Network investigation guides
Investigating network activity
Understand what a network behavior means, what evidence to review, and when a finding should be escalated or de-escalated.
Choose a behavior
Detection and triage guides
Each guide explains the behavior in practical terms, covers common benign causes, and provides a focused investigation workflow.
Investigating ARP Scan
An ARP scan occurs when a device queries many local IP addresses to discover which systems are active on the same network.
Read investigation guide Network discoveryInvestigating Port Sweep
A port sweep occurs when one device probes the same network port across many hosts to find systems offering a particular service.
Read investigation guide Network discoveryInvestigating Port Scan
A port scan occurs when one device probes many network ports on a single host to learn which services the host exposes.
Read investigation guide Remote accessInvestigating Control Connection
A control connection is an active remote administration session using a protocol or tool such as SSH, RDP, WinRM, or remote-support software.
Read investigation guide Discovery and enumerationInvestigating Service Enumeration
Service enumeration is repeated querying of a directory or network service to list accounts, shares, devices, permissions, or other useful resources.
Read investigation guide Credential accessInvestigating Login Brute Force
Login brute-force activity is a rapid series of connection attempts to a password-protected service that resembles repeated rejected sign-ins.
Read investigation guide Automated collectionInvestigating Web Scraping
Web scraping is repeated automated retrieval of pages or resources from a web service to collect content at scale.
Read investigation guide Command and controlInvestigating HTTPS Beacon
An HTTPS beacon is a recurring pattern of short connections from one device to the same internet endpoint, often with little data returned.
Read investigation guide Denial of serviceInvestigating SYN Flood
A SYN flood overwhelms a host or service with large numbers of TCP connection requests, consuming connection capacity and reducing availability.
Read investigation guide Tunneling and proxyingInvestigating SOCKS Tunnel
A SOCKS tunnel carries other network connections through a proxy channel, allowing traffic to cross boundaries through an intermediary.
Read investigation guide Threat intelligenceInvestigating Suspicious Endpoint
A suspicious endpoint finding means network traffic involved an IP address or domain identified by threat-intelligence sources as suspicious or malicious.
Read investigation guide Data movementInvestigating Collection
Collection activity is a large or unusual movement of data that may represent information being gathered or staged before it leaves the environment.
Read investigation guideAnalyze the evidence
Find meaningful behavior in network traffic
Use Red Hand to analyze live traffic or a PCAP file and turn network activity into clear findings and practical investigation guidance.