Red Hand Analytics
Repeated Connections
Find endpoint pairs that communicate repeatedly and distinguish routine traffic from beaconing.Repeated Connections identifies endpoint pairs that communicate frequently, making periodic beacons and noisy recurring traffic easier to see.
What the overview shows
The overview ranks repeated communication patterns using connection count, timing, endpoints, service, and data. High frequency is a clue, not a conclusion: health checks, synchronization, name resolution, and monitoring can all create legitimate repetition.
Timeline
Use Timeline to determine whether connections are evenly periodic, clustered around user activity, or concentrated in a short burst. Regular intervals with little variation can be more interesting than a high count alone.
Activity List
Activity List shows the detections associated with the repeated connection pattern. Filters appear below the preset-context bar and follow the same visual and interaction model used in DNS Requests.
Investigate a repeated pattern
- Compare the interval between connections.
- Check whether the target and service are expected.
- Review data volume in both directions.
- Determine whether one process is responsible when process context is available.
- Look for related suspicious activities on the initiator or target.
Limitations
A short capture may make ordinary retries look periodic or may include too few observations to establish a pattern. Validate repetition across a longer timeframe when possible.
See it in context