Tier: Stealth Device Detection is included in the Protect tier. Customers on Connect or Discover do not see this surface.Beta feature. Stealth Devices is in active development. Interpret results with care — the identification logic continues to improve and some classifications may shift between releases. The toggle is off by default on new tenants.
What it is
Stealth Devices surfaces full-kernel-OS devices — Windows, macOS, Linux desktops, laptops, servers, and VMs — that are visible to network-scanning / discovery integrations (Lansweeper, Qualys, PDQ Inventory, etc.) but not visible to any of your management platforms — EDR, MDM, identity provider, RMM. In other words, real computers on your network that nothing is managing. Scope is intentionally narrow. Stealth Devices does not cover:- Printers, projectors, smart-display kit
- IoT — sensors, building management, lab equipment
- Network gear — switches, routers, access points
- Mobile devices (phones, tablets — these belong to the separate mobile inventory)
- Corporate laptops that slipped out of EDR or MDM enrolment
- Servers (physical or virtual) not in any management tool
- Workstations missing from inventory
- VMs spun up outside change control
- Decommissioned-but-still-pinging servers or laptops
- Shadow IT — full-OS workloads stood up outside change control
How to enable
1
Open Settings → Misc
Settings → Misc from the left rail.
2
Toggle 'Enable Stealth Devices'
The product copy reads: “Try ThreatAware’s new stealth detection capability, designed to identify devices outside of existing management platforms. This feature is in development - interpret results with care.”
3
Open Network Inventory
Stealth-identified devices surface in Network Inventory —
/network-device-inventory.Where it surfaces
The Network Inventory page is the canonical place to investigate individual stealth devices. From there you can:
- Filter by OS, by detecting integration, or by IP range
- Toggle Grouped-by-IP view to find IP ranges full of unmanaged kit
- Cross-reference any row against the Devices grid to confirm it’s genuinely unmanaged
How to use the findings
Each stealth device is one of:
A common operational pattern: create a Snapshot Action over a frozen list of stealth devices for a campaign to bring them into management, with a deadline and explicit resolution criteria.
Caveats
Beta — interpret with care
Beta — interpret with care
Identification logic is evolving. A device classified as Stealth in one release may classify differently in the next as the matching engine improves. Treat individual classifications as advisory, not authoritative.
You need network-scanning integrations connected
You need network-scanning integrations connected
Stealth Devices is computed from the gap between network-scanner discovery and management-tool inventory. If you have no network scanners connected (Lansweeper, Qualys, PDQ Inventory, similar), there’s no signal to compute against.
Some 'stealth' is intentional
Some 'stealth' is intentional
Not every unmanaged corporate-class device is an immediate finding. Standalone lab machines or air-gapped VMs may be unmanaged by design. The point isn’t to drive the count to zero — it’s to make sure the population is known and accounted for.
Cross-check via X-Ray
Cross-check via X-Ray
For any device that surfaces as Stealth, X-Ray shows which sources do see it. If management tools do have it but matching failed, that’s a matching issue, not a true stealth case.
Cross-references
Network Inventory
The operational home
Settings → Misc
Enable Stealth Devices toggle
Device Explorer
Stealth count in the integration sync row
Snapshot Actions
Drive a stealth-device clean-up campaign
X-Ray
Confirm a device is genuinely unmanaged
What's New
Capability updates