Analyze live network traffic with Red Hand Collector.

Red Hand Collector continuously streams compact, enriched network telemetry to redhand.io for real-time analysis. Red Hand can then leverage the extended observation window, endpoint reputation data, and process attribution to reliably detect stealthy activity and other meaningful network behaviors.

Context over time Process visibility Endpoint intelligence

Install Red Hand Collector

To install, copy and run this command in PowerShell.

irm https://api.redhand.io/install.ps1 | iex

Run PowerShell as Administrator. Administrator access is required to capture traffic from the network adapter and read information about running processes.

How Red Hand Collector works

From raw traffic into insights.

Collector continuously streams network and process telemetry to redhand.io. The analysis engine evaluates the data as it arrives, and the live report updates with findings and recommended next steps.

Target endpoint

Live activity

Network activity

Running processes

On the endpoint

Red Hand Collector

Collects network and process data as activity occurs.

Running continuously
redhand.io

Analysis engine

Continuously enriches and analyzes incoming telemetry.

Analyzing now
Red Hand report

Findings update live

Recurring communication

Suspicious endpoint

Recommended next step

See how detected activity, supporting evidence, and recommended next steps appear in the live report.

View an example Red Hand Report

Red Hand Collector Benefits

Better evidence produces better insights.

Collector gives Red Hand the time, process, and endpoint context needed to recognize more behaviors, evaluate them with greater confidence, and recommend useful next steps.

01

See the pattern

Observation over time

Reveals periodic beacons, slow scans, repeated failures, gradual data transfers, and multi-stage behavior that individual events cannot reliably show.

Collector streams compact traffic telemetry to redhand.io without raw packet data. The smaller data volume makes continuous streaming and real-time analysis practical.
02

Know what caused it

Process visibility

Identifies which application generated the traffic so Red Hand can distinguish expected software behavior from activity that requires attention.

Process data helps Red Hand escalate activity generated by unexpected software and deescalate activity attributable to known, expected applications.
03

Understand the other side

Endpoint intelligence

Evaluates destinations using constantly updated threat intelligence, WHOIS information, PageRank information, IP and domain ownership, popularity, reputation, and other contextual data.

Endpoint intelligence helps Red Hand escalate communications with suspicious infrastructure and deescalate connections to established, reputable services.