RedWolf Security
RedWolf Security is a Waterloo, Canada-based provider of cloud-based DDoS and threat simulation platforms serving 200+ Fortune-branded enterprises, offering 300+ attack vectors, 1+ Tbps distributed traffic generation, and both managed and self-serve testing models for security defense validation.
- Company typePrivate
- Founded2006
- HeadquartersWaterloo, Canada
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What RedWolf Security does
RedWolf Security is a Waterloo, Ontario-based cybersecurity firm founded in 2006 that operates a cloud-based threat simulation platform enabling enterprises to validate defenses against DDoS attacks, insider threats, and security device performance under realistic conditions. The core RedWolf Platform serves as a command and control system orchestrating traffic generation from over 100 data centers across 36-45 global regions with aggregate capacity exceeding 1 Terabit/sec, and executes more than 300 proprietary DDoS attack vectors covering Layers 2-7 across IPv4 and IPv6 protocols. The platform includes specialized modules for Mirai IoT botnet simulation (reverse-engineered at packet level), BlackNurse anti-firewall attacks, HTTP/2 Rapid Reset (CVE-2023-44487) testing, VPN protocol testing, and internal threat simulation covering 200+ insider threat scenarios.
The company delivers services through three primary commercial mechanisms: (1) managed testing engagements, which are expert-led, multi-year professional services contracts with dedicated on-bridge support and ~100-page post-test reports; (2) a self-serve platform subscription (auth.redwolfsecurity.com) providing 24/7 portal access with reusable test libraries and API-driven automation; and (3) usage-based agent licensing at hourly rates, supporting up to 20,000 agents per test. The platform integrates with over 400 third-party systems including SIEM platforms (Splunk, ELK, ArcSight), major cloud providers (AWS, Google Cloud, Microsoft Azure, IBM, Oracle, Rackspace), and DDoS mitigation vendors (Akamai, Cloudflare, Imperva, F5, RadWare, Arbor). RedWolf serves 200+ Fortune-branded enterprises, with disclosed customers including BNY Mellon, Foresters Financial, a Fortune 500 Global Bank, Crownpeak, and a Global Payment Processor. The company is currently a subsidiary of BlueSky Holdco (owned by Johnson Control Luxembourg European Finance) and is subject to a pending acquisition by Intelligent Monitoring Group (ASX: IMB) for NZ$45 million, expected to close before March 2026, with FY26 RedWolf-associated revenue forecast at NZ$89.5 million and EBITDA of NZ$10.9 million.
RedWolf Security firmographics
Firmographics- Name
- RedWolf Security
- Legal name
- RedWolf Security Incorporated
- Website
- https://redwolfsecurity.com
- Company type
- Private
- Founded year
- 2006
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- RedWolf Security is a Waterloo, Canada-based provider of cloud-based DDoS and threat simulation platforms serving 200+ Fortune-branded enterprises, offering 300+ attack vectors, 1+ Tbps distributed traffic generation, and both managed and self-serve testing models for security defense validation.
- Ownership category
- akta.pro rank
RedWolf Security industry classification
Industry- Product category
- Cybersecurity Testing Software
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Programming Services (7371), Services-Testing Laboratories (8734)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKADAE)
- akta.pro secondary industry
- Penetration Testing & Red Teaming (BPAKAHAF)
Keywords
Where RedWolf Security is headquartered
LocationHeadquarters
- HQ city
- Waterloo
- HQ country
- Canada
- HQ region
- North America
Offices1 record
Markets served
RedWolf Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Infrastructure, Personnel, Operations, Marketing or Sales
Revenue model
- Managed Testing Services: RedWolf expert-led managed testing engagements including scoping, design, test implementation, live test execution with RedWolf staff on bridge, and detailed post-test reporting (~100-page reports with executive summaries and per-vector analysis). Services include Control Matrix Development, DDoS Testing/Control Validations, Run Book Development, Architectural Assessments, and Operations Training/Wargames.
- Self-Serve Platform Subscription: 24/7 self-serve portal access allowing customers to design, run, and manage their own DDoS and security tests using pre-built or custom test libraries. Includes 10 shared agents by default with options to add virtually unlimited additional agents. Training for 4 people included with initial access.
- Agent/Capacity Licensing: Per-agent usage charges where each agent is priced at a fixed hourly rate. Up to 20,000 agents available per test. Agents can be sourced from any supported cloud provider and deployed by geographic region, provider, or specific IP address.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Hybrid | Multi-year contract | Managed Testing — Dedicated RedWolf-Facilitated Engagement |
| Usage-based | Monthly | Self-Serve Platform — Subscription with Usage-Based Agents |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels7 records
RedWolf Security product offering
Product offeringCore offering
RedWolf Security provides a cloud-based DDoS testing and threat simulation platform that enables enterprises to validate the resilience of their networks, applications, and security infrastructure against large-scale volumetric and application-layer attacks. The platform offers self-service, managed, and consultative testing engagements, complemented by training services for security teams.
