Red Hand Analytics
Connections
Inspect the individual network exchanges that support a finding or summary.Connections shows the individual exchanges behind an activity, endpoint, DNS request, or aggregate widget.
Read a connection row
Each row can include:
- Time when the connection was observed.
- Initiator and source port.
- Target and destination port.
- Connection protocol and recognized service.
- Status such as established or incomplete.
- Duration of the exchange.
- Data, Upload, and Download totals.
Text that does not fit in a column is clipped visually; hover it to see the complete value.
Filters and preset context
The available filters depend on how you opened the screen. Common filters include initiators, targets, ports, protocols, services, and status. A preset filter appears in the matching dropdown so it is clear why the current rows are shown.
Choose Show all to clear the preset context. Use Clear filters to reset manual dropdown selections.
Sorting and paging
Use the sort control to change the ordering and direction. Paging is performed by the server, so changing pages requests the next matching set rather than loading the entire report into the browser. The list scrolls back to its first row after a page change.
Open Endpoint Analysis
Select an endpoint button in the initiator or target column to open Endpoint Analysis immediately. The containing list stays in place, including its filters, sort, and page.
Understand totals
Data is total traffic in both directions. Upload is traffic from initiator to target; download is traffic from target to initiator. An aggregate activity or widget can total multiple connection rows, so its value may be larger than any one row.
Missing values
Service names are inferred from protocol and port when possible. Status, duration, hostname, process, and byte totals depend on what the source captured. Missing fields are shown as unavailable rather than inferred.
See it in context