Event details
David Weston leads Agentic Security at Microsoft, where he and his team build the AI models, autonomous agents, and evaluation systems redefining how defenders operate. At Microsoft since the Windows 7 era, he has worked across exploit mitigation design, malware analysis, APT research, and led security engineering for Windows, Xbox, Azure OS, and Microsoft's Offensive Security Research & Engineering group. His current work is leading teams training frontier security models, agentic security systems for defenders, and pushing AI-driven vulnerability discovery through Microsoft's Multi-Model Agentic Scanning Harness (MDASH). A longtime member of the research community and former CISA technical advisor, David is a regular presenter at BlueHat, Black Hat, and DEF CON.
Key areas Dave and his team can discuss:
- The vision behind Project Perception
- How AI is changing the economics of cyber offense and defense
- Lessons learned from building MDASH and Microsoft's AI security initiatives
- Security-first AI development and deployment
- What's next for defenders as agentic systems become mainstream
This will be a TEXT-BASED AMA, so ask your questions in the comment section down below and David and team will be answering via comment replies during the live hour!
16 Comments
- Sudhir447Copper Contributor
Speaker Background: David Weston leads Agentic Security at Microsoft and works on exploit mitigation and Al security systems like MDASH
- TrevorRusher
Community Manager
What is MAI-Cyber-1-Flash model and how does it work with codename MDASH?
- David_Weston
Microsoft
MAI-Cyber-1-Flash is Microsoft's first AI model built specifically for security. Rather than being a general-purpose model, it's designed to tackle security tasks quickly, efficiently, and at the scale organizations need, while helping reduce the cost of running those workloads.
The model combines Microsoft's decades of security expertise with our latest advances in AI. It's one of the technologies powering codename MDASH, Microsoft's multi-model agentic scanning system. In practice, that means it can help analyze large codebases, identify potential vulnerabilities, and validate findings more efficiently. The goal is to help security teams uncover and prioritize real risks faster, while making advanced security analysis more accessible and cost effective.
Microsoft has positioned MDASH and multi-model agentic scanning as a way to improve vulnerability discovery while reducing cost. however, attackers can also use agentic systems to scale vulnerability research and exploit development. In that environment, what durable defensive advantage does Microsoft believe it can maintain: model quality, telemetry, platform visibility, remediation speed, or something else?
- TrevorRusher
Community Manager
How are Project Perception and codename MDASH related?
- David_Weston
Microsoft
Codename MDASH was our first step toward agentic security. It introduced specialized AI agents and models that can help security teams find, validate, and address vulnerabilities more effectively. Now we're bringing those capabilities into Project Perception. Instead of stopping at vulnerability discovery, MDASH findings become part of a broader, coordinated security workflow. Project Perception can combine those findings with threat intelligence and other security signals to better understand which vulnerabilities are actually exploitable, prioritize the risks that matter most, and help drive remediation. The result is a more connected approach where discovering, evaluating, and addressing risk all work together as part of a continuous feedback loop.
- TrevorRusher
Community Manager
To get things rolling, from our FAQ page: What makes Project Perception different from traditional security tools?
- David_Weston
Microsoft
Project Perception is based on a simple idea: effective defense requires continuously understanding how an attacker sees the world, how a defender evaluates risk, and how protections are improved over time.
- David_Weston
Microsoft
Red team agents help you find weaknesses before attackers do. They continuously look for exposed assets, map potential attack paths, and test applications for vulnerabilities. Think of them as always-on security researchers and penetration testers, proactively identifying risks before they can be exploited.
Blue team agents help you understand what matters most. They investigate suspicious activity, connect signals across your environment, analyze threat intelligence, improve detections, and help security teams sort through alerts. Their job is to separate the noise from the threats that require action.
Green team agents help strengthen your defenses. They identify security gaps, recommend improvements, and help organizations continuously improve their security posture so they're better protected against future attacks.
- TrevorRusher
Community Manager
While you are thinking of questions, you can check out our most recent Project Perception blog here: Rethinking security for the age of AI - The Official Microsoft Blog 😄
Will you sent us a teams meeting link?
- TrevorRusher
Community Manager
This AMA is completely text-based, so David will be responding to questions down here in this comment section :)
- TrevorRusher
Community Manager
Hi all!
The session will begin soon. Please ask your questions down here in this chat for David to answer. Thanks!
- stevlarsCopper Contributor
When will Security Copilot finish rolling out to E5 licensed organizations as described in
https://learn.microsoft.com/en-us/copilot/security/security-copilot-inclusion and
https://learn.microsoft.com/en-us/copilot/security/auto-provisioning-security-copilot?
- HilarySolan
Microsoft
Security Copilot inclusion for eligible Microsoft 365 E5 and E7 customers has been rolling out in phases, and onboarding timelines can vary by tenant. Customers who have questions about their organization's status or rollout timing should contact their Microsoft account team or sales representative for the most up-to-date, personalized information
- TrevorRusher
Community Manager
Hey everyone! Excited to share this event with you tomorrow. Reminder that David and team will be answering questions live down here in this comment section from 8AM - 9AM PST tomorrow, so please submit any questions you have before then or during that time window.
Thanks!