Activities
Surface suspicious and noteworthy behavior, with the evidence behind every detection.
View exampleCatch hackers. Red handed.
Analyze a PCAP or monitor live traffic in Red Hand Analytics, where activities, endpoints, DNS, flows, and connections come together in one investigation.
Red Hand Analytics
Start with a finding, then move through the endpoints, requests, traffic, and connections that explain it without losing context.
Surface suspicious and noteworthy behavior, with the evidence behind every detection.
View exampleSee who communicated, then add reputation, ownership, and threat-intelligence context.
View exampleReview resolvers, noisy clients, unresolved requests, conflicting answers, and unusual DNS data exchange.
View exampleFollow upload, download, and internal traffic to identify unusually large transfers.
View exampleFind repeated and long-running communications that isolated events can hide.
View exampleFilter, sort, and inspect the individual connections behind each observation.
View exampleTwo ways into Red Hand Analytics
PCAP Analyzer and Red Hand Collector feed the same investigation experience. Choose based on how you have the traffic and how long you need to observe it.
| Choose your inputWhat changes | CollectorContinuous visibility | PCAP AnalyzerAnalyze a capture |
|---|---|---|
| Analysis experienceActivities, endpoints, DNS, flows, and connections remain connected. | Red Hand Analytics | Red Hand Analytics |
| Observation windowHow much time the analysis can cover. | Continuous | Snapshot in time |
| Process visibilityIdentify the application responsible for a connection. | Yes | No |
| DeploymentWhat is needed before analysis begins. | Lightweight endpoint installation | No endpoint installation |
Product changelog
Meaningful new capabilities and improvements, with a direct path to try each one.
Screen-by-screen guidance now explains the analysis workspace, its core concepts, and the evidence available in every report.
Read updateA rebuilt report history brings PCAP and Collector reports together with clearer status, expiration visibility, sorting, and server-side paging.
Read updateThe PCAP Analyzer now makes uploading, creating a useful capture, and understanding the resulting investigation easier from the first visit.
Read updateFrom the community
Practical network analysis notes, field-tested ideas, and discussions from r/redhand.
Contact
Have a question about a capture, Red Hand Collector, or Red Hand Analytics? Send us a note.
You’ll hear directly from the Red Hand team.