S32TECHNOLOGIES
Offensive Security

RedLane

A patient adversary does not break in and take. It arrives quietly, waits, uses access you already granted, and leaves months later with exactly what it came for. RedLane operates that way on purpose, so you find out whether anyone would have noticed.

Request a capabilities briefingWhat we measure

Office towers at night with lit floors
122 days

is how long a state-linked intruder stays inside before anyone finds them.

Median dwell time for cyber espionage intrusions. Across all intrusion types the median is 14 days.

Mandiant, M-Trends 2026 Report
MonthsEngagements run at real elapsed time, with dormant periods between phases, so the activity crosses shift handovers and telemetry retention
9 levelsOf defensive response measured, from telemetry through eradication
Your stackTested as deployed, end to end
Two waysA standing line in a platform contract, or a single engagement

A service, bought two ways.

RedLane is not software you install. It is a team, a method and a delivery system that S32 Technologies operates on your behalf. Hold it as a standing line inside a platform contract, with engagements that recur on a cadence only you know, or engage it once against a single objective.

Engagements are technology agnostic and run against the stack you already own. An engagement tests how your defenses perform. It is not a certification of any S32 Technologies product, including our own.

The problem

Every event was logged. Nobody joined them up.

ONE OPERATION, ONE OBJECTIVEidentityabusemailboxdiscoverydocumentsearchsource-codeaccesslow-volumedownloadsecondpersistencecloudAPIcontrolledegressEACH EVENT: LOGGED, ALERTED IN SOME CASES, INDIVIDUALLY DEFENSIBLE

One operation, one objective

  1. identity abuse
  2. mailbox discovery
  3. document search
  4. source-code access
  5. low-volume download
  6. second persistence
  7. cloud API
  8. controlled egress

Individually logged events; the relationship between them is the finding.

Identity abuse, mailbox discovery, a document search, source-code access, repeated low-volume downloads, a second persistence route, cloud API access, controlled egress. Read one at a time, every one of these is something a legitimate user does. The failure is not that they were missed. It is that nobody recognized the relationship between them.

What we measure

A conventional assessment reports whether an attack path existed and which alerts were missed. That answers the first four questions below and stops. RedLane measures all nine, and reports them separately, because the level at which your response broke is the finding.

01TelemetryDid the relevant evidence exist at all?
02DetectionDid a control identify the activity as suspicious?
03AlertingDid an actionable alert reach a human being?
04TriageWas the signal examined correctly, or closed?
05Campaign recognitionDid anyone realize the separate events were one operation?
06Mission inferenceDid anyone work out what the adversary was actually after?
07ContainmentWas the activity in progress stopped?
08EradicationWas every persistence route and compromised identity removed?
09Collection assuranceCan you establish what did, and did not, leave?

These are our assessment dimensions, not an industry standard. We publish the method so you can judge it before you buy it.

Why this
is the test

Mandiant put the 2025 global median dwell time at 14 days. For cyber espionage intrusions specifically, the median was 122 days. One campaign, BRICKSTORM, averaged 393 days inside its victims, living on network appliances that cannot run an endpoint agent.

Defenders got dramatically better at catching the adversary who wants to be found. The one who does not want to be found is still measured in months. That gap is not a detection-tooling problem. It is a recognition problem.

In 1997, the Eligible Receiver exercise used publicly available tools against defenders who had not been told. The finding was not that the systems were weak. It was that nobody could tell. Almost thirty years later, the medians above say the same thing.

How it runs

Paced like the adversary, supervised like an exercise.

CONTROL CELL · REACHABLE THROUGHOUT · CAN HALT ANY ACTION IN ONE SECONDAuthorizeone trusted agentEstablishquietly, then waitCollectagainst a defined objectiveDebriefthe nine levelsACTIVITY DELIBERATELY SPARSE · DORMANT PERIODS · CROSS-SHIFT

A supervised engagement

  1. Authorizeone trusted agent
  2. Establishquietly, then wait
  3. Collectagainst a defined objective
  4. Debriefthe nine levels

The control cell remains reachable throughout and can halt the engagement. Activity is deliberately sparse, with dormant periods and work across shifts.

