Behavior detection
Understand what's happening in your network.
Red Hand analyzes activity across the observation window, looking for behaviors that individual connections may not reveal on their own.
Activities
Activity classifications observed in the traffic
- Suspicious Connections
- Scans
- Noteworthy Connections
- Long Connections
- Beacons
- Brute-force Attempts
- Command and Control
- Data Transfers
- Denial-of-Service Attempts
- Enumerations
- Tunnels
Enriched context
Richer context produces better detections.
Red Hand enriches endpoints with threat intelligence, WHOIS records, domain information, page rank, and other reputation signals. When Red Hand Collector is used, it also adds process attribution and context over time.
Endpoints
Endpoint classifications observed in the traffic
- Internal Endpoints
- Bad Reputation
- Trackers & Ad Servers
- LOTS (Living Off Trusted Sites)
- Malware Infrastructure
- Anonymizers & Proxies
- Crypto Infrastructure
- Phishing
- Registered Recently
- Spam
- Spyware
- Unroutable Addresses
Traffic Data Source
Choose live traffic or packet capture (PCAP) analysis.
Both paths use the same analysis engine, but each provides different evidence and context.
| Feature | Live Traffic Analysis | PCAP File Analysis |
|---|---|---|
| Behavioral analysisDetect patterns and activities across observed network traffic. | ||
| Endpoint intelligenceEnrich endpoints with threat intelligence, WHOIS, domain, and reputation data. | ||
| Observation windows of any lengthObserve activity continuously to detect behavior that requires context over time. | Limited by file size | |
| Process visibilityAttribute network activity to the software responsible. | Not available | |
| No endpoint installationAnalyze a capture created with existing tools without installing Red Hand Collector on the target endpoint. | Collector installation required |