Red Hand AnalyticsDocs

Red Hand Analytics

Core concepts

Learn how Red Hand Analytics uses activities, occurrences, endpoints, connections, and severity.

These terms describe how information is organized across Red Hand Analytics.

Activity, detection, and occurrence

An activity is a named behavior identified in the traffic, such as a control connection, ARP scan, or noteworthy endpoint. A detection describes the behavior itself. Occurrences tells you how many times that activity was observed in the report.

One activity can summarize multiple connections. Open its connection evidence when you need the individual exchanges.

Connection

A connection is a communication between an initiator and a target. It includes the observed addresses, ports, protocol or service, status, duration, and upload and download totals when available.

Connections are evidence. They do not automatically imply malicious intent.

Endpoint

An endpoint is an IP address, hostname, or domain observed in the report. Red Hand Analytics classifies endpoints as internal or external based on the available network context.

An endpoint may also be flagged by threat intelligence or associated with suspicious activity. Those are different signals: reputation describes what is known about the endpoint, while suspicious activity describes behavior observed in this report.

Initiator and target

The initiator started a connection. The target received it. These roles are more precise than client and server when traffic does not follow a conventional application pattern.

Upload and download

Upload is data sent from the initiator to the target. Download is data returned from the target to the initiator. Total data is the sum of both directions.

For internal-to-internal traffic, the direction still follows the initiator and target roles rather than an internet boundary.

First and last observed

First observed is the earliest matching timestamp in the current report or aggregation. Last observed is the latest. Not available means the source data does not contain a usable timestamp for that field.

Severity and threat intelligence

Severity ranks the observed behavior. Threat intelligence adds outside reputation context to an endpoint or domain. A low-severity activity may still include a flagged endpoint, and a high-severity behavioral finding may involve endpoints with no reputation history.

Use both signals, then verify the underlying connections.

Aggregates and rows

Overview widgets group many records. A ranked row may therefore show totals that differ from any single connection. Opening the row applies its grouping fields as filters so you can review the contributing records.

See it in context

Open Core concepts in the sample report

Explore this screen with a completed report and real navigation, filters, and evidence.
Open example
Was this page useful?