recent observations linked to the device

Identities

A list of user identities observed across your environment, derived from authentication events, process activity, and integrations. Each identity record includes:

  • Username and domain
  • Associated devices (endpoints the user has been seen on)
  • Recent activity: last seen timestamp and associated observations
  • Risk score: a composite score based on observation history

Searching and Filtering

Use the search bar at the top of either view to filter by hostname, IP address, username, or any other displayed field. You can combine filters:

Filter Example
Hostname DC01
IP address 192.168.1. (prefix match)
OS type Windows, Linux, macOS
Status Online / Offline
Segment Select from dropdown

Device Detail Panel

Click any device row to open the detail panel on the right-hand side. From here you can:

  • View all observations linked to the device
  • See the full software inventory (name, version, publisher)
  • Check the installed Universal Sensor version and release stream (GA, Beta, Alpha)
  • Open an Active Response session (if you have Active Response access and it is enabled for the device's segment)
  • Navigate to related cases in Investigate

Identity Detail Panel

Click any identity row to open the identity detail panel. From here you can:

  • View all observations linked to the identity
  • See which devices the identity has been active on
  • Review recent authentication and process activity

Endpoint Agent Software Inventory

SenseOn tracks the software installed on each Windows and macOS endpoint via the endpoint agent. The software inventory is updated every time the agent checks in. You can use this data to:

  • Audit software versions across your fleet
  • Identify endpoints with out-of-date or unauthorised software
  • Pivot to Hunt Lab queries pre-filtered by software name or publisher

Integration with Other Modules

Module How Assets relates
Overview The Digital estate summary widget on the Overview page draws from this data
Investigate Case detail panels link to device and identity records here
Active Response Active Response sessions are launched from the device detail panel
Dashboards The Digital Estate Overview dashboard widget summarises device counts and deltas

Active Response Device Sessions

Users with Active Response access can see the Active Response sessions currently open from Assets > Device Sessions. Admins with Active Response access can also see the full audit log of all Active Response sessions from Assets > Device Session History. See the Active Response documentation for details.