Associate network activity with the process responsible and follow behavior on the systems that matter most.
Network Detection & Response
Comparing our Agentless and Agent-based NDR:
Red Hand Network Detection and Response (NDR) continuously analyzes network activity to detect suspicious behavior and support investigation. Install Collector on an endpoint for deeper host context, or monitor mirrored traffic centrally with Red Hand for TAP/SPAN for broader network visibility. In both architectures, the Red Hand service on redhand.io performs the analysis and produces the report.
Analyze mirrored traffic from many devices without installing software on every monitored endpoint.
Two ways to deploy Red Hand NDR
Choose the Network Detection and Response architecture that supports your goal.
Both approaches use the same Red Hand NDR analysis service. The difference is where traffic is observed and the context that can be collected there.
NDR with Red Hand Collector
Understand what a critical endpoint is communicating with and which process is responsible.
- Install Collector on each endpoint you want to monitor.
- Run the initial setup with administrative or root privileges.
- Allow the endpoint to send telemetry to redhand.io.
- Direct coverage is limited to endpoints running Collector.
- The telemetry does not include raw packet data.
NDR with Red Hand for TAP/SPAN
Monitor traffic from many devices through one centrally deployed collection point.
- Provide a dedicated machine to run Red Hand for TAP/SPAN.
- Connect that machine to the destination interface receiving mirrored traffic.
- Configure a network TAP or switch SPAN port to forward the traffic you want monitored.
- Allow the machine to send telemetry to redhand.io.
- Visibility is limited to traffic forwarded to the monitoring machine.
- Mirrored traffic does not provide process attribution.
Red Hand NDR architecture
One Network Detection and Response service. Two collection architectures.
Collection runs in your environment while detection and analysis run on redhand.io. Collector and Red Hand for TAP/SPAN provide two paths for securely delivering network evidence to the Red Hand NDR service.
Network and process telemetry
Network traffic telemetry
- Behavioral detection over time
- Endpoint intelligence and enrichment
- Finding assessment and prioritization
- Live report and investigation guidance
Choose your NDR deployment
Which NDR architecture is right for you?
Start with the visibility and investigation context your security team needs most.
Choose Collector when...
- You need to know which process created suspicious traffic.
- You are investigating or protecting specific high-value endpoints.
- You need continuous visibility even when traffic does not cross a central sensor.
Choose TAP/SPAN when...
- You want visibility across many devices from one deployment.
- You need to monitor systems that cannot or should not run an agent.
- You already have TAP, SPAN, or mirrored traffic available centrally.
Use both when...
You want centralized network coverage and deeper process context on selected endpoints. Both collection paths can contribute evidence to the same Red Hand analysis service.