Red Hand AnalyticsDocs

Red Hand Analytics

Long Connections

Review long-running sessions and the endpoints, services, and data associated with them.

Long Connections highlights persistent sessions so you can distinguish expected long-lived services from unusual communication.

What the overview shows

The overview ranks connections and activities by duration, with endpoint, protocol, service, status, and data context. A long duration is not automatically suspicious; remote administration, streaming, tunnels, messaging, and synchronization often maintain sessions.

Timeline

Timeline shows when long connections began. Compare their start times with user activity, scheduled tasks, deployments, and other findings in the report.

Activity List

Activity List summarizes behaviors related to persistent sessions. Open View connections to inspect the individual rows, including duration, upload, download, ports, and status.

Investigate a long connection

  1. Confirm the initiator, target, and service.
  2. Check whether the connection remained active or simply lacks a closing packet.
  3. Compare its data rate and direction with the expected application.
  4. Review endpoint ownership, reputation, and related activities.
  5. Use process information from Collector reports when available.

Limitations

Packet captures that begin or end mid-session cannot always provide an exact connection duration. Treat the displayed duration as observed duration within the available report.

See it in context

Open Long Connections in the sample report

Explore this screen with a completed report and real navigation, filters, and evidence.
Open example
Was this page useful?