Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

techrepublic+1developer-tech+1techrepublic+1Microsoft on Sunday launched the public preview of Project Perception, an autonomous security framework that deploys specialized AI agents to investigate threats, assess risk, and take corrective action within Microsoft Defender. The system, first announced on July 27 by Microsoft Security, marks a shift from AI-assisted analysis toward coordinated, agent-driven security operations.
Project Perception operates through three classes of AI agents working in continuous loops. Red-team agents identify possible attack paths, blue-team agents investigate findings and determine which represent meaningful risk, and green-team agents take corrective actions to strengthen defenses. Human operators retain control over consequential decisions, though Microsoft has not yet detailed how narrowly each agent can be permissioned.techrepublic+1
The framework is built on what Microsoft calls a "Cyber Stack" comprising six layers: signals and sensors, security context, models, a coordination harness, agents, and actuators that turn decisions into protective changes.windowsforum
Underpinning much of the system is MAI-Cyber-1-Flash, a compact cybersecurity model developed internally by Microsoft and deployed within MDASH, the company's multi-agent vulnerability scanning harness of over 100 specialized agents. The model handles up to 90% of MDASH tasks, with the remaining complex cases escalated to GPT-5.4. Microsoft says this configuration delivers comparable performance at roughly 50% of the cost of its previous setup, which relied entirely on external frontier models.microsoft+4
Microsoft reported that the combined system scored approximately 96% on CyberGym, a UC Berkeley benchmark for evaluating vulnerability detection across real codebases — outperforming Anthropic's Mythos model by about 12 points, according to Microsoft's own metrics. However, as Forbes noted, these figures are self-reported and apply to the full MDASH system rather than the smaller model alone, and independent verification had not appeared on the benchmark's leaderboard as of late July.developer-tech+2
Microsoft has not disclosed simple public pricing, detailed eligibility requirements, or a general-availability date. The preview is delivered inside Microsoft Defender and operates on a consumption-based pricing model through what Microsoft calls Security Compute Units. Organizations with mixed security environments should confirm which telemetry and actions are supported outside Microsoft's ecosystem.futurumgroup+2
The launch arrives as AI-driven attacks intensify. Palo Alto Networks recently reported a single operator using an open-source model to autonomously attack 460 systems, underscoring the arms-race dynamic that Project Perception aims to address.forbes