Skip to content

Microsoft Announces Multi-Model AI Agent System for Security Operations

Key point: Project Perception combines multiple AI models in an agent-based system to identify vulnerabilities, simulate attacks, detect threats, and automatically develop remediation plans.

Microsoft has introduced Project Perception, an AI-powered service that supports security teams through specialized agents in continuously monitoring and improving their security posture. The system enters public preview on August 3.

Project Perception employs a multi-model approach, where a central control instance decides which AI model is best suited for a given task. This is designed to balance quality and cost, as not every task requires the latest frontier model.

Microsoft has also developed the MAI-Cyber-1-Flash model, which was trained specifically to find vulnerabilities in complex codebases. In combination with GPT-5.4 within MDASH — Microsoft’s Multi-Model Harness for Vulnerability Research — this combination achieves substantially better results on the CyberGym benchmark than Anthropic Mythos 5 or OpenAI GPT-5.6-Sol, while doing so at approximately half the cost. MDASH was developed by Microsoft’s new internal team FORGE, led by Georgia Tech professor Taesoo Kim and several of his current and former doctoral students. Multiple FORGE members were previously members of Team Atlanta, which won the two-year DARPA AI Cyber Challenge (AIxCC).

Project Perception combines Microsoft’s extensive threat intelligence, security telemetry, and knowledge of customer environments into a complex security graph. Specialized agents — Red Team, Blue Team, and Green Team — use this graph to execute specialized playbooks. In the demonstration, Microsoft showed a scenario in which a new threat intelligence report with indicators of compromise and attack tactics arrives: the system automatically distributes tasks to the required agents, which examine the environment for protection, identify vulnerabilities, and prioritize them based on likelihood of attack by the specific threat actor.

The results are then automatically forwarded to additional agents that generate custom detection rules, propose remediation plans, or even submit code fixes to the internal repository. David Weston, CVP for Microsoft Security and leader of Perception, reports that tasks previously requiring hours of manual work by multiple specialized security professionals are now completed in minutes through automation — including vulnerability detection, prioritization, detection rules, and code fixes.


Source: www.csoonline.com · Published July 28, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: