Microsoft MDASH

Multiple models argue over a suspected bug until one can prove it

Security & Safety Contact
Researched · Published · Reviewed
RECATOOLS Score
7 / 10
Capability
8
Value for money
8.5
Ease of use
5.5
ASEAN readiness
5.5
API quality
6
Founded
2026
HQ
Redmond, Washington, USA
Users
Launched
Developer
Microsoft

Overview

MDASH is Microsoft's multi-model agentic scanning harness for vulnerability discovery. It runs more than a hundred specialised agents across an ensemble of frontier and distilled models, has a separate set of agents debate whether each candidate bug is real, and builds a proof-of-concept before reporting. It scored 88.4% on CyberGym and is in public preview.

Advertisement

Pricing

Pricing shown for reference only. These figures reflect RECATOOLS research as of 1 Aug 2026 and may be out of date or incomplete. This is not financial or purchasing advice — always confirm the current price on the provider’s official website before making any decision.

Free
Free
Public preview — external security teams can run the scanner against their own code

Use cases

Automated vulnerability discovery Code security review Exploitability verification

What you can produce with Microsoft MDASH

  • Scan a codebase with an ensemble of frontier and distilled models rather than one model's judgement
  • Put candidate findings through a debate step so weakly supported bugs are challenged before reporting
  • Run a proof pipeline that attempts to demonstrate exploitability instead of asserting it
  • Cut the false-positive volume that makes most automated scanning output unusable
  • Surface classes of defect that manual review passes over in large, long-lived codebases
  • Run the same scanner Microsoft benchmarked against your own code, through the public preview
Advertisement

ASEAN Perspective

Microsoft MDASH in Southeast Asia

ASEAN-region availability and pricing notes coming soon. Drop the editorial team a note via /contact/ if you can supply local context (Singapore/Malaysia/Indonesia/Thailand/Vietnam).

RECATOOLS Verdict

The design is the interesting part. Most AI code-scanning fails on precision rather than recall, and MDASH is engineered around exactly that — agents that debate each other, then a proof-of-concept requirement before a finding is reported, rather than a bigger model and more prompting. The DARPA Cyber Challenge pedigree behind it is not decoration.

Take the public preview seriously as the thing to act on. An 88.4% CyberGym score is Microsoft's account of Microsoft's tool; running it against your own code is how you find out whether it holds. And note what success costs you: finding more real bugs faster is only a win if there is capacity to fix them.

Independent AI-assisted assessment by RECATOOLS.

What people say

MDASH is Microsoft's answer to the central problem with AI-assisted vulnerability hunting, which is not finding candidate bugs but discarding the ones that are not real. A single model asked to review code produces a long list of plausible-sounding findings, most of which dissolve on inspection, and the triage cost has historically eaten the time saved. MDASH attacks that directly: more than a hundred specialised agents run across an ensemble of frontier and distilled models, a separate set of agents debates whether each finding is genuine, and a final stage constructs a proof-of-concept before anything is reported.

It scored 88.4% on the CyberGym benchmark, ahead of Mythos Preview's 83.1%. The provenance is worth knowing: MDASH came out of a Microsoft team called FORGE, led by Georgia Tech professor Taesoo Kim, several of whose members came from Team Atlanta — the group that won the DARPA AI Cyber Challenge. This is not a repurposed code scanner with a model bolted on.

Microsoft has since put MDASH into public preview, so external security teams can run the same scanner against their own code rather than taking the benchmark on trust. That matters more than any vendor figure, because it is the first route to independent evidence. As of writing, that evidence does not exist yet — most public discussion still restates Microsoft's own account.

Two caveats. Running an ensemble of frontier models over a large codebase and then attempting proofs is computationally expensive, and the published material does not make the economics clear at organisational scale. And the vulnerability-discovery surge documented through 2026 cuts both ways: tools like this are why disclosure counts have climbed steeply, which is a gain for defenders and simultaneously a larger queue for whoever has to ship the fixes. The bottleneck moves rather than disappearing.

Summary of public user & expert reviews, compiled by RECATOOLS.

About this listing

Researched on
Published on
Last reviewed

This entry was compiled from publicly available data including Microsoft MDASH's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with Microsoft MDASH unless explicitly stated.

Data accuracy

Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.

For the latest details, please refer to Microsoft MDASH directly →

Spotted something out of date? Suggest an update →

Advertisement