Network investigation guide
Investigating Suspicious Endpoint
A suspicious endpoint finding means network traffic involved an IP address or domain identified by threat-intelligence sources as suspicious or malicious.
Understand the finding
What does Suspicious Endpoint mean?
Reputation is a starting point, not proof of malicious behavior. Outbound contact initiated by an internal device is generally more significant than an unanswered inbound probe. This finding also covers suspicious DNS content, where a device queried a listed domain or received a listed name in a response even if no connection followed.
Triage workflow
How to investigate Suspicious Endpoint
- 1
Determine which endpoint or DNS name was flagged, who initiated the activity, and whether a real exchange occurred.
- 2
Review the current threat-intelligence verdict, listing reason, match precision, source consensus, and age relative to the event.
- 3
Identify the internal process responsible for the connection or DNS query and verify whether it is expected.
- 4
Look for recurring contact, DNS-to-connection follow-through, beaconing, control traffic, downloads, tunneling, or data transfer involving the same infrastructure.
Interpret the context
Common benign explanations
Finding this behavior does not by itself prove malicious intent. Common explanations include:
- Unanswered inbound probes from internet scanners that appear on blocklists
- Shared hosting or CDN ranges where one abusive tenant affects the reputation of neighboring services
- Sinkholes, security research, mail scanners, sandboxes, or security tools intentionally contacting flagged infrastructure
Make a decision
When to escalate or de-escalate
Escalate when
- An internal host establishes outbound contact with a malicious endpoint, especially through an unknown process or with repeated communication.
- The reputation match is corroborated by another behavioral detection, several internal hosts contact the same infrastructure, or a suspicious DNS query leads to a connection.
De-escalate when
- The event is an unanswered inbound probe with no evidence that an internal service or host engaged.
- A current reputation review confirms a broad shared-infrastructure match, stale listing, or approved security workflow and no suspicious behavior remains unexplained.
Analyze the evidence
Investigate network behavior with Red Hand
Red Hand turns network traffic into a report that identifies meaningful behavior, adds endpoint and process context when available, and provides practical investigation guidance.