project perception
1 TopicUnified AI Defense: Security Copilot, Project Perception, and MDASH
Executive Summary This triumvirate of tools present a cohesive and unified platform that tells a compelling story: Microsoft Security Copilot as the assistive AI experience and extensible agent platform for security and IT work; Project Perception as the coordinated multi-agent defense system that executes Red, Blue, and Green workflows. MDASH as the specialized multi-model agentic code-scanning harness for discovering, validating, proving, and helping remediate exploitable source-code vulnerabilities. Security Copilot helps analysts and teams ask, summarize, investigate, report, and extend workflows. Project Perception coordinates agents that reason and act across the defense lifecycle. MDASH feeds high-confidence vulnerability findings into broader security workflows, including Project Perception. Simple distinction Security Copilot assists the human. Project Perception coordinates the defense workflow. MDASH finds and validates software vulnerabilities. Platform Description Security Copilot AI that assists security and IT teams through natural-language investigation, summarization, promptbooks, plugins, embedded experiences, and extensible agents across Microsoft Security products. Project Perception AI that acts through coordinated multi-agent defense, using Red, Blue, and Green agents to expose gaps, investigate threats, remediate, and harden with humans in control of critical decisions. MDASH AI that finds and proves code vulnerabilities through a multi-model agentic scanning harness focused on source-code vulnerability discovery, validation, deduplication, proof, prioritization, and fix guidance. Relationship Model Security Copilot, Project Perception, and MDASH should not be positioned as interchangeable AI security tools. They sit at different layers of the security operating model: Security Copilot is the broad assistance and agent platform across Microsoft Security experiences; Project Perception is the coordinated multi-agent defense system for continuous defense; MDASH is the specialized code-security harness whose findings can feed Project Perception workflows. Layer Role How it connects Security Copilot Assistive AI and extensible agent platform Provides the user-facing experience, promptbooks, plugins, reporting, investigation help, and custom/Microsoft-built agents. Project Perception Coordinated multi-agent defense system Coordinates Red, Blue, and Green agents across exposure discovery, investigation, prioritization, remediation, and hardening. MDASH Specialized source-code vulnerability scanner Produces validated vulnerability findings and fix guidance that can inform broader Project Perception workflows. Detailed Comparison Matrix Category Security Copilot Project Perception MDASH Primary purpose Improve defender efficiency through generative AI assistance, embedded experiences, plugins, promptbooks, and agents. Coordinate specialized Red, Blue, and Green agents across the security lifecycle. Discover, validate, prove, prioritize, and help remediate exploitable source-code vulnerabilities. Core operating model Natural-language assistant and extensible agent platform. Coordinated agent playbooks and workflows with shared security context. Multi-model, multi-agent code-scanning pipeline. Primary users SOC analysts, threat hunters, IT admins, data security admins, identity teams, and teams building custom agents. Security operations, exposure management, posture, and incident response teams. AppSec, DevSecOps, product security, engineering, and authorized security teams. Inputs Prompts, incidents, alerts, logs, threat intelligence, plugins, policies, and product context. Security signals, threat intelligence, organizational context, sensors, models, agents, and approved actions. Source repositories or code folders, scan configuration, model outputs, code context, and vulnerability signals. Outputs Summaries, reports, investigations, KQL/query help, recommendations, and agent-generated results. Exposure findings, investigations, triage, detections, remediation/hardening recommendations, and approved actions. HTML/SARIF outputs, severity/confidence details, affected paths, proof details, and remediation suggestions. Strength Breadth and usability across Microsoft Security workflows. End-to-end coordinated defense across agent roles. Depth in software vulnerability discovery and exploitability validation. Best fit Productivity, explanation, reporting, analyst assistance, and workflow extension. Machine-speed coordinated defense for mature security operations. Deep application security and secure engineering workflows. Overlap Analysis Shared AI security reasoning All three use AI for security reasoning, but at different levels. Security Copilot grounds analyst-facing assistance through prompts, plugins, connectors, and organization context. Project Perception coordinates agents across security workflows. MDASH uses a specialized multi-model harness for code vulnerability analysis and proof-oriented validation. Investigation and analyst assistance Security Copilot and Project Perception overlap most clearly around investigations. The difference is the operating model: Security Copilot is optimized for human-assisted investigation; Project Perception is optimized for coordinated multi-agent workflows. Vulnerability discovery and remediation MDASH and Project Perception overlap around vulnerability discovery, exploitability validation, prioritization, and remediation. MDASH focuses on code vulnerabilities, while Project Perception can use MDASH findings with threat intelligence and broader security context to prioritize and drive remediation actions. Agent orchestration Security Copilot agents automate specific security and IT tasks. Project Perception coordinates Red, Blue, and Green