HomeMalware & ThreatsArmadin Secures $255.5 Million Series B for Autonomous Remediation Efforts

Armadin Secures $255.5 Million Series B for Autonomous Remediation Efforts

Published on

spot_img

Company Plans to Extend Compensating Controls Across MDR and WAF Platforms

A notable development in the cybersecurity sector has emerged, with startup Armadin announcing significant funding aimed at enhancing its defensive capabilities against evolving digital threats. The company, co-founded by industry leader Kevin Mandia, successfully secured $255.5 million in Series B funding, reaching a valuation of $2.5 billion. This financial boost, led by venture capital firms Andreessen Horowitz and Accel, is intended to strengthen Armadin’s ability to deliver rapid, near-real-time defenses against critical vulnerabilities and emerging cyber threats.

Evan Pena, co-founder and Chief Offensive Security Officer of Armadin, explained that the funding will be pivotal in the integration of autonomous remediation features with managed detection and response (MDR) providers, as well as the establishment of compensating controls, including web application firewalls (WAF). This forward-thinking approach aims to address the increasing threat level posed by AI-powered attacks, which have become a growing concern within the cybersecurity landscape.

Pena emphasized the urgency of the situation, stating, "We need this capital to truly scale what is needed in the moment." The cybersecurity environment is fraught with state-sponsored adversaries and insider threats, presenting challenges for customers across the industry. Armadin’s strategic goals include scaling operations to meet these threats head-on.

At the helm of Armadin is Mandia, a seasoned veteran with over two decades of experience in threat intelligence and incident response. His journey began with Mandiant, a company he founded and later sold to FireEye in 2013. After serving as FireEye’s CEO, Mandia orchestrated a series of lucrative transactions that included selling FireEye’s product portfolio to Symphony Technology Group for $1.2 billion and subsequently selling its services business, rebranded as Mandiant, to Google for $5.4 billion in 2022. Mandia departed Google in 2024, paving the way for his new venture with Armadin.

How Compensating Controls Can Block Exploits

A central focus for Armadin is the development of compensating controls, designed as stopgap measures that can be implemented at machine speed to fend off cyber exploits while organizations work on permanent solutions. According to Pena, necessary fixes can often take days or even weeks to fully implement.

The initial step in this plan is the integration with CrowdStrike’s Falcon MDR platform. This configuration allows users to implement a block rule with a single click, effectively halting a cyber kill chain in its tracks. Armadin has expressed intentions to broaden this integration to include other platforms such as SentinelOne and Microsoft, aiming to enhance overall responsiveness to threats.

Pena noted the practical challenges of timely responses in the cybersecurity space. "It generally takes longer than five minutes; it could take days. What can you do in the meantime to prevent that from happening?" This question underscores the importance of Armadin’s immediate measures to protect clients while longer-term fixes are underway.

Choosing to start with MDR solutions was a strategic decision, as managed detection and response tends to be less disruptive. The integration of AI can facilitate the creation of specific block rules tailored to counteract adversarial activities on endpoints, particularly concerning issues like remote code execution. Following this, plans to integrate with web application firewalls intend to protect against application-layer attacks, including SQL injection.

"Adding different compensating controls at various layers of the network stack or OSI model is crucial for comprehensive protection," Pena articulated, highlighting the multifaceted nature of cybersecurity defenses.

However, developing compensating controls for WAFs poses unique challenges, particularly in ensuring that legitimate user activities are not mistakenly blocked. Armadin is working closely with current customers who offer development and staging environments for rigorous testing and iteration. In contrast, monitoring activities through the Falcon dashboard minimizes the risks associated with false positives in managed detection and response scenarios.

Pena candidly observed, "It’s not a silver bullet. We bypass WAFs all the time, but it will definitely help for a small period of time before it gets bypassed again."

Addressing Customer Vulnerabilities

The recent investment will also be allocated toward enhancing integration capabilities for ticketing and remediation tracking, extending beyond merely using Jira and ServiceNow. Armadin aims to streamline its processes to improve the ways in which emerging threats are monitored and managed. Enhancements include notifications via the platform, alongside integrations with chat tools like Slack, ensuring that clients receive timely updates.

"We don’t want to just tell you where you’re lacking; we want to inform you how to fix it," Pena stated. This philosophy will guide the integration of features that enable remediation tickets to automatically trigger retests to verify successful fixes.

Moreover, the investment will bolster Armadin’s internal threat intelligence team, dedicated to researching how AI can generate proofs of concept for new vulnerabilities. This effort aims to create a proprietary intelligence pipeline capable of rapidly identifying which clients are at risk from emerging threats, such as the recent vulnerabilities identified in Citrix NetScaler, and delivering actionable notifications within a short time frame.

Pena underscored the efficiency that AI brings to the process: "We built it so fast because we’re able to scale with AI." He further noted that the traditional methods were time-consuming, as they had built their knowledge based on years of manual effort.

Success metrics for this Series B round will be centered on revenue growth, which is expected to correlate with increases in headcount. Armadin will rigorously monitor the number of new integrations developed, the volume of attack simulations executed, the number of agents deployed, inference costs, and overall cost of goods sold. The company’s overarching aim is to enhance operational efficiency while simultaneously lowering costs.

Pena concluded with a cautionary note about the industry landscape: "Brace for impact, and I say that very genuinely because what we’re seeing in the industry, what we’re discovering even at Armadin, reflects the capabilities of adversaries who can do the same." With fluctuating threats being ever-present, the moment to act is urgent, underscoring the critical nature of Armadin’s mission in cybersecurity.

Source link

Latest articles

Shadow AI and the Permissions Dilemma: What to Consider Before Granting Access to AI

The Rise of AI and the Urgent Need for Caution AI tools have transitioned from...

Cyber Briefing – 2026.10.02 – CyberMaterial

In a rapidly evolving digital landscape, several key issues related to cybersecurity have emerged,...

Sony PS5 Relapse Jailbreak Exploit Utilizes JSC Memory Corruption and Kernel UAF

A recent development in the realm of gaming technology has surfaced with the release...

More like this

Shadow AI and the Permissions Dilemma: What to Consider Before Granting Access to AI

The Rise of AI and the Urgent Need for Caution AI tools have transitioned from...

Cyber Briefing – 2026.10.02 – CyberMaterial

In a rapidly evolving digital landscape, several key issues related to cybersecurity have emerged,...