Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

Microsoft Project Perception Brings Agentic Defense to the Cybersecurity Stack

Microsoft Project Perception Brings Agentic Defense to the Cybersecurity Stack
Photo by Laura Musikanski on Pexels

Microsoft has introduced Project Perception, an agentic security system designed to identify risks, investigate threats and coordinate defensive actions at machine speed. The platform combines specialized red, blue and green team agents with shared security context and multiple AI models. A public preview is scheduled to begin on August 3, 2026.

Microsoft is preparing to test a new approach to enterprise defense with Project Perception, an agentic security system intended to continuously discover, evaluate and reduce cyber risk. Rather than presenting another assistant that summarizes alerts, Microsoft is positioning the technology as an operational layer capable of coordinating security decisions and actions across identities, endpoints, applications, data and cloud environments.

Three Types of Agents

Project Perception divides its work among three classes of specialized agents. Red team agents search for potential attack paths before adversaries can use them. Blue team agents investigate activity and determine which findings represent meaningful risk. Green team agents apply corrective actions and strengthen the environment.

These agents operate with access to a shared representation of an organization's assets, identities, relationships and security conditions. This context is intended to reduce the time and computing resources agents would otherwise spend reconstructing the environment from raw alerts.

A Multi-Model Security Architecture

Microsoft is also avoiding dependence on a single AI model. Project Perception uses a multi-model architecture that can select a model according to the required quality, latency, reliability and cost. Its initial vulnerability-management scenario incorporates MAI-Cyber-1-Flash into MDASH, Microsoft's team of software vulnerability agents.

The company says this configuration achieved a 96 percent result on the CyberGym benchmark while reducing costs by almost half compared with the current MDASH configuration. Those results should still be evaluated carefully under real enterprise conditions, where incomplete inventories, unusual software and conflicting business requirements can complicate automated remediation.

Control Must Remain Visible

In my view, the most important part of Project Perception is not its ability to generate findings. It is the proposed connection between analysis and controlled action. Security teams already receive more alerts than they can comfortably process. An agentic platform becomes useful only when it can prioritize accurately, document its reasoning and make reversible changes under clear human supervision.

Organizations evaluating the August 3 public preview should begin with limited permissions and isolated workflows. Every agent action should be logged, high-impact changes should require approval, and rollback procedures should be tested before production use. Project Perception reflects where security platforms are heading, but its long-term value will depend on whether machine-speed response can be delivered without sacrificing accountability.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path