Network investigation guide

Investigating Collection Activities

Collection activity is a large or unusual movement of data that may represent information being gathered or staged before it leaves the environment.

Data movement MITRE ATT&CK: T1074 Data Staged
Network illustration representing Collection Activities

What do Collection Activities mean?

Backups, synchronization, software delivery, and normal downloads move large volumes legitimately. Direction, data sensitivity, process attribution, destination, and a later outbound transfer determine whether collection indicates data theft or operational activity.

How to investigate Collection Activities

  1. 1

    Identify the source, destination, direction, process, user, volume, and data type.

  2. 2

    Compare the transfer with normal baselines, schedules, and approved storage services.

  3. 3

    Determine whether sensitive repositories or unusual staging locations were accessed.

  4. 4

    Look for compression, encryption, external transfer, deletion, or ransomware behavior afterward.

Common benign explanations

Finding this behavior does not by itself prove malicious intent. Common explanations include:

  • Scheduled backup, replication, database dump, or synchronization
  • Software, image, media, or dataset distribution
  • Approved cloud storage, file sharing, and large downloads

When to escalate or de-escalate

Escalate when

  • Sensitive data is staged by an unusual process or transferred toward an unapproved destination.
  • Collection is followed by exfiltration, deletion, encryption, or other intrusion activity.

De-escalate when

  • The transfer matches an approved backup, synchronization, deployment, or business workflow.
  • The identities, systems, data, timing, and volume are all expected.

Investigate network behavior with Red Hand

Red Hand turns network traffic into a report that identifies meaningful behavior, adds endpoint and process context when available, and provides practical investigation guidance.