Skip to main content
Tier: Stealth Device Detection is included in the Protect tier. Customers on Connect or Discover do not see this surface.Beta feature. Stealth Devices is in active development. Interpret results with care — the identification logic continues to improve and some classifications may shift between releases. The toggle is off by default on new tenants.

What it is

Stealth Devices surfaces full-kernel-OS devices — Windows, macOS, Linux desktops, laptops, servers, and VMs — that are visible to network-scanning / discovery integrations (Lansweeper, Qualys, PDQ Inventory, etc.) but not visible to any of your management platforms — EDR, MDM, identity provider, RMM. In other words, real computers on your network that nothing is managing. Scope is intentionally narrow. Stealth Devices does not cover:
  • Printers, projectors, smart-display kit
  • IoT — sensors, building management, lab equipment
  • Network gear — switches, routers, access points
  • Mobile devices (phones, tablets — these belong to the separate mobile inventory)
Those device classes are out of scope for ThreatAware’s kernel-level matching model. The point of Stealth Devices is the manageable-but-unmanaged gap — boxes that should be in EDR / MDM / RMM but aren’t. Typical stealth devices in scope:
  • Corporate laptops that slipped out of EDR or MDM enrolment
  • Servers (physical or virtual) not in any management tool
  • Workstations missing from inventory
  • VMs spun up outside change control
  • Decommissioned-but-still-pinging servers or laptops
  • Shadow IT — full-OS workloads stood up outside change control
These are the boxes that fall through the cracks of an EDR-centric inventory: they’re real, they’re on the network, and no security control owns them.

How to enable

1

Open Settings → Misc

Settings → Misc from the left rail.
2

Toggle 'Enable Stealth Devices'

The product copy reads: “Try ThreatAware’s new stealth detection capability, designed to identify devices outside of existing management platforms. This feature is in development - interpret results with care.”
3

Open Network Inventory

Stealth-identified devices surface in Network Inventory/network-device-inventory.
The toggle is tenant-wide. You’ll need a role with permission to edit Misc settings.

Where it surfaces

The Network Inventory page is the canonical place to investigate individual stealth devices. From there you can:
  • Filter by OS, by detecting integration, or by IP range
  • Toggle Grouped-by-IP view to find IP ranges full of unmanaged kit
  • Cross-reference any row against the Devices grid to confirm it’s genuinely unmanaged

How to use the findings

Each stealth device is one of: A common operational pattern: create a Snapshot Action over a frozen list of stealth devices for a campaign to bring them into management, with a deadline and explicit resolution criteria.

Caveats

Identification logic is evolving. A device classified as Stealth in one release may classify differently in the next as the matching engine improves. Treat individual classifications as advisory, not authoritative.
Stealth Devices is computed from the gap between network-scanner discovery and management-tool inventory. If you have no network scanners connected (Lansweeper, Qualys, PDQ Inventory, similar), there’s no signal to compute against.
Not every unmanaged corporate-class device is an immediate finding. Standalone lab machines or air-gapped VMs may be unmanaged by design. The point isn’t to drive the count to zero — it’s to make sure the population is known and accounted for.
For any device that surfaces as Stealth, X-Ray shows which sources do see it. If management tools do have it but matching failed, that’s a matching issue, not a true stealth case.

Cross-references

Network Inventory

The operational home

Settings → Misc

Enable Stealth Devices toggle

Device Explorer

Stealth count in the integration sync row

Snapshot Actions

Drive a stealth-device clean-up campaign

X-Ray

Confirm a device is genuinely unmanaged

What's New

Capability updates