Network investigation guide
Investigating Collection
Collection activity is a large or unusual movement of data that may represent information being gathered or staged before it leaves the environment.
Understand the finding
What does Collection mean?
Backups, synchronization, software delivery, and normal downloads move large volumes legitimately. Direction, data sensitivity, process attribution, destination, and a later outbound transfer determine whether collection indicates data theft or operational activity.
Triage workflow
How to investigate Collection
- 1
Identify the source, destination, direction, process, user, volume, and data type.
- 2
Compare the transfer with normal baselines, schedules, and approved storage services.
- 3
Determine whether sensitive repositories or unusual staging locations were accessed.
- 4
Look for compression, encryption, external transfer, deletion, or ransomware behavior afterward.
Interpret the context
Common benign explanations
Finding this behavior does not by itself prove malicious intent. Common explanations include:
- Scheduled backup, replication, database dump, or synchronization
- Software, image, media, or dataset distribution
- Approved cloud storage, file sharing, and large downloads
Make a decision
When to escalate or de-escalate
Escalate when
- Sensitive data is staged by an unusual process or transferred toward an unapproved destination.
- Collection is followed by exfiltration, deletion, encryption, or other intrusion activity.
De-escalate when
- The transfer matches an approved backup, synchronization, deployment, or business workflow.
- The identities, systems, data, timing, and volume are all expected.
Analyze the evidence
Investigate network behavior with Red Hand
Red Hand turns network traffic into a report that identifies meaningful behavior, adds endpoint and process context when available, and provides practical investigation guidance.