Catch Hackers. Red Handed.

Red Hand automatically analyzes live or captured raw network traffic to detect meaningful behavior, assess suspicious activity, and present the evidence in a report or as an alert.

Red Hand network analysis dashboard showing findings, endpoints, and protocol summaries

Behavior detection

Understand what's happening in your network.

Red Hand analyzes activity across the observation window, looking for behaviors that individual connections may not reveal on their own.

Detects suspicious usage patternsAnalyzes connection timing, repetition, duration, direction, and traffic volume to reveal behavior across the observation window.
Identifies activity worth reviewingSurfaces scans, long-running connections, large transfers, and other behavior that may be legitimate but deserves attention.
Analyzes protocol activityAnalyzes ARP, DNS, Ethernet, ICMP, IGMP, TCP, and UDP activity to identify protocol-specific patterns and anomalies.

Activities

Activity classifications observed in the traffic

  • Suspicious Connections
  • Scans
  • Noteworthy Connections
  • Long Connections
  • Beacons
  • Brute-force Attempts
  • Command and Control
  • Data Transfers
  • Denial-of-Service Attempts
  • Enumerations
  • Tunnels

Enriched context

Richer context produces better detections.

Red Hand enriches endpoints with threat intelligence, WHOIS records, domain information, page rank, and other reputation signals. When Red Hand Collector is used, it also adds process attribution and context over time.

Evaluates behavior over timeAnalyzes recurring communication, event sequences, and changes across the observation window to reveal activity that short captures may not reliably expose.
Recognizes suspicious infrastructureIdentifies endpoints associated with malware, phishing, poor reputation, anonymization, and other risk indicators.
Attributes activity to a processIdentifies the software responsible and uses that context to escalate unexpected activity or deescalate communication from known applications.

Endpoints

Endpoint classifications observed in the traffic

  • Internal Endpoints
  • Bad Reputation
  • Trackers & Ad Servers
  • LOTS (Living Off Trusted Sites)
  • Malware Infrastructure
  • Anonymizers & Proxies
  • Crypto Infrastructure
  • Phishing
  • Registered Recently
  • Spam
  • Spyware
  • Unroutable Addresses

Traffic Data Source

Choose live traffic or packet capture (PCAP) analysis.

Both paths use the same analysis engine, but each provides different evidence and context.

Comparison of live traffic analysis and packet capture file analysis
Feature Live Traffic Analysis PCAP File Analysis
Behavioral analysisDetect patterns and activities across observed network traffic.
Endpoint intelligenceEnrich endpoints with threat intelligence, WHOIS, domain, and reputation data.
Observation windows of any lengthObserve activity continuously to detect behavior that requires context over time. Limited by file size
Process visibilityAttribute network activity to the software responsible. Not available
No endpoint installationAnalyze a capture created with existing tools without installing Red Hand Collector on the target endpoint. Collector installation required