Project Perception launch

A mysterious silhouette with red binary code projected over the face, set against a dark, moody background.

Microsoft announced Project Perception, an AI-powered service that lets enterprise security teams continuously evaluate and update their organization's security posture through a set of AI agents that can find vulnerabilities, simulate attacks, detect and triage threats, and propose remediations. The service is scheduled to enter public preview on August 3, according to CSO Online's write-up of Microsoft's launch event. Microsoft framed the system as a way to compress workflows that previously took hours of manual effort across multiple specialists into a process measured in minutes, with David Weston, corporate vice president at Microsoft Security, quoted in CSO Online's report.

MAI-Cyber-1-Flash and the MDASH harness

Project Perception takes a multi-model approach: the underlying harness decides which AI model is best suited to a particular task, balancing quality against cost. Microsoft also unveiled its own model, MAI-Cyber-1-Flash, trained specifically to find vulnerabilities in complex codebases. When deployed inside MDASH, Microsoft's multi-model harness for vulnerability research, a combination of MAI-Cyber-1-Flash and GPT 5.4 scored considerably higher on the CyberGym benchmark than Anthropic's Mythos 5 and OpenAI's GPT 5.6-Sol, and did so for nearly half the cost, CSO Online reported. MDASH was originally announced in May.

Red, blue, and green agent workflow

Project Perception draws on Microsoft's threat intelligence, security telemetry, and knowledge of customer environments to assemble a security graph that specialized agents then act on, with red team, blue team, and green team roles executing separate playbooks. In a demonstration, a new threat intelligence report about an actor with indicators of compromise and TTPs triggered Perception to investigate whether the organization was protected; the system dispatched agents to map attacker TTPs to the organization's exposed surface, run a penetration testing agent against identified assets, and prioritize the vulnerabilities most likely to be exploited by that actor. A detection agent then generated custom rules to scan logs for exploitation attempts, while a green posture remediation agent proposed fixes ranging from web application firewall blocks to automatic patch submission, according to CSO Online.

FORGE team and research background

MDASH was built by a new Microsoft internal group called FORGE (Frontier Offensive Research & Generative Exploration), led by Georgia Tech professor Taesoo Kim and composed largely of his current and former PhD students, CSO Online reported. Several FORGE members previously belonged to Team Atlanta, which won the DARPA AI Cyber Challenge (AIxCC), a two-year competition for autonomous systems that secure critical open-source software. Microsoft's own blog post, headlined "Rethinking security for the age of AI," appeared the same day, framing the announcements as part of a broader reset of how the company approaches security in the era of generative AI.

Share this article

FacebookX

4 sources

Sources