Investigate live activity, not an old snapshot.
Red Hand Analytics updates as Collector observes new connections, endpoints, activities, and data movement, keeping everything in one continuously evolving investigation.
Live network analysis
Continuously analyze endpoint network traffic, identify the process behind each connection, and investigate new findings in real time with the context needed to understand what is happening.
Red Hand Collector runs on Windows, Linux, and macOS. It must be installed on a laptop or desktop computer. If your operating system was detected incorrectly, select the appropriate tab above to continue.
To install, copy and run this command in PowerShell.
irm https://api.redhand.io/install.ps1 | iex
Run PowerShell as Administrator. Administrator access is required to capture traffic from the network adapter and read information about running processes.
To install, copy and run this command in Terminal.
curl -fsSL https://api.redhand.io/install.sh | sudo bash
sudo access is required to capture traffic from the network interface and read information about running processes.
Create a free account now or create one during first-time setup.
Red Hand Collector
Collector keeps the investigation current while adding the process and endpoint context needed to understand each connection.
Red Hand Analytics updates as Collector observes new connections, endpoints, activities, and data movement, keeping everything in one continuously evolving investigation.
Reveal periodic beacons, slow scans, repeated failures, gradual transfers, and multi-stage behavior that isolated events cannot reliably show.
Identify the responsible application so expected software behavior can be separated from activity that requires attention.
Add threat intelligence, ownership, reputation, popularity, and domain context to the endpoints involved in each connection.
How Red Hand Collector works
Collector follows network connections as they happen and keeps the investigation updated over time. It also records which process initiated each connection, while Red Hand Analytics adds endpoint context and supporting evidence.
Network activity + process context
Findings + evidence + next steps
Open a sample report to see the findings and supporting evidence.
View an example investigation