Red Hand Analytics
Endpoints
Review internal and external systems, reputation, ownership, services, and related behavior.Endpoints provides an inventory of internal and external systems, then adds activity and reputation context to help you decide where to look next.

Endpoint summary
The summary shows observed, threat-intelligence-flagged, and suspicious endpoints. A flagged endpoint has reputation context from an external source. A suspicious endpoint initiated or participated in behavior detected as suspicious in this report.
Ranked endpoint groups
The overview separates:
- Your Endpoints for internal systems.
- External Endpoints for internet or otherwise external systems.
- Suspicious or Breached Endpoints for systems associated with suspicious activity or threat intelligence.
Use Flagged Only in External Endpoints to focus on reputation matches. An amber flag indicates a threat-intelligence match that is not itself a suspicious behavioral finding.
Endpoint Analysis
Select an endpoint icon or View to open Endpoint Analysis. The dialog can include identity, ownership, location, threat intelligence, page rank for domains, first and last observation, related services, activities, peers, and connections.
For a domain, page rank is shown as its position in the top one million domains. Not in top 1M domains means a domain was present but had no matching rank. Endpoints without a domain show Unknown.
Endpoint List
Endpoint List is useful when the overview does not show the endpoint you need. Filter and sort the full inventory, then open Endpoint Analysis without leaving the list.
Questions to ask
- Is the endpoint internal or external as expected?
- Which endpoint initiated the traffic?
- Is its hostname or ownership consistent with the service?
- Is it flagged by threat intelligence, and how current is that information?
- Which activities and connections explain its presence in the report?
Limitations
Hostname, ownership, process, and reputation fields depend on available telemetry and enrichment. Missing enrichment is not evidence that an endpoint is safe.
See it in context