Microsoft · Agentic security
MDASH
Governed intelligence profile for MDASH
First observed 2026-08-27 · Last verified 2026-08-27 ·FRESH · ASI-1.0 · ASI-TAXONOMY-1.1
Lifecycle
UNKNOWN — no evidence-backed lifecycle event recorded.
Agents
UNKNOWN — no named agent is established by current evidence.
Autonomy and control
UNKNOWN — autonomy facets have not been established.
MDASH uses AI confidence and severity for triage while directing uncertain high-severity findings to human investigation before action.
AFFIRMED
The MDASH portal view surfaces only the most recent 90 days of scan activity.
AFFIRMED
Architecture
MDASH accepts Defender CLI and connector-triggered remote scans and labels their origin for provenance.
AFFIRMEDCapabilities
Vulnerability Validation
Codename MDASH is a private-preview agentic code scanner that surfaces code-level weaknesses across connected repositories.
AFFIRMEDPrivate preview; repository connector prerequisites apply.Capability evidence
- Vendor documentation
- HIGH
- Public demonstration
- NONE_FOUND
- Independent validation
- NONE_FOUND
- Production effectiveness
- UNKNOWN
ASI-1.0: Rows represent evidence categories; assertion support confidence is intentionally not rendered beside the capability name.
Assertion support
HIGH under ASI-1.0:HIGH for quote-to-assertion support; truth not independently confirmed
Remediation
MDASH exports validated findings to CSV for existing remediation workflows.
AFFIRMEDExport transfers findings; it does not establish automated remediation.Capability evidence
- Vendor documentation
- HIGH
- Public demonstration
- NONE_FOUND
- Independent validation
- NONE_FOUND
- Production effectiveness
- UNKNOWN
ASI-1.0: Rows represent evidence categories; assertion support confidence is intentionally not rendered beside the capability name.
Assertion support
HIGH under ASI-1.0:HIGH for quote-to-assertion support; truth not independently confirmed
Evidence conflicts
No open conflict is recorded for this system.
Recent changes
CAPABILITY_ADDITION
Codename MDASH is a private-preview agentic code scanner that surfaces code-level weaknesses across connected repositories.
ARCHITECTUREEVALUATIONPROCUREMENTCONTROL_CHANGE
MDASH uses AI confidence and severity for triage while directing uncertain high-severity findings to human investigation before action.
AUTHORIZATIONEVALUATIONRISKARCHITECTURE_CHANGE
MDASH accepts Defender CLI and connector-triggered remote scans and labels their origin for provenance.
ARCHITECTUREEVALUATIONOPERATIONSCAPABILITY_ADDITION
MDASH exports validated findings to CSV for existing remediation workflows.
OPERATIONSPROCUREMENTAVAILABILITY_LIFECYCLE_CHANGE
MDASH is in private preview and its documentation/access path requires authorization.
DEPLOYMENTEVALUATIONPROCUREMENTCONTROL_CHANGE
The MDASH portal view surfaces only the most recent 90 days of scan activity.
EVALUATIONOPERATIONSRISKUnknowns
Any evidence-panel row marked UNKNOWN is not a negative capability claim. Any NONE_FOUND row means the current governed corpus contains no qualifying evidence.
Sources
- SRC-MS-MDASH: Microsoft — MDASH initiative
Compare claims with evidence categories