Project Perception is described as an 'agentic security system' that integrates signals, context, models, and specialized agents into a continuously learning defense system. Its core consists of three types of agents: Red Team agents identify potential intrusion paths before attackers exploit them; Blue Team agents investigate, reason about context, and determine meaningful risks; Green Team agents take corrective actions and strengthen defenses. The three work together in a closed loop, continuously discovering, assessing, and improving the security posture.
The underlying system is a new 'Cyber Stack,' starting from the signal and sensor layer, moving up through the Security Context layer, model layer, orchestration layer (Harness), agent layer, and execution layer. Microsoft particularly emphasizes the role of Security Context: it transforms Microsoft's visibility, threat intelligence, and security expertise into a near-real-time representation of assets, identities, relationships, risks, and activities that agents can directly use, thereby improving reasoning accuracy and reducing computational costs.