Network investigation guides

Investigating network activity

Understand what a network behavior means, what evidence to review, and when a finding should be escalated or de-escalated.

Detection and triage guides

Each guide explains the behavior in practical terms, covers common benign causes, and provides a focused investigation workflow.

Network discovery

Investigating ARP Scan

An ARP scan occurs when a device queries many local IP addresses to discover which systems are active on the same network.

Read investigation guide
Network discovery

Investigating Port Sweep

A port sweep occurs when one device probes the same network port across many hosts to find systems offering a particular service.

Read investigation guide
Network discovery

Investigating Port Scan

A port scan occurs when one device probes many network ports on a single host to learn which services the host exposes.

Read investigation guide
Remote access

Investigating Control Connection

A control connection is an active remote administration session using a protocol or tool such as SSH, RDP, WinRM, or remote-support software.

Read investigation guide
Discovery and enumeration

Investigating Service Enumeration

Service enumeration is repeated querying of a directory or network service to list accounts, shares, devices, permissions, or other useful resources.

Read investigation guide
Credential access

Investigating Login Brute Force

Login brute-force activity is a rapid series of connection attempts to a password-protected service that resembles repeated rejected sign-ins.

Read investigation guide
Automated collection

Investigating Web Scraping

Web scraping is repeated automated retrieval of pages or resources from a web service to collect content at scale.

Read investigation guide
Command and control

Investigating HTTPS Beacon

An HTTPS beacon is a recurring pattern of short connections from one device to the same internet endpoint, often with little data returned.

Read investigation guide
Denial of service

Investigating SYN Flood

A SYN flood overwhelms a host or service with large numbers of TCP connection requests, consuming connection capacity and reducing availability.

Read investigation guide
Tunneling and proxying

Investigating SOCKS Tunnel

A SOCKS tunnel carries other network connections through a proxy channel, allowing traffic to cross boundaries through an intermediary.

Read investigation guide
Threat intelligence

Investigating Suspicious Endpoint

A suspicious endpoint finding means network traffic involved an IP address or domain identified by threat-intelligence sources as suspicious or malicious.

Read investigation guide
Data movement

Investigating Collection

Collection activity is a large or unusual movement of data that may represent information being gathered or staged before it leaves the environment.

Read investigation guide

Find meaningful behavior in network traffic

Use Red Hand to analyze live traffic or a PCAP file and turn network activity into clear findings and practical investigation guidance.