Product documentation
Red Hand Analytics Documentation
Learn how to move from a network finding to the endpoints, requests, data, and connections that explain it.
Start here
3 guides
Getting started
Open a report, understand the workspace, and follow evidence from a finding to its connections.
Core concepts
Learn how Red Hand Analytics uses activities, occurrences, endpoints, connections, and severity.
My Reports
Create, monitor, sort, open, and manage PCAP and Collector reports.
Analyze
7 guides
Activities
Prioritize detected behavior and open the connection evidence behind each finding.
Endpoints
Review internal and external systems, reputation, ownership, services, and related behavior.
Connections
Inspect the individual network exchanges that support a finding or summary.
Data Flows
Trace inbound, outbound, and internal transfers and identify unusually large exchanges.
Repeated Connections
Find endpoint pairs that communicate repeatedly and distinguish routine traffic from beaconing.
Long Connections
Review long-running sessions and the endpoints, services, and data associated with them.
DNS
Inspect resolvers, unresolved requests, noisy clients, data exchange, and conflicting answers.
Operate
3 guides
Real Time
Understand continuous Collector reports, refresh behavior, and live network and process context.
Data Source
Review report metadata, capture timeframe, completion details, and data-quality recommendations.
Troubleshooting
Resolve empty screens, unavailable metadata, processing reports, and unexpected totals.
No matching documentation
Try a screen name, metric, or concept such as DNS, severity, or upload.