Your trusted agent authorizes the window and forms the control cell. From there the engagement runs against a team operating normally, at a deliberately low action rate, with dormancy between phases, because an operation compressed into a fortnight cannot produce the signal profile of one that takes months. The control cell can confirm whether an event your people are chasing is ours, and halt any part of it instantly.

What you are left holding

Not a list of vulnerabilities. An answer to the questions a board asks after an incident, gathered while the incident was still ours to control.

Engagement report · illustrative

Mission detection assessment: nine-level result and recognition timeline

ENGAGEMENT  RL-2026-014WINDOW  11 WEEKSCONTROL CELL  YOUR TRUSTED AGENTCLASSIFICATION  AS AGREED

Did anyone notice?

Level 04

How long did it take, and at which level did it break?

Day 47

Did anyone see it as one operation?

No

What did they think we were after?

Recorded

Would eradication have removed all of it?

Partial

What did, and did not, leave?

Established

The report is about your team, not our tools.

Engagements

Mission detection assessment

The flagship. Assumed breach, a defined collection objective rather than domain admin, and the nine-level result. The fastest route to knowing where recognition breaks.

Extended campaign

Real elapsed time, dormancy between phases, and activity deliberately crossing your telemetry retention boundary. For programs that need to know what a patient adversary would achieve.

Adversary emulation

Threat-led. We replicate the tradecraft of an actor your sector is actually facing, with the scenario traced back to the evidence it was built from.

Penetration testing

External, internal, web, API, mobile and cloud. Scoped and announced, when what you need is control validation rather than a test of response.

Detection validation

Run alongside your defenders with everything called out live. The techniques nothing caught are the deliverable rather than a footnote.

Operational technology

Assessed in a modeled environment. We do not run active testing against live plant, and the rules of engagement say so in writing before anything starts.

Delivered remote, on premises, or fully offline inside your facility. Engagements run without notice to your defenders, which is the standard for red teaming and the only way the nine levels can be measured honestly.

Where this differs

Conventional red teamAutomated simulationRedLane
What is measuredWhether an attack path exists, and which alerts were missedWhether a known technique trips a controlWhether your team recognized one operation, at nine separate levels
PacingConcentrated into the engagement windowAtomic tests, executed on demandDeliberately sparse, with dormancy and cross-shift activity
The objectiveUsually privilege, often domain adminTechnique coverageA defined collection objective, so mission inference can be tested
Where it operatesVaries by teamWhere the agent runsIncluding appliances, hypervisors and identity, where agents cannot run
Whose toolingVaries by firmThe vendor platformYours. We stay technology agnostic and certify nothing we sell

Fixed-scope testing for commercial teams.

If you are here because an auditor, an insurer or a customer asked for a penetration test, you do not need the rest of this page. There is a shorter one with defined scopes, turnaround times and what your auditor will accept.

Fixed-scope engagements

Questions

Is this not just a long red team?

A red team reports the path it took and the alerts you missed. This reports the level at which your response broke, separating whether you saw the events from whether you understood them as one operation. Those are different failures, and the second is the one that produces long dwell times.

Do we have to run your products?

No. Engagements are technology agnostic and run against the stack you already have. If we find gaps our own products would close, we will say so, and you remain free to close them any way you like. An engagement validates how your defenses performed; it is not an independent certification of anything S32 Technologies sells.

Who in our organization has to know?

One authorizing executive, plus whoever they place in the control cell. That is the whole list, and it is agreed in writing before the window opens. Your defenders are not told, which is the standard for red teaming.

How does RedLane relate to NetDefense and Cyber Response?

NetDefense is a detection layer an engagement tests, and Cyber Response investigates when it is not an exercise. RedLane runs against whatever you already have. We do not require any of it, and an engagement certifies none of it.

What if our team escalates for real?

That is the exercise working, and it is a measurement. Your trusted agent can confirm the activity is ours and stand them down at any point, or let it run to see how far the response goes.