defense agents across end-to-end workflows. MDASH orchestrates specialized scanning agents inside the code vulnerability pipeline. Scenario-Based Guidance Scenario Lead with Reason Faster SOC investigation, summarization, reporting, KQL help, and embedded assistance Security Copilot Best when the goal is analyst productivity and guided work inside existing Microsoft Security experiences. Deep source-code vulnerability discovery and exploitability validation MDASH Best when the organization has large code estates and needs richer AppSec analysis than traditional scanners alone. Coordinated Red/Blue/Green defense workflow across security domains Project Perception Best when the organization is ready for agentic defense workflows that identify, investigate, prioritize, and reduce risk. Organization asks whether Project Perception is just Security Copilot Clarify distinction Security Copilot assists; Project Perception coordinates agentic defense workflows. Organization asks whether MDASH is the same as Project Perception Clarify layered relationship MDASH produces code vulnerability findings; Project Perception operationalizes findings in broader defense workflows. Organization wants a complete agentic security story Combination Use Security Copilot for interaction and extensibility, Project Perception for coordinated defense, and MDASH for code vulnerability signals. How to position these AI offerings Lead with Security Copilot for analyst productivity, MDASH for source-code vulnerability discovery, and Project Perception for coordinated agentic defense. Project Perception is not a Security Copilot rebrand. Position the product as a distinct multi-agent defense system that complements Security Copilot. Each of these products complement each other rather than replace any of them. MDASH is not a general SOC platform. In essence, it is a specialized code vulnerability discovery and validation capability. Organization maturity Primary message Recommended offering Early AI/security productivity Use AI to help analysts and IT teams work faster inside the tools they already use. Security Copilot Mature SOC / Defender-centric operations Move from task assistance to coordinated defense workflows with agents that expose, investigate, and harden. Project Perception Strong engineering/AppSec focus Use AI to find, validate, prove, prioritize, and help remediate vulnerabilities in code repositories. MDASH Strategic AI-era security transformation Combine assistive AI, agentic defense, and deep code security. Combination Summary Security Copilot is a great entry point for organizations starting their Frontier journey and how AI can empower their security analysts, investigations and autonomous agent deployments. Project Perception is a coordinated agentic defense system. MDASH is a specialized code-security analysis engine. A simple, concise explanation would be: Copilot assists humans analyzing vast amount of security sources, MDASH discovers software vulnerabilities at machine speed level, and Project Perception coordinates security agents to determine what’s exploitable before an attacker does. Additional insights The newly updated documentation adds a clearer operating model for Project Perception: a continuous cycle to perceive risk, reason across security context, and act with human oversight. It also describes the underlying cyber stack and the role of the purpose-built MAI-Cyber-1-Flash model. Perceive, reason, and act Perceive: Continuously identify emerging risk across endpoints, identities, clouds, applications, and broader security signals. Reason: Apply threat intelligence, organizational context, and security signals to determine which risks are meaningful. Act: Help defenders move from findings to protective action faster, while retaining human judgment and approval for high-impact decisions. The new cyber stack Layer Role in Project Perception Field positioning cue Signals and sensors Provide visibility across endpoints, identities, clouds, applications, data, and AI. Start with the breadth of the digital estate. Security context Connect signals, threat intelligence, and organizational knowledge so agents can reason with operational context. Context turns raw signals into relevant understanding. Models Use a multi-model approach, including specialized cybersecurity reasoning. Select the right model for the task rather than relying on one model. Harness Orchestrate models and agents with the tools and controls required for reliable operation. The harness coordinates workflow, evaluation, and control. Agents Apply Red, Blue, and Green roles across discovery, investigation, response, remediation, and hardening. Agents are specialized roles working as one defense team. Actuators Translate decisions into real-world protective effects, not only recommendations. Actions remain governed and subject to the appropriate oversight. MAI-Cyber-1-Flash and the MDASH relationship MAI-Cyber-1-Flash is a Microsoft purpose-built cybersecurity model optimized for software vulnerability analysis. It operates as one model within the multi-model MDASH system, supporting selected stages of vulnerability discovery and analysis. MAI-Cyber-1-Flash provides specialized reasoning, while MDASH coordinates multiple models and scanning agents, and Project Perception connects those findings to broader defense workflows. Governance and human control Human oversight remains part of the operating model, especially for critical or high-impact actions. Agent activity should be positioned as governed, logged, auditable, and aligned to least-privilege access. Project Perception is designed to inherit enterprise security, governance, privacy, and compliance foundations rather than operate outside them. Appendix A: Project Perception Agent Roles and Relationship to Security Copilot and MDASH Understanding the Red, Blue, and Green