Product overview
RedWolf Security provides a comprehensive threat simulation platform for enterprise cybersecurity validation. The core RedWolf Platform serves as the central command and control system, integrating Cloud DDoS Testing, Security Device Testing, Training Services, and multiple threat simulation capabilities. The platform offers over 300 attack vectors spanning volumetric, connection, and application-layer attacks, with distributed traffic generation from over 100 global data centers. Key product modules include External Threat Simulation for DDoS and load testing, Internal Threat Simulation for insider threat scenarios, Situational Awareness for monitoring and data fusion, and Next Generation SOC services for security operations transformation. The company delivers services through both Self-Serve Testing (web-based portal) and Managed Testing (expert-led) models, supported by professional consulting services. The platform integrates with SIEM systems (Splunk, ELK, ArcSight) and supports REST API automation.
Differentiator
Problem solved
Functional benefit
Products and services
- The RedWolf Platform Cloud-based DDoS testing and threat simulation platform used by enterprise security teams to validate network, application, and infrastructure resilience against realistic cyberattacks.
- Cloud DDoS Testing Generates large-scale, distributed DDoS attack traffic from global points-of-presence to stress-test cloud and hybrid environments for enterprises.
- Security Device Testing Validates the effectiveness of enterprise security infrastructure including scrubbing centers, CDNs, web application firewalls, firewalls, and intrusion prevention systems under simulated attack conditions.
- Training Services Hands-on training programs for enterprise security, network, and operations teams to develop DDoS mitigation, incident response, and platform administration skills.
- Self-Serve Testing Customer-controlled, on-demand DDoS and security testing through a web portal with MFA authentication, enabling in-house teams to schedule and run attack simulations autonomously.
- Managed Testing White-glove DDoS testing service in which RedWolf engineers design, execute, and report on attack simulations for enterprise customers end-to-end.
- Consulting Services Expert advisory and consulting engagements that help enterprises design DDoS mitigation strategies, assess security posture, and remediate gaps identified through testing.
Quantifiable outcome
- DDoS defense success rate improved from 25% to 80% over three test periods within one year at a Fortune 500 bank
- +4 more outcomes
Companies that use RedWolf Security
Customer profileNamed customers5 records
Segments3 records
Ideal customer profiles2 records
RedWolf Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability4 records
Feature8 records
RedWolf Security partnerships and signals
Strategic signalPartnerships
13 partnerships are on record, tiered flagship and core.
- Intelligent Monitoring Group (ASX: IMB)flagshipIntelligent Monitoring Group (IMG) agreed to acquire BlueSky Holdco — the parent of Tyco New Zealand and RedWolf Security — from Johnson Control Luxembourg European Finance for NZ$45 million (approximately A$39 million) in cash. The acquisition is expected to complete before March 2026 and is forecast to be accretive from FY26, generating RedWolf-associated revenue of NZ$89.5m and EBITDA of NZ$10.9m. This represents a significant strategic partnership where RedWolf becomes part of IMG's monitored security network of over 217,000 sites.
- Amazon Web Services (AWS)coreRedWolf was the first DDoS testing vendor allowed to legally launch large DDoS attacks against Amazon AWS (2008) and has maintained a long-standing partnership. AWS has an official DDoS Partner Testing Policy that includes pre-approved AWS DDoS Test Partners. RedWolf is listed as an AWS DDoS testing partner and has been invited to present at AWS Re:Invent.
- Google CloudcoreRedWolf sources traffic from Google Cloud data centers as part of its globally distributed testing infrastructure. Google Cloud availability zones are among the sources used for RedWolf's multi-region DDoS simulation tests.
- Microsoft AzurecoreRedWolf sources traffic from Microsoft Azure data centers globally. Azure availability zones are integrated into RedWolf's distributed traffic generation network for DDoS and load testing simulations.
- IBM SoftLayercoreRedWolf sources traffic from IBM SoftLayer (now IBM Cloud) data centers and has a longstanding relationship. IBM SoftLayer is specifically noted as supporting IPSEC VPN testing traffic that other cloud providers filter by default (e.g., Amazon does not support IPSEC).
- CrownpeakcoreCrownpeak is a website hosting and management provider that engages RedWolf Security to perform DDoS testing and cloud hardening for its enterprise clients, including BNY Mellon. Crownpeak collaborated with RedWolf on the AWS WAF hardening case study presented at AWS Re:Invent.
- Akamai (Prolexic)coreAkamai (including Prolexic) is one of the DDoS mitigation vendors RedWolf has extensive experience testing against. RedWolf has tested Akamai's cloud DDoS scrubbing, CDN + Kona WAF offerings and has deep knowledge of their testing authorization processes and configuration requirements.
- CloudflarecoreCloudflare is listed among the DDoS mitigation providers RedWolf has worked with extensively. RedWolf has tested Cloudflare's CDN, WAF, and DDoS protection systems and has developed specific knowledge of their testing authorization processes.
- Imperva / IncapsulacoreImperva/Incapsula is listed among RedWolf's tested DDoS mitigation providers. RedWolf has worked with Imperva's Cloud WAF and DDoS protection solutions and has documented testing approaches specific to their technology.
- F5 SilverlinecoreF5 Silverline is a managed DDoS mitigation service that RedWolf has tested and validated. RedWolf also has extensive experience with F5 LTM, ASM, and other F5 on-premise technologies including best-practice configuration guidance for DDoS scenarios.
