RedLane
A patient adversary does not break in and take. It arrives quietly, waits, uses access you already granted, and leaves months later with exactly what it came for. RedLane operates that way on purpose, so you find out whether anyone would have noticed.

is how long a state-linked intruder stays inside before anyone finds them.
Median dwell time for cyber espionage intrusions. Across all intrusion types the median is 14 days.
A service, bought two ways.
RedLane is not software you install. It is a team, a method and a delivery system that S32 Technologies operates on your behalf. Hold it as a standing line inside a platform contract, with engagements that recur on a cadence only you know, or engage it once against a single objective.
Engagements are technology agnostic and run against the stack you already own. An engagement tests how your defenses perform. It is not a certification of any S32 Technologies product, including our own.
Every event was logged. Nobody joined them up.
One operation, one objective
- identity abuse
- mailbox discovery
- document search
- source-code access
- low-volume download
- second persistence
- cloud API
- controlled egress
Individually logged events; the relationship between them is the finding.
Identity abuse, mailbox discovery, a document search, source-code access, repeated low-volume downloads, a second persistence route, cloud API access, controlled egress. Read one at a time, every one of these is something a legitimate user does. The failure is not that they were missed. It is that nobody recognized the relationship between them.
What we measure
A conventional assessment reports whether an attack path existed and which alerts were missed. That answers the first four questions below and stops. RedLane measures all nine, and reports them separately, because the level at which your response broke is the finding.

These are our assessment dimensions, not an industry standard. We publish the method so you can judge it before you buy it.
is the test
Mandiant put the 2025 global median dwell time at 14 days. For cyber espionage intrusions specifically, the median was 122 days. One campaign, BRICKSTORM, averaged 393 days inside its victims, living on network appliances that cannot run an endpoint agent.
Defenders got dramatically better at catching the adversary who wants to be found. The one who does not want to be found is still measured in months. That gap is not a detection-tooling problem. It is a recognition problem.
In 1997, the Eligible Receiver exercise used publicly available tools against defenders who had not been told. The finding was not that the systems were weak. It was that nobody could tell. Almost thirty years later, the medians above say the same thing.
Paced like the adversary, supervised like an exercise.
A supervised engagement
- Authorizeone trusted agent
- Establishquietly, then wait
- Collectagainst a defined objective
- Debriefthe nine levels
The control cell remains reachable throughout and can halt the engagement. Activity is deliberately sparse, with dormant periods and work across shifts.
Your trusted agent authorizes the window and forms the control cell. From there the engagement runs against a team operating normally, at a deliberately low action rate, with dormancy between phases, because an operation compressed into a fortnight cannot produce the signal profile of one that takes months. The control cell can confirm whether an event your people are chasing is ours, and halt any part of it instantly.
What you are left holding
Not a list of vulnerabilities. An answer to the questions a board asks after an incident, gathered while the incident was still ours to control.
Mission detection assessment: nine-level result and recognition timeline
Did anyone notice?
Level 04How long did it take, and at which level did it break?
Day 47Did anyone see it as one operation?
NoWhat did they think we were after?
RecordedWould eradication have removed all of it?
PartialWhat did, and did not, leave?
EstablishedThe report is about your team, not our tools.
Engagements
Mission detection assessment
The flagship. Assumed breach, a defined collection objective rather than domain admin, and the nine-level result. The fastest route to knowing where recognition breaks.
Extended campaign
Real elapsed time, dormancy between phases, and activity deliberately crossing your telemetry retention boundary. For programs that need to know what a patient adversary would achieve.
Adversary emulation
Threat-led. We replicate the tradecraft of an actor your sector is actually facing, with the scenario traced back to the evidence it was built from.
Penetration testing
External, internal, web, API, mobile and cloud. Scoped and announced, when what you need is control validation rather than a test of response.
Detection validation
Run alongside your defenders with everything called out live. The techniques nothing caught are the deliverable rather than a footnote.
Operational technology
Assessed in a modeled environment. We do not run active testing against live plant, and the rules of engagement say so in writing before anything starts.
Delivered remote, on premises, or fully offline inside your facility. Engagements run without notice to your defenders, which is the standard for red teaming and the only way the nine levels can be measured honestly.
Where this differs
| Conventional red team | Automated simulation | RedLane | |
|---|---|---|---|
| What is measured | Whether an attack path exists, and which alerts were missed | Whether a known technique trips a control | Whether your team recognized one operation, at nine separate levels |
| Pacing | Concentrated into the engagement window | Atomic tests, executed on demand | Deliberately sparse, with dormancy and cross-shift activity |
| The objective | Usually privilege, often domain admin | Technique coverage | A defined collection objective, so mission inference can be tested |
| Where it operates | Varies by team | Where the agent runs | Including appliances, hypervisors and identity, where agents cannot run |
| Whose tooling | Varies by firm | The vendor platform | Yours. We stay technology agnostic and certify nothing we sell |
Fixed-scope testing for commercial teams.
If you are here because an auditor, an insurer or a customer asked for a penetration test, you do not need the rest of this page. There is a shorter one with defined scopes, turnaround times and what your auditor will accept.
Questions
Is this not just a long red team?
A red team reports the path it took and the alerts you missed. This reports the level at which your response broke, separating whether you saw the events from whether you understood them as one operation. Those are different failures, and the second is the one that produces long dwell times.
Do we have to run your products?
No. Engagements are technology agnostic and run against the stack you already have. If we find gaps our own products would close, we will say so, and you remain free to close them any way you like. An engagement validates how your defenses performed; it is not an independent certification of anything S32 Technologies sells.
Who in our organization has to know?
One authorizing executive, plus whoever they place in the control cell. That is the whole list, and it is agreed in writing before the window opens. Your defenders are not told, which is the standard for red teaming.
How does RedLane relate to NetDefense and Cyber Response?
NetDefense is a detection layer an engagement tests, and Cyber Response investigates when it is not an exercise. RedLane runs against whatever you already have. We do not require any of it, and an engagement certifies none of it.
What if our team escalates for real?
That is the exercise working, and it is a measurement. Your trusted agent can confirm the activity is ours and stand them down at any point, or let it run to see how far the response goes.