Agents Project Perception is built around a coordinated virtual team of specialized AI agents. Just as human security organizations employ Red Teams, Blue Teams, and Security Engineering functions, Project Perception introduces AI agents that perform analogous activities at machine speed while maintaining human oversight for critical decisions. Red Agents Red Agents are responsible for identifying weaknesses before attackers can exploit them. Typical activities: Discover attack paths Identify exposed assets Detect privilege escalation opportunities Analyze risky configurations Correlate exposures across systems Surface previously unknown attack opportunities Business value: Red Agents help organizations move from reactive security to proactive exposure management by continuously searching for conditions that could enable compromise. Blue Agents Blue Agents investigate and validate risk. Once a potential exposure or threat is identified, Blue Agents determine whether it represents a meaningful security concern. Typical activities: Analyze alerts and incidents Correlate telemetry Validate exploitability Assess likelihood of attack Prioritize findings Evaluate business impact Generate investigative conclusions Business value: Blue Agents reduce alert fatigue and help security teams focus on the threats and vulnerabilities that present the highest operational risk. Green Agents Green Agents focus on remediation and hardening. After a risk has been identified and validated, Green Agents help eliminate or reduce that risk. Typical activities: Recommend fixes Validate remediation strategies Propose configuration changes Reduce attack surface Improve security posture Coordinate hardening activities Track remediation progress Business value: Green Agents help close the gap between identifying a problem and fixing it, accelerating risk reduction across the environment. Overlap with Security Copilot Security Copilot and Project Perception share some capabilities but are optimized for different operating models. Security Copilot is fundamentally an analyst-facing experience whose primary objective is to make humans more effective. Incident investigation Threat hunting Alert analysis Report generation Threat intelligence research Security summarization Security operations assistance Workflow automation through Security Copilot agents Positioning statement Security Copilot helps security professionals perform their jobs faster and more effectively. Area Security Copilot Project Perception agents Positioning Red overlap Assists analysts in understanding exposure data. Red Agents proactively discover exposures and attack opportunities. Security Copilot explains the exposure; Red Agents discover the exposure. Blue overlap Helps analysts investigate incidents and alerts. Blue Agents investigate as part of coordinated defense workflows. Security Copilot helps analysts investigate; Blue Agents investigate as part of the defense system. Green overlap Recommends remediation actions and implementation guidance. Green Agents coordinate remediation and hardening activities. Security Copilot recommends fixes; Green Agents drive remediation activities. Overlap with MDASH MDASH differs significantly from Security Copilot because it is focused specifically on software and source-code security. Its mission is vulnerability discovery, exploitability validation, and remediation guidance rather than general security operations. Area MDASH Project Perception agents Positioning Red overlap Identifies software weaknesses in source code. Red Agents evaluate broader attack surface across identity, endpoint, cloud, network, applications, and configuration weaknesses. MDASH identifies software weaknesses; Red Agents identify security weaknesses across the environment. Blue overlap Validates vulnerabilities and exploitability from a software perspective. Blue Agents validate operational risk using endpoint telemetry, identity exposure, threat intelligence, business impact, and attack paths. MDASH validates vulnerabilities; Blue Agents validate operational risk. Green overlap Provides code-level remediation guidance. Green Agents focus on broader environmental remediation and hardening. MDASH fixes code; Green Agents reduce organizational risk. Capability Comparison Matrix Capability Security Copilot Red Agents Blue Agents Green Agents MDASH Natural language interaction Primary No No No Limited Analyst assistance Primary No Limited Limited No Exposure discovery Limited Primary Limited No Code-focused Attack path analysis Limited Primary Yes No Limited Vulnerability discovery Limited Limited Limited No Primary Incident investigation Yes Limited Primary No Limited Alert triage Yes No Primary No No Risk prioritization Yes Limited Primary Limited Yes Exploitability validation Limited Limited Yes Limited Primary Remediation guidance Yes No Limited Primary Yes Code fix recommendations Limited No No Limited Primary Security hardening Limited No Limited Primary Limited Multi-agent orchestration Limited Yes Yes Yes Internal scanning agents End-to-end security lifecycle coverage Partial Partial Partial Partial No Final Takeaway Simple explanation In simple terms: Security Copilot assists humans. MDASH discovers software vulnerabilities. Project Perception coordinates security agent's activities and actions. Within Project Perception, Red Agents identify weaknesses, Blue Agents determine what matters, and Green Agents reduce risk. Technical Resources Getting started with Project Perception Project Perception FAQ Codename MDASH Overview Introducing MAI-Cyber-1-Flash inside MDASH Getting started with Security Copilot Security Copilot is now included for Microsoft 365 E5 and E7 organizations The AI Strategy Roadmap: Five drivers of successful AI transformation The AI Strategy Roadmap: How organizations are achieving Frontier Transformation (pdf)