Open a router's device list for the first time and it looks like noise: a column of MAC addresses, some vague hostnames, a few blank entries. Once you know what each field means, that same list becomes the fastest way to answer "is someone on my network who shouldn't be" or "what's actually using my bandwidth."
The hostname is a hint, not a fact
Most devices announce a hostname when they join a network, something like "Samsung-Galaxy-S23" or "DESKTOP-4F92K1." Treat this as a hint rather than a guarantee. Some devices report generic or blank hostnames, and a determined user can manually rename their device to anything. It's a fast first pass, not proof.
The MAC address is the reliable identifier
Every network interface has a MAC address, a unique hardware identifier separate from whatever hostname a device chooses to report. It normally doesn't change even if a device is renamed or reconnects, which is why it's the field worth trusting when a hostname looks suspicious.
What actually counts as suspicious
A single unfamiliar device isn't automatically a problem; smart bulbs, TVs, and guest phones all show up as unfamiliar entries the first time. What's worth investigating is a device with a blank or randomized hostname, connected during hours nobody in your house is normally active, using unusually high data. Any one of those alone is common. All three together is worth a closer look.
A five-minute audit routine
Once a week, scan your connected devices and give any unfamiliar-but-legitimate device (a new phone, a smart plug) a real name. That turns your device list from a wall of anonymous MAC addresses into something you can scan in five seconds next time, since anything not already labeled immediately stands out as new.