In an era where AI can write exploits and launch attacks at machine speed, traditional security tools designed for human speed are gradually failing to keep up with the speed of threats. Microsoft believes it has found a solution that matches the pace of this new attack, and calls it “Project Perception.”

Microsoft hopes “Project Perception” can use AI to intercept hackers in time before they launch attacks
The core of “Project Perception” is an intelligent security system driven by AI, which can think, reason and react at the same pace as modern attackers. The purpose is not to stack more alerts on security teams, but to enable AI to continuously monitor, understand and act across an organization’s digital environment, from identities to devices to cloud resources.
The system is operated by three AI agents to form an automated and continuous learning safety loop. The first is the red team agent, which actively searches for weaknesses in the system and identifies problems before attackers find them. The blue team agent then conducts an investigation to determine which vulnerabilities are real risks that need to be prioritized. Finally, the green team agent made repairs and improvements. The three form a continuously iterative cycle, and the final decision-making is still in the hands of humans.

Microsoft believes that their biggest advantage is visibility. With its broad presence across identity management, devices, applications, data and the cloud, Microsoft can gain a holistic view across systems and take direct action based on the signals it observes. In addition, Microsoft adopts a multi-model architecture so that different tasks are handled by the most suitable AI model, rather than relying on a single model to handle all situations, improving accuracy and efficiency. Underpinning all this is a new network security overlay proposed by Microsoft. It transforms a large amount of raw signals into contextual information, which is then handed over to AI models and agents for reasoning and action. This design moves away from the pursuit of “more alerts is better” and instead focuses on providing insights that truly enable defenders to take action.

One of the early efforts is MAI‑Cyber‑1‑Flash, a purpose-built model built by Microsoft that is now integrated into its vulnerability management tool MDASH. Microsoft said the model achieved a score of 96% in the CyberGym benchmark, 12 points higher than Mythos, while costing almost half, demonstrating its advantages in performance and efficiency.

Project Perception will be available for public preview on August 3rd. Microsoft emphasized that this system has been designed to follow its “responsible artificial intelligence” principles from the beginning. Cybersecurity has always been a cat-and-mouse race, and now that both sides have AI, the real difference is who can master and use the technology faster and more efficiently.
Source: KOCPC Chinese