Skip to main content
All articles

Product Updates

The Brain: giving security agents knowledge of your environment

Cantina 5 min read
The Brain AI Security Security Operations
On this page

The Brain is Cantina’s shared context and memory layer for AI security agents. It connects the people and systems in your environment with operating context and prior investigations.

Security work depends on knowing which device belongs to a user, how a repository connects to production, and what the team established during a previous investigation. We’re launching The Brain to make that knowledge available to Cantina’s agents.

The Brain asset catalog with a selected identity

The Brain’s asset catalog and a selected identity in the demo workspace. Recreated from the supplied screenshot, with text edited for readability.

Investigating an impossible-travel alert

In our demo environment, Microsoft Sentinel and Defender XDR surface an impossible-travel alert after sign-ins appear from locations a person could not realistically move between in the available time. The alert includes the user, locations, IPs and timestamps. A VPN or a change between Wi-Fi and cellular service can account for a location change, so the agent needs to check what happened.

The triage agent starts by pulling the user’s context from The Brain: a finance identity, payment-approver group memberships and one managed, compliant Windows laptop. It then checks live Entra sign-ins and sees that the user’s successful sign-ins came from that device in Stockholm.

Identity, managed device and group context retrieved by the triage agent

The agent retrieves the user’s identity, managed device and group memberships. Edited demo view.

When it checks the risky source IP, The Brain returns another relevant memory: the IP had already been recorded as attacker infrastructure during a prior investigation.

Prior investigation memory for a risky source IP

The Brain retrieves an IP recorded as attacker infrastructure during a prior demo investigation. Edited demo view.

The stored context gives the agent a starting point; the live Entra checks provide evidence about the current activity. In impossible-travel cases where the evidence cannot rule out compromise, the agent escalates by default for human input.

How The Brain works

Knowledge of an environment is distributed across the stack. SIEMs hold events and investigation data. CNAPPs map cloud resources and security posture. CMDBs record ownership and dependencies. Tickets, docs and conversations can explain why a change happened or how a team reached a decision.

The difficult part is connecting their records to the same person or service and carrying relevant knowledge into the next task.

The Brain is a shared context and memory layer. Its current implementation includes identities, cloud assets such as AWS and Vercel, MDM-managed devices, repositories, vulnerabilities and their relationships. Agents can begin with a single entity and discover the people and systems they are connected to.

That knowledge takes two forms. Structured records connect entities through stable identifiers: the repository, the service and its cloud resources. Agentic memory holds context that doesn’t fit neatly into an edge, such as why a team considered a pattern benign or which operational constraint shaped a decision.

Demo security policy knowledge and linked reference documents

An excerpt from the demo workspace’s security policies and linked reference documents. Edited demo view.

The Brain captures high-level knowledge to help agents find their way through an environment, and individual data points when precise values are required. An agent can use that map to identify the source system it should check before acting.

Connecting records

A user has an Okta name, a GitHub username, an AWS IAM role, a Slack username and a hostname in an endpoint console. Service accounts sometimes look like users. People leave teams, but their accounts remain. These records need to be connected to the right person or asset.

Matching is deterministic today. The Brain uses an email address for a user and the natural key for other asset types. Entities are validated as they are extracted. If an investigation encounters an entity that isn’t in The Brain, it is added as inferred. When a stable identifier is missing or unclear, the record stays inferred until it is corrected or merged.

An inferred record lets an agent carry a possible relationship into an investigation while keeping its status visible. Ownership relationships may also need reconciliation when records from different systems disagree.

Agents can write information to The Brain, with that behaviour configured at the agent level. Humans and agents can correct or merge records as more information becomes available, so knowledge captured during an investigation can be used in subsequent work.

Investigating an application

Another captured investigation shows this in application security. Apex, Cantina’s autonomous OffSec agent, begins with a GitHub repository, and The Brain hands over the surrounding topology: its load balancer, database, cache, jobs, Datadog service, other repositories and AWS resources.

Apex can see where request parsing happens, which edge controls sit in front of the service and which connected systems belong in the attack path.

Application topology with 13 connected resources

Apex retrieves the repository and its 13 connected resources across GitHub, AWS and Datadog. Edited demo view.

What we observed in alert triage

In an observational comparison of 40 low-severity Okta alerts, with 20 per workspace and equal counts by alert type, the Brain-enabled workspace averaged 170.8 seconds from alert creation to closure, versus 220.4 seconds in the comparison workspace: 22.5% less time. It also averaged 12.15 tool calls per alert, versus 19. Example traces in the evaluation illustrate how stored context can reduce discovery work: one agent retrieved a user baseline from The Brain, while the other queried identity and device data across more systems.

