Microsoft's MDASH Scanner Unveiled on Azure Government
Microsoft has rolled out its AI-powered MDASH security scanner to Azure Government, providing select US government customers and authorized partners with preview access to a technology designed to identify and validate exploitable vulnerabilities in software.
The company claims that traditional pattern-based security scanning tools may miss complex software vulnerabilities, which MDASH can uncover using over 100 specialized AI agents and multiple AI models to analyze the same codebase.
MDASH works as an agentic code scanner within Microsoft Defender, analyzing source code to determine whether suspected vulnerabilities are reachable and exploitable. Unlike traditional scanning tools, it uses AI agents to identify specific categories of software weaknesses and consolidates duplicate findings.
According to Steve Faehl, Microsoft's chief technology officer for US Public Sector, MDASH can 'agentically do things now to rationalize data that we weren’t able to' and doesn't put as much burden on the end user. He also mentioned that using multiple models provides independent assessments of potential vulnerabilities.
Microsoft said the system also demonstrates that a vulnerability can be exploited rather than simply flagging a potential weakness, providing security teams with a more refined and prioritized set of vulnerabilities to investigate and remediate.