Network Detection & Response

Network Detection and Response for the way your network works.

Red Hand Network Detection and Response (NDR) continuously analyzes network activity to detect suspicious behavior and support investigation. Install Collector on an endpoint for deeper host context, or monitor mirrored traffic centrally with Red Hand for TAP/SPAN for broader network visibility. In both architectures, the Red Hand service on redhand.io performs the analysis and produces the report.

Installed on selected endpointsGain deeper context

Associate network activity with the process responsible and follow behavior on the systems that matter most.

Installed on a central serverGain broader visibility

Analyze mirrored traffic from many devices without installing software on every monitored endpoint.

Analyzed by Red Hand on redhand.ioBehavior detection, enrichment, reports, and investigation guidance

Two ways to deploy Red Hand NDR

Choose the Network Detection and Response architecture that supports your goal.

Both approaches use the same Red Hand NDR analysis service. The difference is where traffic is observed and the context that can be collected there.

Agent-based Network Detection and Response

NDR with Red Hand Collector

Understand what a critical endpoint is communicating with and which process is responsible.

Investigate with process contextUse process attribution to escalate activity from unexpected software or de-escalate communication explained by a known application.
Build context continuouslyStream compact telemetry over extended observation windows to reveal recurring, low-and-slow, and sequence-based behavior.
See activity at its sourceObserve enrolled endpoints directly, including traffic that may never pass through a central monitoring point.
Requirements
  • Install Collector on each endpoint you want to monitor.
  • Run the initial setup with administrative or root privileges.
  • Allow the endpoint to send telemetry to redhand.io.
Considerations
  • Direct coverage is limited to endpoints running Collector.
  • The telemetry does not include raw packet data.
Runs in your environmentCollector is installed on a Windows, Linux, or macOS endpoint. It sends compact network and process telemetry to redhand.io without sending raw packet data.
Install Red Hand Collector
Agentless Network Detection and Response

NDR with Red Hand for TAP/SPAN

Monitor traffic from many devices through one centrally deployed collection point.

Cover more of the networkObserve managed endpoints, unmanaged systems, appliances, and other devices whose traffic is visible to the monitoring point.
Avoid endpoint deploymentAdd Network Detection and Response without installing or maintaining collection software on every monitored device.
Use existing network visibilityTurn mirrored traffic from a network TAP or switch SPAN port into continuously analyzed security evidence.
Requirements
  • Provide a dedicated machine to run Red Hand for TAP/SPAN.
  • Connect that machine to the destination interface receiving mirrored traffic.
  • Configure a network TAP or switch SPAN port to forward the traffic you want monitored.
  • Allow the machine to send telemetry to redhand.io.
Considerations
  • Visibility is limited to traffic forwarded to the monitoring machine.
  • Mirrored traffic does not provide process attribution.
Runs in your environmentRed Hand for TAP/SPAN is installed on a central server that receives mirrored traffic and sends traffic telemetry to the Red Hand service on redhand.io.
Explore Agentless NDR

Red Hand NDR architecture

One Network Detection and Response service. Two collection architectures.

Collection runs in your environment while detection and analysis run on redhand.io. Collector and Red Hand for TAP/SPAN provide two paths for securely delivering network evidence to the Red Hand NDR service.

Your environment
Selected endpointRed Hand Collector

Network and process telemetry

Compact telemetry
OR
Central server receiving mirrored trafficRed Hand for TAP/SPAN

Network traffic telemetry

Traffic telemetry
redhand.ioRed Hand Analysis Service
  • Behavioral detection over time
  • Endpoint intelligence and enrichment
  • Finding assessment and prioritization
  • Live report and investigation guidance

Choose your NDR deployment

Which NDR architecture is right for you?

Start with the visibility and investigation context your security team needs most.

Choose Collector when...

  • You need to know which process created suspicious traffic.
  • You are investigating or protecting specific high-value endpoints.
  • You need continuous visibility even when traffic does not cross a central sensor.
Learn about Collector

Choose TAP/SPAN when...

  • You want visibility across many devices from one deployment.
  • You need to monitor systems that cannot or should not run an agent.
  • You already have TAP, SPAN, or mirrored traffic available centrally.
Learn about Agentless NDR

Use both when...

You want centralized network coverage and deeper process context on selected endpoints. Both collection paths can contribute evidence to the same Red Hand analysis service.

Deploy Red Hand NDR

Put Network Detection and Response to work.

Install Collector for endpoint-level context or contact us to evaluate centralized TAP/SPAN monitoring.