Network investigation guide

Investigating Collection

Collection activity is a large or unusual movement of data that may represent information being gathered or staged before it leaves the environment.

Data movement MITRE ATT&CK: T1074 Data Staged

What does Collection mean?

Backups, synchronization, software delivery, and normal downloads move large volumes legitimately. Direction, data sensitivity, process attribution, destination, and a later outbound transfer determine whether collection indicates data theft or operational activity.

How to investigate Collection

  1. 1

    Identify the source, destination, direction, process, user, volume, and data type.

  2. 2

    Compare the transfer with normal baselines, schedules, and approved storage services.

  3. 3

    Determine whether sensitive repositories or unusual staging locations were accessed.

  4. 4

    Look for compression, encryption, external transfer, deletion, or ransomware behavior afterward.

Common benign explanations

Finding this behavior does not by itself prove malicious intent. Common explanations include:

  • Scheduled backup, replication, database dump, or synchronization
  • Software, image, media, or dataset distribution
  • Approved cloud storage, file sharing, and large downloads

When to escalate or de-escalate

Escalate when

  • Sensitive data is staged by an unusual process or transferred toward an unapproved destination.
  • Collection is followed by exfiltration, deletion, encryption, or other intrusion activity.

De-escalate when

  • The transfer matches an approved backup, synchronization, deployment, or business workflow.
  • The identities, systems, data, timing, and volume are all expected.

Investigate network behavior with Red Hand

Red Hand turns network traffic into a report that identifies meaningful behavior, adds endpoint and process context when available, and provides practical investigation guidance.