Microsoft Corporation

09/08/2026 | Press release | Distributed by Public on 09/08/2026 16:00

Codename MDASH brings agentic AI cybersecurity to the US government

AI is transforming everything from how doctors care for patients to how products are manufactured. At the same time, threat actors are attempting to leverage AI capabilities to hunt for weaknesses in the software behind critical missions. Today, Microsoft is helping shift the advantage to defenders by equipping the US government and authorized partners with advanced AI tools to proactively identify and address cyberthreats. Microsoft's multi-model agentic scanning system (codename MDASH), designed specifically for finding security flaws in software, has deployed to Microsoft Azure Government and with preview access available to select US government customers and authorized partners.

For government, the significance is straightforward. The software weaknesses that put agency missions at risk are rarely the obvious ones. They are subtle problems that only become visible when you look across an entire software supply chain at once, and they are precisely what a well-resourced cyberattacker will be looking to exploit. Codename MDASH was built specifically to find those kinds of vulnerabilities, and to help find them first.

Defending the nation's critical systems from an increasingly sophisticated cyberthreat landscape is a shared mission, and Microsoft is committed to bringing the most advanced security capabilities to US government agencies, building on its longstanding partnership with federal, state, and local government customers.

How codename MDASH works: Finding flaws faster

Most traditional security scanning tools work by looking for known patterns, the software equivalent of checking for a list of common mistakes. They are fast but quickly become difficult to maintain at high quality as the number of patterns to scan for can number in the thousands. This approach can miss more complex flaws that could matter most, and in the process generate so many uncertain results that developers and security teams often spend more time sifting out the false positives than fixing real issues. Codename MDASH takes a fundamentally different approach by working as an agentic code scanner that finds and validates exploitable vulnerabilities in source code. It reads and reasons about software the way an expert security researcher would, rationalizing the codebase and following how information moves through a program to work out whether a weakness could actually be exploited by a cyberattacker.

Codename MDASH works by putting more than 100 specialized AI agents, leveraging a variety of models, to work on the same body of code, each trained to recognize a different category of weakness. Their findings are then handed to a second group of agents whose job is to argue the case, for and against, whether each suspected flaw is genuinely reachable and genuinely dangerous. The harness also saves time for defenders by merging and deduplicating results, and where possible the system demonstrates the flaw rather than merely asserting it. What reaches the security team at the end is a more comprehensive, refined, and prioritized list of vulnerabilities that can be assessed and acted on, consistently finding strong signals in the noise.

This multi-model, multi-step agentic approach is the key factor in how codename MDASH scored a 96.55 on the public CyberGym benchmark of real-world vulnerabilities and has produced similar results on first-party code validated against Microsoft's historical vulnerability cases.

Built to keep getting better: The advantage of a multi-model approach

The key differentiator of codename MDASH is its harness design, a system that directs and coordinates the use of whichever models are best for a specific task. This allows for more robust analysis, increased cost effectiveness, and the flexibility to rapidly adopt new models. Multiple models provide independent analysis, because disagreement between models is useful information in its own right: when one AI flags a problem and another cannot argue it away, or when two models agree out of the gate, confidence in the finding rises.

This matters more than it might first appear. AI models improve at a rapid pace, and a security tool tied to one model is only ever as good as that model's last release. Because codename MDASH is multi-model by design, adopting newer, better models as they arrive doesn't require going back to the drawing board, and everything an agency has already invested in downstream of the system carries forward. The models will keep changing. The harness stays the same, and for the customer the experience remains consistent in their existing Microsoft security products.

This design also helps control costs. Microsoft's own MAI model family is designed to make this work affordable at scale, and our newest addition is expected to cut the cost of an individual scan roughly in half. There is far more code in the world than can currently be reviewed at this level of depth, so agencies are ranking their software by mission importance and working steadily down the list. Every reduction in cost moves that line closer to the goal of 100% code coverage without additional budget cycles.

Azure Government: A secure home for sensitive work

The source code behind a mission system is a critical element of national security systems that requires additional levels of assurance, especially when dealing with vulnerability analysis. Azure Government provides a separate, isolated cloud operated by screened US persons and built to meet the compliance obligations that federal, national security, and state and local government customers carry, including FedRAMP High authorization and Department of War accreditation for controlled and mission-critical workloads. Codename MDASH is available in Azure Government as a feature of Microsoft Defender that works with models available within the FedRAMP High-authorized Microsoft Foundry service. This allows an agency's source code and everything the system learns about it to remain within a boundary already approved for handling of that data.

A warning worth heeding

AI offers tremendous capabilities for interacting with software that can cut both ways. An AI system capable enough to find a vulnerability in a defender's software is capable enough to help a threat actor find one to exploit. Threat actors are investing in AI capabilities, and the only durable advantage available to defenders is time -the gap between when a weakness can be found and patched and before someone else finds it.

The good news is that agencies do not have to wait to act. Microsoft has been using codename MDASH on its own software for months, and the US government is not far behind, with customers across national security and civilian agencies already exploring its capabilities. If your organization owns software a mission depends on, the question is no longer whether to examine it with a system like this. It is how quickly you can work through the list.

For more information on how to access codename MDASH in your tenant contact your Microsoft account team about MDASH in Azure Government.

Microsoft Corporation published this content on September 08, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 08, 2026 at 22:00 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]