Home Solutions RedSeal
Network Model · Attack Path · Compliance · DRS
RedSeal logo

Turn attack paths into
dead ends.

RedSeal builds a mathematical model of your network, down to every firewall, router and cloud VPC. You see every possible attack path between segments before an attacker finds it.

DoD
used by the US Department of Defense and the world’s largest banks.
2004
founded. A pioneer of attack path analysis.
200K+
network devices modeled by the largest customer.
Agentless
no agents on devices, just config imports.
Attack Path Analysis

Where an attacker can get from point A to the crown jewels.

RedSeal models every firewall rule, route, NAT and cloud security group. It overlays data from vulnerability scanners and shows real attack paths, with the CVE at each step.

Internetuntrusted
DMZ web-01CVE-2024-3094
app-tier db-jumpCVE-2023-4863
Core-DBPII / Payments
Backup VLANisolated ✓
OT segmentisolated ✓
Reachable path
3 hops · 2 CVE · risk 92 / 100
3 hops
from any untrusted node to Core-DB: RedSeal finds them in minutes.
×5
CVE prioritization by real reachability instead of “everything is critical”.
What-if
testing a firewall change before it is applied in production.
Capabilities

What the RedSeal platform can do.

Asset Inventory

Visibility of the entire network

Config imports from Cisco, Fortinet, Palo Alto, Juniper, Check Point and F5; synchronization with AWS and Azure. A graph of every subnet, route and policy.

Attack Path

Attack path analysis

A source→target reachability graph with the CVE at every hop. The top 10 paths to the crown jewels on a single screen.

Compliance

Segmentation audit

Ready-made reports for PCI DSS, NIST 800-53, CIS and central bank requirements. Every firewall change is automatically checked for violations.

Vuln Prioritization

CVE prioritization

RedSeal takes CVEs from Tenable, Rapid7 or Qualys and ranks them by real exposure from untrusted zones instead of by CVSS.

DRS Score

Digital Resilience Score

A single 0-800 KPI for the board of directors. Trends over time by business unit and domain.

Hybrid Cloud

On-prem + AWS + Azure

Import of Security Groups, NACLs, TGW and Azure NSG. A single model of the data center and cloud network.

Use cases

Where RedSeal helps right away.

01
PCI segmentation checks
RedSeal automatically checks whether the CDE segment is really isolated, with no manual audit of firewall rules.
02
Before every firewall change
Simulate a policy change in the model before it goes into production. Change management teams know what to expect.
03
Pre-M&A network audit
Before networks merge, assess the integration risks and plan segmentation for the new segments.
04
Cyber resilience for the board
The DRS score and its trend: a simple KPI for CISO/CIO reports to the board.
05
Post-incident review
After an incident, rebuild the attacker’s path and find the gap in segmentation.
06
Hybrid-cloud audit
Corporate network + AWS/Azure: a single model and a single compliance report.
CYBER BOOST × RedSeal

We help you build the network model.

We set up RedSeal from start to finish. We connect devices, import configs, link your vulnerability scanners and train analysts to read models and attack paths.

2-4 weeks
typical PoC: a model of 50-100 devices and the first attack path reports.
Tenable
integration with vulnerability scanners (Tenable, Rapid7, Qualys).
RU/UZ
certified RedSeal Professional analysts.
L1–L3
local support and escalation to RedSeal R&D.
FAQ

Frequently asked questions about RedSeal.

What is the RedSeal Digital Resilience Score?
The Digital Resilience Score is a single number from 0 to 800 that shows how well your network is protected. It is calculated from factors such as asset visibility, correct segmentation, firewall policy effectiveness and vulnerability exposure. It is a KPI the board of directors understands.
How does RedSeal calculate attack paths?
RedSeal imports the configurations of firewalls, routers, L3 switches and cloud security groups. It builds a reachability graph and overlays data from vulnerability scanners (Tenable, Rapid7, Qualys). For each source→target pair, it calculates the shortest attack path, taking into account the CVEs along the way.
Which vulnerability scanners does RedSeal work with?
Tenable Nessus / SC, Rapid7 InsightVM, Qualys VM, OpenVAS. RedSeal imports their data natively and ranks vulnerabilities by whether they can actually be reached from untrusted zones.
Does RedSeal work with the public cloud?
Yes. RedSeal imports the configurations of AWS Security Groups, NACLs, Transit Gateway, Azure NSG, Route Tables and VNet Peering. On-prem and cloud networks are modeled together as one graph.
Is RedSeal suitable for central bank and PCI DSS compliance?
Yes. RedSeal provides ready-made reports for PCI DSS segmentation, NIST 800-53, CIS Benchmarks and central bank segmentation requirements. Any firewall configuration change is automatically checked for violations.
Request · RedSeal

A network model PoC on your own devices.

Tell us what you need: compliance, segmentation audit, attack paths or hybrid cloud. We will put together a PoC plan.