The landscape of cybersecurity is undergoing a significant transformation. With the advent of autonomous systems that can reason, adapt, and function continuously, the balance of power is shifting. The cost of launching cyberattacks is decreasing, while the breadth, speed, and complexity of what needs safeguarding are expanding. Malicious actors are now able to create exploits more quickly, extend their reach, and operate at unmatched efficiencies. Traditional security strategies designed for human involvement simply cannot keep up with threats born from artificial intelligence and machine-speed attacks.
This evolution calls for a revamped Cyber Stack—one that continuously assesses risk across an organization's entire digital infrastructure, processes vast amounts of contextual information, and responds at machine speed. The objective is to foster a system that not only learns and adapts to evolving environments but also empowers security personnel with enhanced insights and effective operational capabilities. The hallmark of these next-generation security systems will be their ability to perceive threats in real-time, reason through them, and take decisive action, rather than simply generating a flood of alerts.
This vision inspired the development of Project Perception, an innovative agentic security framework tailored for a reality where AI plays a central role. By converting signals into instantaneous protections, Project Perception harnesses AI to defend against AI-driven threats.
Project Perception integrates various signals, contextual information, models, and specialized agents into a self-improving defense mechanism. It operates at machine speed, allowing for prioritized reasoning and actions, all while maintaining human oversight and facilitating more efficient workflows.
At its core, Project Perception operates on the principle that effective defense hinges on an ongoing comprehension of an attacker’s perspective, the defender’s risk assessment framework, and the iterative enhancement of security measures. It employs a collaborative trio of specialized agents: Red team agents scout for potential vulnerabilities that attackers might exploit; Blue team agents analyze and evaluate contextual risks; and Green team agents implement corrective measures to fortify defenses. Together, these teams create a comprehensive loop that perpetually identifies, assesses, and enhances an organization’s security stance.
The efficacy of Project Perception is directly linked to its visibility, actions it can enact, the expertise of its developers, and the models it employs. Microsoft integrates all these elements effectively.
With extensive visibility across identities, endpoints, applications, data, cloud environments, and AI systems, we ensure comprehensive awareness for clients. Equally pivotal is our capability to enable action across these diverse environments. Coupled with years of security research, threat intelligence, and operational experience in defending organizations, these resources shape the reasoning, prioritization, and responses of Project Perception.
In the realm of cybersecurity, constant vigilance is essential. Organizations require robust protection that is effective, consistently available, and scalable at an affordable cost. This necessitates more than just access to advanced models; it involves deploying the most suitable model for each specific task. Project Perception employs a multi-model architecture that merges cutting-edge and specialized cyber models, balancing quality and cost considerations.
Our intention is to provide clients with top-tier models for various security tasks, including the development of our specialized models. The first implementation focuses on managing software vulnerabilities, utilizing the MAI-Cyber-1-Flash model within MDASH, our advanced software vulnerability response team. MDASH, powered by MAI-Cyber-1-Flash, achieves a 96% score on CyberGym—a leading industry benchmark—surpassing Mythos by 12 points. Furthermore, this configuration can yield nearly 50% in cost savings compared to existing solutions on the market. This exemplifies the effectiveness of a finely-tuned, multi-model system leveraging rich historical training data. Future applications of Project Perception will explore numerous other security workflows beyond just software vulnerabilities.
This groundbreaking initiative will be accessible to clients globally as Project Perception enters public preview on August 3.
A properly devised Cyber Stack is crucial for achieving agentic security.
Creating an effective agentic security environment goes beyond merely adding agents to established workflows; it necessitates a new Cyber Stack built from the ground up.
The structure of this stack begins with signals and sensors that provide comprehensive awareness of the digital landscape. Advanced security context transforms these signals into actionable insights that agents can utilize efficiently. Intelligence and reasoning are supplied by sophisticated models, while a coordinating harness aligns models and agents throughout security workflows. Agents then utilize this intelligence, and actuators implement the decisions to create robust protections. Together, these components construct a continuously evolving system capable of understanding risks, adapting to changes, and improving security outcomes over time.
The true power of Project Perception lies in the synergy of these layers.
For AI-driven reasoning to be effective, context is crucial.
Microsoft cultivates its extensive visibility, threat intelligence, and security expertise into a robust security context that links data, knowledge, and meanings across the digital ecosystem. This results in a continuously refreshed overview of an organization’s assets, identities, connections, risks, and activities. Such a resource provides agents with a shared, near-real-time understanding of the setting they are tasked with securing.
This collective comprehension serves as the foundation of Project Perception's functionality. Rather than constantly re-gathering and reconstructing context from raw signals, agents are equipped with direct, efficient access to the information needed to evaluate risks, prioritize actions, and make informed decisions. By grounding interactions in this comprehensive security context, Project Perception enhances the accuracy and consistency of its reasoning while significantly reducing the time, computational resources, and costs required for large-scale operations.
A multi-model architecture tailored specifically for security needs.
A single model cannot effectively address every security task. A successful cybersecurity strategy entails deploying the most appropriate model for each unique challenge at the right moment.
In the case of Project Perception, the optimal model is identified based on a combination of quality, reliability, latency, and cost. By implementing a multi-model approach, Project Perception continuously matches tasks with the most suitable capabilities, optimizing both effectiveness and economic viability. Given the imperative for continuous security operations, sustainable cost structures are crucial for providing scalable protection.
This methodology is informed by ongoing research, rigorous benchmarking, and evaluations spanning both advanced and specialized models. Our dedicated security researchers consistently examine models against real-world scenarios, allowing for precise alignment of each task with the model that delivers the superior outcome. This strategic approach enables clients to leverage advancements in AI without being locked into a singular model.
Actuators are pivotal for translating insights into actionable measures.
Security professionals do not require an influx of new information; they need practical outcomes.
Thus, actuators form a vital element of the Cyber Stack. Project Perception seamlessly integrates with Microsoft Security products, enabling agents to translate insights into effective actions. Organizations can continually reduce risks rather than merely identify them, thereby aiding defenders in fortifying security while maintaining control over their environments.
Constructed with safety as a top priority.
Each layer of the Cyber Stack is founded on a principle of trust. Project Perception aligns with Microsoft’s Responsible AI principles and incorporates the same security, compliance, governance, and operational frameworks that our clients depend on, ensuring that these capabilities are delivered with the accountability and enterprise readiness expected by customers.
Looking ahead in security.
Cybersecurity has always been a competition between attackers and defenders. AI is altering the dynamics of this contest in terms of speed, scale, and financial implications. Defenders now demand systems that can continually perceive, reason, and act alongside them.
Project Perception is a significant step toward realizing that vision.
For further insights into Microsoft Security solutions, visit our website. Stay updated with expert coverage on security topics by bookmarking our Security blog. Additionally, connect with us on LinkedIn and follow us on X for the latest cybersecurity news and developments.
Other resources:
Hayete Gallot leads Microsoft’s initiatives to ensure that organizations can navigate securely in an AI-driven landscape, overseeing aspects such as identity, threat protection, compliance, and data security on a global scale.


