Live activity
Network activity
Running processes
Red Hand Collector continuously streams compact, enriched network telemetry to redhand.io for real-time analysis. Red Hand can then leverage the extended observation window, endpoint reputation data, and process attribution to reliably detect stealthy activity and other meaningful network behaviors.
To install, copy and run this command in PowerShell.
irm https://api.redhand.io/install.ps1 | iex
Run PowerShell as Administrator. Administrator access is required to capture traffic from the network adapter and read information about running processes.
To install, copy and run this command in Terminal.
curl -fsSL https://api.redhand.io/install.sh | sudo bash
sudo access is required to capture traffic from the network interface and read information about running processes.
Create a free account now or create one during first-time setup.
How Red Hand Collector works
Collector continuously streams network and process telemetry to redhand.io. The analysis engine evaluates the data as it arrives, and the live report updates with findings and recommended next steps.
Network activity
Running processes
Collects network and process data as activity occurs.
Running continuouslyContinuously enriches and analyzes incoming telemetry.
Analyzing nowRecurring communication
Suspicious endpoint
Recommended next step
See how detected activity, supporting evidence, and recommended next steps appear in the live report.
View an example Red Hand ReportRed Hand Collector Benefits
Collector gives Red Hand the time, process, and endpoint context needed to recognize more behaviors, evaluate them with greater confidence, and recommend useful next steps.
See the pattern
Reveals periodic beacons, slow scans, repeated failures, gradual data transfers, and multi-stage behavior that individual events cannot reliably show.
Collector streams compact traffic telemetry to redhand.io without raw packet data. The smaller data volume makes continuous streaming and real-time analysis practical.Know what caused it
Identifies which application generated the traffic so Red Hand can distinguish expected software behavior from activity that requires attention.
Process data helps Red Hand escalate activity generated by unexpected software and deescalate activity attributable to known, expected applications.Understand the other side
Evaluates destinations using constantly updated threat intelligence, WHOIS information, PageRank information, IP and domain ownership, popularity, reputation, and other contextual data.
Endpoint intelligence helps Red Hand escalate communications with suspicious infrastructure and deescalate connections to established, reputable services.