• Home
  • Blog
  • How MDASH Signals the Next Evolution of Microsoft Security
Blog Banners

Microsoft’s latest Digital Defense Report shows how attackers are using AI to automate phishing and intrusion at scale. Defenders now face the challenge of responding faster than ever. Microsoft processes over 100 trillion security signals, analyses 38 million identity risks and blocks 4.5 million new malware files every day. The real issue for most organisations is not a lack of data, but how to turn that data into decisions quickly enough to reduce risk and stay ahead of threats. [Source: Microsoft Digital Defense Report 2025] 

Security teams are under pressure to manage more identities, cloud services and vulnerabilities than ever. Attackers are using AI to accelerate their efforts, making it harder for defenders to keep up.

Microsoft’s answer is not just more automation. It is building systems where specialised AI agents help identify risks, investigate issues and support remediation. MDASH, Microsoft’s multi-agent vulnerability and remediation platform, is a clear example of this approach.

MDASH is more than a technical innovation. It signals the future direction of Microsoft Security, where AI agents work with security professionals to reduce exposure, speed up investigations and build organisational resilience. 

What Is MDASH?

MDASH is Microsoft's multi-agent vulnerability identification and remediation harness designed to find, validate and help address security weaknesses within software codebases at scale.

Calling MDASH a vulnerability scanner misses the scale of what Microsoft has delivered. Traditional tools flag potential weaknesses and generate reports, leaving security teams to spend valuable time validating findings, assessing risk and coordinating remediation. 

MDASH takes a different approach. It brings together specialist AI agents, security models and coordinated workflows to cover vulnerability discovery, validation and remediation support. 

Its capabilities include: 

  • Vulnerability Discovery - MDASH scans large and complex codebases to identify potential weaknesses that could be exploited by attackers. 
  • Vulnerability Validation - One of the main challenges in vulnerability management is separating real risks from false positives. MDASH helps validate findings and reduce noise, so security teams can focus on what matters. 
  • Proof-of-Concept Generation - The platform can help reproduce identified vulnerabilities and demonstrate exploitability, providing additional confidence before remediation efforts begin. 
  • Remediation Support - MDASH supports patch generation and validation, helping organisations move quickly from identification to resolution. 
  • Multi-Agent Security Orchestration - MDASH coordinates over 100 specialised AI agents, each focused on a specific stage of the vulnerability lifecycle. These agents support threat modelling, repository mapping, validation and remediation. 

This orchestration shows Microsoft’s direction: moving from single AI assistants to teams of specialised agents, each driving a specific security outcome. 

Where MDASH Fits Within the Microsoft Security Ecosystem 

The value of MDASH is best understood as part of Microsoft’s security strategy. 

Microsoft is unifying security operations, vulnerability and exposure management, and AI-driven investigation into a connected platform. MDASH strengthens this focus on reducing exposure and driving proactive improvement, not just reacting to incidents. 

This direction complements investments like Microsoft Security Copilot, which helps analysts investigate incidents faster and gain deeper context. 

The bigger picture is not just adding AI to existing tools. Microsoft is building workflows where AI supports the full lifecycle of identifying, understanding and reducing risk. 

The Mythos Benchmark: Why Microsoft's Results Matter 

One of the main reasons MDASH has attracted attention is its performance against the CyberGym benchmark. 

According to Microsoft, MDASH achieved a 96% score on CyberGym and outperformed competing approaches, including Mythos, Gemini and GPT-based systems.

The benchmark matters because it tests how well AI can reason across complex codebases to find real vulnerabilities. It focuses on cybersecurity reasoning, not just general AI performance. 

This is important because strong security outcomes now depend on specialised expertise, not just general-purpose AI.  The results show that purpose-built cybersecurity models deliver stronger results for specialised security tasks. For organisations investing in Microsoft Security, this reinforces the value of security-specific AI models and workflows. 

More broadly, the benchmark reflects a wider trend. The future of AI in security will be shaped by specialised systems that can reason within specific security contexts, not just provide generic answers. 

The Latest Update: Inside MAI-Cyber-1-Flash 

The most recent development for MDASH is the introduction of MAI-Cyber-1-Flash, a specialised cybersecurity model integrated directly into the platform. 

Microsoft states that MAI-Cyber-1-Flash was designed specifically to identify challenging vulnerabilities in complex codebases while operating more efficiently than larger foundation models. According to Microsoft, the model can handle up to 90% of tasks within MDASH, allowing larger and more expensive models to be reserved for the most complex issues.

Microsoft also reports that the combined MDASH and MAI-Cyber-1-Flash solution delivers benchmark-leading performance while reducing costs compared to previous model combinations used within the platform. 

This announcement also reveals Microsoft’s broader AI strategy. The future of agentic security is not about a single, powerful model. Microsoft is building coordinated systems where specialised models, agents and reasoning engines work together across the security workflow. 

This mirrors how effective security teams operate, with specialists contributing expertise at each stage of investigation and remediation. 

What This Means for Your Business 

MDASH signals a broader shift in Microsoft Security. Microsoft is moving from AI-powered assistance to AI-supported security operations, where specialised agents help investigate vulnerabilities, prioritise risk and support remediation. 

For security leaders, the question is not if AI will shape security operations. That shift is already happening. 

The more important questions are: 

  • How prepared is your organisation to adopt AI-assisted security workflows? 
  • Do you have the governance required to oversee AI-driven security activities? 
  • How will you prioritise risk in increasingly complex environments? 
  • Are you maximising the value of your existing Microsoft Security investments? 

The latest updates on MDASH reinforce a key point: technology alone does not deliver resilience. Organisations get the most value from Microsoft Security, Security Copilot, exposure management and MXDR when they combine technology with strong governance, clear processes and experienced oversight. 

MDASH began as a vulnerability-focused innovation, but its impact is broader. It is a clear example of Microsoft’s vision for agentic security, where AI agents and security professionals work together to reduce risk, strengthen resilience and help organisations stay ahead of complex threats. 

Ready to Operationalise Microsoft's Agentic Security Vision? 

CyberOne's MXDR brings together Microsoft Security technologies, expert analysts and continuous threat monitoring. We help organisations reduce cyber risk and prepare for the next generation of AI-assisted security operations. 

Speak to a CyberOne security specialist to discuss your Microsoft Security strategy. 

Share this post

Related Articles