Starting August 3, Microsoft will make a security stack available in preview to all customers. The security stack has been named Perception and combines all of the company’s (AI) security tools to provide the most comprehensive view possible, enabling faster responses and more effective threat resolution.
We should view Microsoft Perception primarily as a new way to bring together Microsoft’s security capabilities, which are undoubtedly extensive, in a manner that aligns with the current state of the security landscape. Everything is moving faster and faster, partly due to the role AI plays in the cyberattacks being carried out. To respond effectively to this, more context is needed, but also greater speed. This is only possible if the various components integrate well with one another and it’s clear how everything is interconnected. That’s what the Perception security graph does.

Red, blue, and green agents
Of course, simply aggregating all the telemetry and creating context isn’t enough on its own. After all, the volume of data is still enormous. That’s why Microsoft itself provides multiple agents. Red, blue, and green agents are designed to ensure that vulnerabilities and threats are quickly identified and resolved. Red agents perform offensive actions and can simulate attacks; blue agents handle defensive tasks; and green agents ensure that the identified issues are resolved.
In addition, Microsoft is introducing MDASH within Perception. This is a combination of red and green agents designed to scan repositories for vulnerabilities, assess their severity, and determine which are more critical than others. The green agent that is part of MDASH then ensures that a fix can be applied.
Perception, by the way, is not a new environment within Microsoft that you navigate to. It is a framework that organizations can use from within the Defender environment. It is also possible to get started with it via the CLI.

Multi-model and custom models
It’s also noteworthy that Microsoft has made Perception a multi-model platform. The company made this very clear during the official presentation. This makes sense, since not everyone uses the same models and, more importantly, some models perform better in specific areas than others.
Nevertheless, Microsoft also sees ample opportunity to build its own specific models. For example, the company is announcing MAI-Cyber-1-Flash today. This is a model focused exclusively on finding vulnerabilities in software. It is part of the AI suite offered by Perception and, within that suite, part of MDASH.
While MAI-Cyber-1-Flash may not be a massive model, Microsoft says it performs very well on the well-known CyberGym benchmark. It outperforms many well-known security models, including the legendary Mythos, as you can see below. Note that MAI-Cyber-1-Flash doesn’t do this entirely on its own, but in combination with GPT 5.4. The cyber model handles some tasks entirely on its own, while at other times it must offload tasks to GPT 5.4. It’s important to note here that MAI-Cyber-1-Flash and GPT 5.4 can accomplish this together at 50 percent of the cost of other models.

The concept isn’t new, so is the execution any better?
If you follow the security market, much of what Microsoft is announcing today with Perception won’t be entirely new to you. In fact, this story is more than a little reminiscent of Google Cloud’s partnership with Wiz. It’s essentially the same concept: combining a security graph (the foundation of Wiz and the reason that company was valued at over $30 billion by Alphabet) with Wiz’s three types of agents. Naturally, those agents also share the same color coding, as that’s simply the standard in the security world.
So what Microsoft is announcing today isn’t necessarily new, not even for a hyperscaler. Is it ultimately a better story than that of Google Cloud and Wiz? That’s hard to say at this point, but it certainly could be (provided it’s executed well, of course). After all, no vendor in the world has a larger footprint when it comes to telemetry and software than Microsoft. The company has more than six million business customers worldwide. If it can properly aggregate all the insights and telemetry and provide the right context, that could be extremely valuable.
The bottom line is that Perception is a major step forward for Microsoft Security. We’re very curious to see if that will also be the case for the company’s customers. Will they be significantly better protected starting August 3?
Screenshots on this page were taken during the official presentation of Microsoft Perception