Consulting Licence Offer From Redseal – Security Risk Manager (SRM)


Redseal is launching a free offer next week for security consultants, pen testers and auditors.

Redseal develops a product called Security Risk Manager (SRM), it does the following – (non sales overview)

  1. Imports firewall and router configuration files
  2. Audits and checks them for errors, mis configurations, redundant rules, checks against best practices etc
  3. Draws a network topography map from the configs (you can move this around, save layouts, export to Visio)
  4. Builds a network blueprint of all permitted traffic flows which you can query (i.e. can traffic from internet get to my PCI servers etc)
  5. Built in “inference intelligence” auto populates what applications are running on the network and gives them asset values (you can customize and define as much as you want)
  6. Has a built in Threat Reference Library to provide vulnerability info, currently over 23,000 and updated on a weekly basis (you can also load in Nessus, Qualys and Foundstone scan data if you have it as well)
  7. Analyzes the network and security data to identify what vulnerabilities are the most important to fix based on network access and importance.
  8. Shows unique graphical ways to quickly view and drill down through huge sets of data to find the most important information.

The product has been referenced by some consultants as the first way to perform a passive pen test as it is completely unobtrusive, you just need to load in configs, no scanning required.

Redseal has launched a license for Consultants to use out in the field and to promote it they are offering security consultants and auditors free and full use of the product for 30 days. They are keen for consultants to use the product and prove out it’s capabilities and values in the field and they want to hear feedback and so if anyone would like to take us up on this offer please email consultants@redseal.net to sign up for the program, it’s quick, easy and free.

Some of the latest news is below:

Red Seal Press Releases

There is also a short white paper here.

Posted in: Countermeasures, Security Software

, , , , ,


Latest Posts:


tko-subs - Detect & Takeover Subdomains With Dead DNS Records tko-subs – Detect & Takeover Subdomains With Dead DNS Records
tko-subs is a tool that helps you to detect & takeover subdomains with dead DNS records, this could be dangling CNAMEs point to hosting services and more.
Arcane - Tool To Backdoor iOS Packages (iPhone ARM) Arcane – Tool To Backdoor iOS Packages (iPhone ARM)
Arcane is a simple script tool to backdoor iOS packages (iPhone ARM) and create the necessary resources for APT repositories.
SharpHose - Asynchronous Password Spraying Tool SharpHose – Asynchronous Password Spraying Tool
SharpHose is an asynchronous password spraying tool in C# for Windows environments that takes into consideration fine-grained password policies and can be run over Cobalt Strike's execute-assembly.
Axiom - Pen-Testing Server For Collecting Bug Bounties Axiom – Pen-Testing Server For Collecting Bug Bounties
Project Axiom is a set of utilities for managing a small dynamic infrastructure setup for bug bounty, basically a pen-testing server out of the box with 1-line.
Quasar RAT - Windows Remote Administration Tool Quasar RAT – Windows Remote Administration Tool
Quasar is a fast and light-weight Windows remote administration tool coded in C#. Used for user support through day-to-day administrative work to monitoring.
Pingcastle - Active Directory Security Assessment Tool Pingcastle – Active Directory Security Assessment Tool
PingCastle is a Active Directory Security Assessment Tool designed to quickly assess the Active Directory security level based on a risk and maturity framework.


Comments are closed.