Bottom line: Project Perception automates threat analysis, vulnerability detection, and remediation through specialized AI agents using a multi-model approach, reducing processes from several hours to minutes.
Microsoft announces Project Perception, an AI-powered service that supports security teams through specialized agents in the continuous assessment and optimization of their security posture. The system will be available in public preview beginning August 3, 2024.
Project Perception combines Microsoft’s threat intelligence, security telemetry, and knowledge of customer environments into a complex security graph. A multi-model approach selects the best AI model for each task to strike a balance between quality and cost — not every operation requires a top-tier frontier model.
The system’s core consists of specialized agents (Red Team, Blue Team, Green Team) that automatically distribute and execute tasks. For example, the agents can analyze new threat intelligence reports, match infrastructure exposure against known adversary TTPs, conduct penetration tests, prioritize vulnerabilities by criticality and attack likelihood, generate detection rules, and propose remediation plans with code fixes — from WAF blocking rules to patch submissions into the internal repository.
Microsoft also introduced the MAI-Cyber-1-Flash model, specifically trained for vulnerability detection in complex codebases. In combination with GPT 5.4 within MDASH (Microsoft’s multi-model harness), the combination achieved significantly higher scores on the CyberGym benchmark than Anthropic Mythos 5 and OpenAI GPT 5.6-Sol — at roughly half the cost structure. MDASH was developed by Microsoft’s new FORGE department (Frontier Offensive Research & Generative Exploration), led by Georgia Tech professor Taesoo Kim, whose team includes several members of the DARPA AI Cyber Challenge (AIxCC) winner Team Atlanta.
According to David Weston, Corporate Vice President at Microsoft Security, Project Perception reduces processes that previously required several hours of specialized experts (application security analysts, remediation engineers) to minutes. The integration of vulnerability detection, prioritization, detection, and automated remediation into a single automated workflow addresses a core burden for large security organizations.
Source: www.csoonline.com · Published July 28, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification through Lumi News Pipeline v1.7.3.