"You need agents to fight agents," David Weston, corporate VP for AI security at Microsoft, told an audience during a Microsoft Security launch preview on July 27. The company followed that assertion with a suite of products and programs that tie agentic AI, new cybersecurity models, offensive research teams and external grants into a single public-facing strategy.
Project Perception: Red, Blue, Green agents in an agentic security system
Microsoft introduced Project Perception as a new agentic security system meant to help cyber defenders "continuously identify, evaluate and reduce security risk." Perception coordinates three classes of specialized agents: red agents that identify potential attack paths and vulnerabilities, blue agents that investigate findings and apply security context to determine meaningful risk, and green agents that take corrective action and harden defenses across the environment.
Microsoft framed Perception as leveraging its global signal collection—Hayete Gallot, executive VP at Microsoft Security, said the company sees "about 100 trillion signals a day"—and then organizing those signals into a "security context" for the agents to act on. Gallot warned that applying an agent directly to raw signal data would be "very slow" and yield "terrible results," which the company says Perception avoids by correlating signals before agent invocation.
Microsoft positioned Project Perception as conceptually similar to another vendor product, noting it is "akin to Google’s AI Threat Defense platform, powered by Wiz’s Red, Blue and Green agents," which the company said was released in May 2026. Project Perception will be available in Preview mode for all Microsoft customers from August 3.
MAI-Cyber-1-Flash and MDASH: a Microsoft-made cyber model in a multi-model harness
Microsoft also announced MAI-Cyber-1-Flash, a new generative AI model purpose-built for cybersecurity use cases, particularly software vulnerability analysis. The model was developed within Microsoft AI (MAI) and is based on the internally developed MAI-Thinking-1 reasoning model. Microsoft said it has integrated MAI-Cyber-1-Flash into its multi-model agentic scanning harness, MDASH.
Mustafa Suleyman, CEO at Microsoft AI, stated the system is "further enhanced by GPT-5.4" and said it outperformed competing solutions from Anthropic, OpenAI and Google in CyberGym benchmarking. The announcement cited a 95.95% success rate for "the MAI-Cyber-1-Flash and GPT4.5 enhancement" on the CyberGym benchmark. By comparison, the release listed OpenAI’s GPT-5.5 Cyber at 85.6%, GPT-5.6 Sol at 83.6%, Anthropic’s Mythos at 83.8%, and Google’s Gemini 3.5 Flash Cyber at 83.2%.
Within MDASH, Microsoft said MAI-Cyber-1-Flash handles approximately 90% of queries—identifying and patching software vulnerabilities before verifying fixes—while the more complex 10% are passed to the larger GPT-5.4 model. Suleyman noted that GPT-5.4 is "around ten times larger than MAI-Cyber-1-Flash" and said the two-model collaboration yields stronger performance while "costing roughly 50% less."
Microsoft Security FORGE Lab: DARPA winners, Team Atlanta, and offensive research at scale
Microsoft announced the Microsoft Security Frontier Offensive Research and Generative Exploration (FORGE) Lab, led by Team Atlanta—the group of researchers that won the Defense Advanced Research Projects Agency’s AI Cyber Challenge (AIxCC) at DEFCON in summer 2025—and which Microsoft hired to head the initiative. Taesoo Kim, who led Team Atlanta, will head FORGE.
Kim described the DARPA competition as a "real world AI cyber challenge" that blended cutting‑edge research and practical engineering. He said DARPA’s process pushed teams to "strike the balance between engineering and high‑risk, high‑return research throughout the competition" and that Microsoft provides an environment to translate those advances into production "given its scale across Azure and GitHub." Microsoft framed FORGE's mission as advancing "the frontier of offensive security research and accelerate[ing] the evolution from AI‑assisted vulnerability discovery to autonomous security research," positioning the lab as a bridge from DARPA breakthroughs to enterprise defenses.
External Red Team Alliance (EXTRA): unrestricted university funding and distributed expertise
Microsoft announced the External Red Team Alliance (EXTRA), a two-pronged effort to broaden AI safety research. The first component is an in‑house AI red team distributing what the company described as "unrestricted gifts" to 18 university labs across six continents to support AI safety-related research. Ram Shankar Siva Kumar, Microsoft’s head of the AI red team, wrote that the funding carries "no strings attached" and is not intended to steer research to specific products or outcomes.
Siva Kumar said some of the funded universities will study cybersecurity risks posed by AI systems—how models might be exploited, manipulated or misused—while others will explore how AI can be leveraged to strengthen defenses and enhance cyber operations. The initiative's second component assembles a distributed network of specialized experts for red teaming: researchers, practitioners and regional specialists with knowledge of particular attack methods, languages, cultural nuances or technical fields where Microsoft’s internal teams may not have full coverage.
What this means for technologists, procurement leaders, and adversaries
- Technologists and security teams: Microsoft is betting agentic playbooks and a layered model architecture will allow SOCs to automate routine vulnerability identification and remediation—MAI-Cyber-1-Flash is slated to handle roughly 90% of MDASH queries, with the larger GPT-5.4 addressing harder cases—and Perception promises correlated "security context" built from Microsoft’s signal set.
- Procurement leaders and enterprise buyers: Microsoft is offering Project Perception in Preview on August 3 and is pitching a cost-performance story—Suleyman claimed the dual-model approach delivers stronger performance at "roughly 50% less" cost—claims buyers will likely scrutinize during pilots and previews.
- Adversaries and red-teamers: Microsoft is expanding offensive research capacity via the FORGE Lab and broadening external red-teaming through EXTRA’s university grants and distributed experts. Those moves are presented as efforts to harden defenses and to map novel attack paths before they are exploited.
Microsoft’s July 27 rollout stitches agentic defenses, in-house cyber models, DARPA-era offensive research, and external academic funding into a single public strategy. The immediate test will arrive in early August when Project Perception enters Preview on August 3 and customers can evaluate whether agents—red, blue and green—can operate at the scale Microsoft describes and deliver the performance and cost improvements the company has claimed.




