
Microsoft has introduced Project Perception, a new agentic cybersecurity system designed to coordinate specialised artificial intelligence agents across vulnerability discovery, threat investigation, remediation and enterprise security hardening.
The platform is scheduled to enter public preview on August 3, initially bringing its coordinated multi-agent capabilities to Microsoft Defender. The company plans to extend the system across other parts of its security portfolio.
Project Perception organises agents into three categories. Red agents assess systems from an attacker’s perspective and identify potential weaknesses. Blue agents investigate suspicious activity and support threat detection and response. Green agents focus on remediation, configuration improvements and long-term system hardening.
The agents can exchange findings across different stages of an investigation. For example, a red agent could identify a vulnerable service, a blue agent could determine whether it has been exploited and a green agent could recommend or initiate remediation, depending on the permissions provided by the customer.
Microsoft also introduced MAI-Cyber-1-Flash, its first internally developed AI model focused specifically on cybersecurity. The compact, code-oriented model will operate within MDASH, Microsoft’s multi-model vulnerability-research system comprising more than 100 specialised agents.
Microsoft said the combination of MDASH and MAI-Cyber-1-Flash achieved a score of approximately 96% on the CyberGym vulnerability benchmark. This was 12 percentage points higher than the result attributed to Anthropic’s Mythos system. The company also claimed that the updated configuration reduces operating costs by nearly 50% compared with its existing MDASH offering.
The benchmark result reflects the performance of the complete orchestrated system rather than MAI-Cyber-1-Flash operating independently.
Project Perception uses a multi-model architecture that assigns work according to its complexity, urgency and cost. Routine assignments can be handled by smaller specialised models, while more demanding security investigations can be escalated to frontier models.
Microsoft said human operators will retain control over critical decisions. The platform includes organisational context, security signals, specialised models, orchestration controls and actuators that can convert decisions into defensive actions. Depending on customer permissions, those actions could include changing a security policy, isolating an endpoint or adjusting a system configuration.




