Armadin
by Armadin
Autonomous offensive security: AI agent swarms that chain your weak spots into proven attack paths before an attacker does
Armadin is an agentic offensive security platform that sends swarms of specialized AI agents against an enterprise's own infrastructure to find and chain vulnerabilities into validated attack paths. It is built for CISOs and red teams at large enterprises and government agencies who want continuous adversary testing in place of a periodic penetration test.
Armadin is an AI-native cybersecurity company founded by Kevin Mandia, who previously founded Mandiant (acquired by Google for $5.4 billion in 2022), with co-founders Travis Lanham (CTO), Evan Peña (Chief Offensive Security Officer) and David Slater (Chief Architect). It emerged from stealth on March 10, 2026 with $189.9 million in combined seed and Series A funding, and on October 1, 2026 announced a $255.5 million Series B co-led by Andreessen Horowitz and Accel at a valuation above $2.5 billion, bringing total funding to $445 million. The platform deploys a swarm of specialized agents that behave like skilled adversaries: they first map internal systems and users, scan assets for weak points in parallel (100 agents can run 100 scans at once), share findings across the swarm, and chain individually low-severity weaknesses into validated kill chains that run from unauthenticated remote code execution at the perimeter through lateral movement to full cloud compromise. Agents operate inside a sandbox, without privileged credentials, and submit actions through a safety model supervised by human experts. Each finding comes with prioritized remediation advice and automated retesting once a fix lands. The company is extending into autonomous remediation through compensating controls, starting with a one-click block via CrowdStrike Falcon MDR, with SentinelOne, Microsoft, WAF integrations and Jira, ServiceNow and Slack ticketing on the roadmap. In one August 2026 engagement, 26,000 agents launched 1,300 attacks across more than 25,000 services and produced 238 findings, 98 of them significant, and 38 validated attack paths. Armadin says it runs in production for Fortune 500 and government customers but names none, and discloses no revenue or pricing. Its closest rival is Horizon3.ai's NodeZero.
A CISO or head of offensive security at a large enterprise or government agency whose annual penetration test no longer keeps pace with how fast AI-assisted attackers can find and chain weaknesses.
Continuous, autonomous attack campaigns that prove which exposures actually chain into a breach, with prioritized fixes and automatic retesting.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing
- Target Market
- CISOs, CIOs, Security Operations Teams, Red Teams, Government Agencies
- Deployment
- Cloud-first
- Founded
- 2025
- Headquarters
- Palo Alto, United States
Key Features
- ✓Agent swarm attack campaigns
Thousands of specialized agents scan assets in parallel and share findings, so coverage of large estates takes hours rather than the weeks a human team needs.
- ✓Kill-chain validation
Chains individually low-severity weaknesses into validated paths from perimeter code execution through lateral movement to cloud compromise, showing real blast radius.
- ✓Supervised safety model
Agents run sandboxed without privileged credentials and submit actions through a safety model overseen by human experts, which reduces the risk of disrupting production.
- ✓Prioritized remediation and retesting
Each finding ships with prioritized remediation advice, and the platform automatically retests once the fix is reported complete to confirm closure.
- ✓Compensating controls via MDR
Deploys temporary blocks at machine speed through CrowdStrike Falcon MDR while permanent fixes are built, with WAF and other integrations planned.
- ✓Emerging-threat notification
A proprietary threat-intelligence pipeline generates proof-of-concept tests and notifies customers about newly relevant threats within 24 hours.
Capabilities
Use Cases
- •Continuous red teaming
Run daily autonomous attack campaigns against production infrastructure instead of waiting for an annual penetration test to surface exploitable paths.
- •Attack-path prioritization
Turn thousands of scanner findings into a short list of validated kill chains so remediation effort goes to exposures that lead to compromise.
- •Machine-speed containment
Push a compensating control through Falcon MDR the moment a validated path is found, buying time while engineering ships a permanent fix.
- •Remediation verification
Automatically retest a closed ticket to confirm the attack path is actually broken, giving audit and board reporting verified evidence.
Ideal For
Best For
- ✓Fortune 500 security teams replacing periodic penetration tests with continuous adversary emulation
- ✓Government and critical-infrastructure organizations that need validated attack paths across large estates
- ✓Exposure-management programs that want low-severity findings correlated into real kill chains
- ✓Security operations teams running CrowdStrike Falcon MDR that want one-click compensating controls
Not Ideal For
- ✗Small and mid-sized companies looking for a published, self-serve price: Armadin sells to large enterprise and government buyers and discloses no pricing
- ✗Buyers who require named reference customers or independent benchmark results before a shortlist, since none have been published yet
- ✗Teams standardized on EDR or MDR tools other than CrowdStrike that need automated remediation today, because SentinelOne and Microsoft support is still on the roadmap
Deployment
Market Analysis
Pros
- ✓Founding team with a proven record in incident response and offensive security (Mandiant)
- ✓Validated attack paths give a much shorter, more actionable list than raw vulnerability counts
- ✓Very well capitalized, with $445M raised, which lowers vendor-viability risk for a multi-year contract
- ✓Remediation loop (compensating controls plus retesting) goes beyond reporting
Cons
- ✗No named customers, revenue or customer count disclosed; analysts note the valuation prices the team and thesis ahead of traction
- ✗All performance figures, including the August 2026 exercise, come from the vendor with no independent verification
- ✗Running autonomous attacks in production raises an unresolved safety question for change-averse environments
- ✗Automated remediation currently integrates only with CrowdStrike Falcon MDR
Pricing
Enterprise
Contact for pricing
- ✓Agentic attack campaigns
- ✓Validated attack paths
- ✓Remediation guidance and retesting
- ✓Compensating controls via CrowdStrike Falcon MDR
Armadin publishes no list pricing and none of its funding coverage disclosed a price or metering unit. Expect a sales-led enterprise contract; ask for a scoped test on your own network, with findings and false positives counted, before committing.
Security & Compliance
Sources
This page was written from 8 sources, 8 on domains other than armadin.com.
- 1.prnewswire.com — armadin raises 255 5 million series b to scale effective aut
- 2.siliconangle.com — armadin nabs 255 5m to detect vulnerabilities with ai agent
- 3.securityweek.com — kevin mandias armadin raises 255 million at 2 5 billion valu
- 4.datafloq.com — armadin raises 255 5m for ai attack swarms what the 2 5b val
- 5.bankinfosecurity.com — armadin targets autonomous remediation 2555m series b a 3301
- 6.helpnetsecurity.com — armadin raises 255 5 million funding
- 7.techcrunch.com — kevin mandias new agent swarm security startup armadin raise
- 8.ballisticventures.com — armadin
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
DeepKeep
AI security platform covering red teaming, an AI firewall, agent attack-surface scanning and runtime controls for coding agents
WitnessAI
Network-layer AI security and governance for employee AI use, models, apps and agents
Ascerta
Enterprise AI management: measure the ROI, cost and adoption of every AI initiative, agent and coding tool
Reco
AI agent security and SaaS security platform that discovers, governs and secures every agent, app and identity