Red Hand Analytics
Getting started
Open a report, understand the workspace, and follow evidence from a finding to its connections.Red Hand Analytics turns a packet capture or continuous Collector traffic into a connected workspace for reviewing activities, endpoints, DNS, data movement, and individual connections.
Open a report
Reports are available from My Reports. Select a completed PCAP or Collector report to open it. A PCAP report represents a fixed capture; a Collector report can continue to receive new traffic and analysis updates.
If you want to explore before using your own data, open the sample report.
Move through the workspace
The left navigation organizes the report by the question you are trying to answer:
- Activities surfaces detected behavior and supporting evidence.
- Endpoints inventories the systems and domains in the report.
- Data Flows explains where data moved and in which direction.
- Repeated Connections highlights frequently communicating endpoint pairs.
- Long Connections isolates persistent sessions.
- DNS focuses on resolvers, requests, responses, and DNS-specific anomalies.
- Data Source describes the report, its timeframe, and capture quality.
Use overview, timeline, and list views
Most sections provide three levels of detail:
- Overview summarizes the most important totals and ranked results.
- Timeline shows when behavior occurred and lets you select a timeframe.
- List shows the underlying activities, requests, or connections and provides filters, sorting, and paging.
The exact tabs depend on the section. DNS uses a Request List, while Endpoints uses an Endpoint List.
Follow evidence without losing context
Use View, View Activities, View Requests, or View Connections to carry the current item into a more detailed screen. Preset filters are applied automatically, and matching dropdowns show the selected values.
Endpoint buttons open Endpoint Analysis without leaving the current list. Close the dialog to return to the same filters and page.
A practical first pass
- Start in Activities and review suspicious findings.
- Open the connections for an interesting activity.
- Inspect the initiator and target endpoints.
- Check DNS and Data Flows for related requests or transfers.
- Return to the activity and decide whether the combined evidence is expected, noteworthy, or suspicious.
Account-gated sections
Activities is available in shared reports. Some deeper analysis sections require a signed-in account. If a section is gated, sign in or create a free account and reopen the report.
See it in context