Microsoft unveils multi-model agentic cyber stack for security operations


MDASH, previously announced in May, was built by a new Microsoft internal team called FORGE (Frontier Offensive Research & Generative Exploration) that’s led by Georgia Tech professor Taesoo Kim and consists of many of his current and former PhD students. Several of the Microsoft Security FORGE members were previous members of Team Atlanta, which won the DARPA AI Cyber Challenge (AIxCC), a two-year competition for developing autonomous AI systems capable of securing critical open-source software.

A team of specialized agents

Project Perception combines Microsoft’s extensive threat intelligence, security telemetry, and knowledge about customer environments to create a complex security graph. This knowledge is then leveraged by a series of specialized agents — red team, blue team, and green team — that execute specialized playbooks to achieve the desired tasks.

During its launch event, Microsoft demonstrated a case where a new threat intelligence report comes in about a new threat actor, complete with some indicators of compromise and TTPs. A human security analyst then tasks Perception to investigate whether their organization is protected against this threat group and the system automatically distributes tasks to the needed agents with the corresponding playbooks.

Leave a Reply

Your email address will not be published. Required fields are marked *