- RadWarecoreRadWare is listed among RedWolf's tested DDoS mitigation providers, including RadWare Cloud and Defense Pro/Alteon on-premise solutions. RedWolf has documented testing approaches and configuration guidance for RadWare technologies.
- Arbor CloudcoreArbor Cloud (including Arbor Pravail/TMS) is listed among the on-premise and cloud DDoS mitigation technologies RedWolf has extensive experience testing. RedWolf has documented testing approaches for Arbor's Pravail availability protection and TMS (Threat Management System).
- Splunk, ELK, ArcSightcoreSIEM platforms including Splunk, ELK Stack, and ArcSight are among the monitoring systems RedWolf integrates with. RedWolf agents can correlate scenario activity against SIEM evidence, and monitoring data is exported in formats compatible with these platforms.
Scale indicators8 records
Recent moves6 records
Expansion highlights6 records
RedWolf Security competitors and assessment
Company assessmentEmerging players
- Bugcrowd: Bugcrowd runs a crowdsourced security testing platform connecting enterprises with vetted researchers for pentest and red team engagements — a partial overlap with RedWolf's on-demand enterprise testing model.
- Cobalt: Cobalt provides a pentest-as-a-service platform enabling on-demand, results-driven penetration testing for enterprises — a SaaS-flavored counterpart to RedWolf's managed and self-serve testing offerings.
Broad incumbents
- NCC Group: NCC Group is a global cybersecurity services firm providing extensive penetration testing, red teaming, and managed security testing across industries; a broader incumbent with overlapping threat simulation services.
- Akamai (Prolexic): Akamai operates one of the world's largest DDoS mitigation platforms (including Prolexic) and runs an authorized DDoS testing partner program that includes RedWolf — comparable as adjacent infrastructure that validates the same controls RedWolf tests.
Direct peers
- Pentera: Pentera offers automated security validation that safely emulates adversary attacks across the full kill chain, mirroring RedWolf's model of testing defenses against simulated real-world threats for enterprise customers.
- AttackIQ: AttackIQ delivers a security optimization platform that emulates adversary behaviors and validates controls at scale, competing head-on with RedWolf in continuous security control validation and threat-informed defense.
- Cymulate: Cymulate provides an exposure management platform including breach-and-attack simulation, automated red teaming, and attack-surface management — closely aligned with RedWolf's external/internal threat simulation offerings.
- SafeBreach: SafeBreach provides a breach-and-attack simulation platform that validates enterprise security controls against real-world adversary techniques, directly overlapping with RedWolf's continuous security validation and threat simulation positioning.
- Bishop Fox: Bishop Fox is a cybersecurity consulting firm offering penetration testing, red teaming, and continuous security testing for Fortune 500 companies — overlapping with RedWolf's enterprise testing practice and customer base.
- IOActive: IOActive is a cybersecurity consultancy specializing in penetration testing, red teaming, and security device assessments — directly comparable to RedWolf's managed testing and security device validation services for enterprises.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights7 records
Customer concentration
RedWolf Security social profiles
Digital presenceRedWolf Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
RedWolf Security leadership team
Management profileNumber of profiles
Profiles1 record
RedWolf Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
RedWolf Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about RedWolf Security
What does RedWolf Security do?
RedWolf Security provides a cloud-based DDoS testing and threat simulation platform that enables enterprises to validate the resilience of their networks, applications, and security infrastructure against large-scale volumetric and application-layer attacks. The platform offers self-service, managed, and consultative testing engagements, complemented by training services for security teams.
Is RedWolf Security a public or private company?
RedWolf Security is a private company. It is classified as corporate owned and is currently operating.
When was RedWolf Security founded?
RedWolf Security was founded in 2006. It employs 11 to 50 people.
Where is RedWolf Security based?
RedWolf Security is headquartered in Waterloo, Canada, in the North America region.
How does RedWolf Security make money?
Three revenue lines are on record. Managed Testing Services are the primary driver. The others are self-Serve Platform Subscription and agent/Capacity Licensing.
Who are RedWolf Security's main competitors?
Emerging players on record are Bugcrowd and Cobalt. Broad incumbents are NCC Group and Akamai (Prolexic). Direct peers are Pentera, AttackIQ, Cymulate, SafeBreach, Bishop Fox and IOActive.
Does RedWolf Security have an API?
Yes. RedWolf platform offers a Full API for automation, enabling users to create, configure, and execute DDoS tests programmatically. The platform supports API access for self-serve testing via auth.redwolfsecurity.com, with multi-factor authentication and IP restriction capabilities. Users can automate test creation, modify attack parameters in real-time, and integrate with external systems through REST API endpoints. Developer documentation is at auth.redwolfsecurity.com.
What industry is RedWolf Security in?
RedWolf Security's product category is Cybersecurity Testing Software. Its primary akta.pro industry code is BPAKADAE, Penetration Testing & Red Teaming, with a secondary code of BPAKAHAF, Penetration Testing & Red Teaming. Its NAICS code is 5415 and its SIC code is 7371.