I recently attended Microsoft Security’s Project Perception launch event in San Francisco. The software giant continues to refine its broad cybersecurity platform, offering a diverse set of defensive capabilities across its Entra identity, Defender endpoint, email, and cloud-native application protection suite, Sentinel security operations, Purview data security, and secure service edge network security offerings – all informed by Microsoft’s deep threat intelligence.
Project Perception is a logical next step for Microsoft, given the growing threats posed by the weaponization of frontier AI that aims to exploit both known and undiscovered vulnerabilities at machine speed. It is designed to add depth and breadth to Microsoft’s already well-established AI security portfolio, which includes workload runtime protection, application and copilot governance, prompt injection detection and mitigation, data protection for generative AI usage, and broad security posture management.
This LoneStar Advisory & Research note will unpack what is new with Project Perception, what Microsoft is doing to support its massive global customer base with a newly deployed frontier-class cybersecurity model, and highlight the importance of agentic harnessing and Microsoft’s investment.
What is Project Perception?
Currently in preview, Project Perception is a new Microsoft agentic security system to combat the evolution of AI-assisted to fully automated attacks. By utilizing three classes of agents, Microsoft is effectively comprehending the entire threat lifecycle. To help defenders discern the agent triad, the company has cleverly assigned a color-coding scheme that I liken to the U.S. military DEFCON readiness condition system. Project Perception functions as an orchestration layer with red agents identifying potential attack paths, blue agents investigating and imbuing security context, and green agents taking corrective action and strengthening defense posture.
Project Perception employs a multi-model approach that applies the best resources to balance economics and optimize security outcomes through the power of agentic AI. This best-of-breed AI model deployment strategy by Microsoft is a smart move, providing the flexibility to meet defenders with their current tooling selections while augmenting security operations with a new Microsoft model, MAI-Cyber-1-Flash.
Microsoft Unveils Its First Cybersecurity AI Model
Microsoft has traditionally partnered with AI model providers, but that strategy has changed. With the introduction of the MAI-Cyber-1-Flash, the company has developed a purpose-built, frontier-class model that assists defenders with vulnerability analysis. Included within Microsoft’s MDASH multi-agent vulnerability identification and remediation harness, the MAI model is architected to detect vulnerabilities within expansive codebases and is informed and fine-tuned with the company’s threat intelligence.
It makes logical sense for Microsoft to enter the security model market. The company is the largest software company on the planet, and its corresponding telemetry is immense. Other infrastructure providers, including Cisco, Palo Alto Networks, and Fortinet, have been successful in their model-building and deployment efforts, and Microsoft could be equally successful in its endeavors.
The Importance of Agentic Harnessing
The importance of agentic harnessing cannot be understated, and Microsoft is making big investments in this regard. An agentic harness is the software stack that envelops a large language model to facilitate autonomous operations through execution loops and context management.
Initially, Microsoft’s MDASH harness was developed for internal use, but it is now integrated into Project Perception. At the event, the company shared that the combination of MDASH, MAI-Cyber-1-Flash, and GPT-5.4 is delivering impressive results based on CyberGym cybersecurity benchmarking – including besting Anthropic Mythos 5. That claim is impressive given Anthropic’s groundbreaking work with Project Glasswing and Microsoft’s inclusion as a founding participant.
Final Thoughts
Microsoft continues to refine its security platform, and Project Perception strengthens its capabilities, fighting the weaponization of AI with AI. The company claims that the combination of its newly minted MAI-Cyber-1-Flash model and MDASH harness delivers uncompromised performance at half the cost of leading AI models. That is a compelling value proposition for security operations professionals, and it will be interesting to monitor Microsoft Security’s progress in maturing its efforts over time.