Average time to close and tool calls per alert

Mean time from alert creation to closure and mean tool calls, based on 20 low-severity Okta alerts per workspace. The Brain-enabled sample used 22.5% less elapsed time and 36.1% fewer calls. Hover for sample size, median and observed range.

Time to close by alert type

Average time from alert creation to closure, grouped by alert type. Sample sizes are shown beside each row.

About the data

The sample contains 20 low-severity alerts from each of two workspaces. The Brain-enabled sample spans September 14–16, 2026; the comparison spans September 11–16. Each workspace has 10 sign-in-location alerts, seven sign-in-time alerts, two MFA-deactivation alerts and one impossible-travel alert. All 40 were closed as benign or false positive without human action.

Elapsed time runs from alert creation to closure, including pickup. The evaluation records each workspace’s own alerts, history and integrations. Two comparison alerts use gpt-5.6-terra; the other 38 use claude-opus-4-8. The source also records 18 Brain read calls in the comparison workspace.

Every alert’s time to close

One point per alert; vertical lines mark medians (191 s comparison, 159.5 s Brain enabled). Points spread vertically only to prevent overlap. Diamonds identify the two comparison alerts using gpt-5.6-terra. Hover for alert type, model and exact time.

Using the same model

This view includes the 18 comparison alerts and 20 Brain-enabled alerts run with claude-opus-4-8.

Among alerts run with claude-opus-4-8, the Brain-enabled sample averaged 22.5% less elapsed time and 27.8% fewer tool calls.

Bars show arithmetic means. For an even number of alerts, the median is the average of the two middle values.

Explore all 40 source rows

All 40 alert records are shown below. Time values are seconds; tokens are output tokens.

Per-alert values underlying the figures
WorkspaceAlertTypeTime (s)ToolsStepsOutput tokensModelOutcome
Brain enabledISS-1272Sign-In Time1077235,455claude-opus-4-8benign
Brain enabledISS-1271Sign-In Time1418266,810claude-opus-4-8benign
Brain enabledISS-1268Sign-In Location1069286,029claude-opus-4-8benign
Brain enabledISS-1267Sign-In Location14111338,533claude-opus-4-8benign
Brain enabledISS-1266Sign-In Time18110318,472claude-opus-4-8benign
Brain enabledISS-1264Sign-In Time14312368,006claude-opus-4-8benign
Brain enabledISS-1262Sign-In Location17511347,628claude-opus-4-8false positive
Brain enabledISS-1261Sign-In Location19213388,925claude-opus-4-8benign
Brain enabledISS-1260Sign-In Location14310307,570claude-opus-4-8benign
Brain enabledISS-1259Sign-In Location258165010,524claude-opus-4-8benign
Brain enabledISS-1257Impossible Travel191133611,502claude-opus-4-8false positive
Brain enabledISS-1256Sign-In Location13711317,351claude-opus-4-8benign
Brain enabledISS-1254Sign-In Time282216414,848claude-opus-4-8benign
Brain enabledISS-1253Sign-In Time14011327,176claude-opus-4-8false positive
Brain enabledISS-1251Sign-In Location16211329,637claude-opus-4-8benign
Brain enabledISS-1250Sign-In Time15012347,333claude-opus-4-8benign
Brain enabledISS-1248Sign-In Location15713358,758claude-opus-4-8benign
Brain enabledISS-1244MFA Deactivated239164217,734claude-opus-4-8benign
Brain enabledISS-1242Sign-In Location173143810,104claude-opus-4-8benign
Brain enabledISS-1239MFA Deactivated198143912,273claude-opus-4-8benign
ComparisonISS-2364Sign-In Time17843938,630gpt-5.6-terrabenign
ComparisonISS-2362Sign-In Location265347511,485gpt-5.6-terrabenign
ComparisonISS-2357Sign-In Time14011348,271claude-opus-4-8benign
ComparisonISS-2356Sign-In Location170133611,064claude-opus-4-8benign
ComparisonISS-2351Sign-In Time14412378,933claude-opus-4-8false positive
ComparisonISS-2350Sign-In Time15613389,578claude-opus-4-8benign
ComparisonISS-2349Sign-In Time15411337,758claude-opus-4-8benign
ComparisonISS-2347Impossible Travel213174914,319claude-opus-4-8false positive
ComparisonISS-2346MFA Deactivated333257522,016claude-opus-4-8benign
ComparisonISS-2343Sign-In Location169133810,820claude-opus-4-8benign
ComparisonISS-2340Sign-In Time201175713,144claude-opus-4-8benign
ComparisonISS-2339Sign-In Time164134210,284claude-opus-4-8benign
ComparisonISS-2330Sign-In Location349267720,920claude-opus-4-8benign
ComparisonISS-2326Sign-In Location18313388,825claude-opus-4-8benign
ComparisonISS-2325Sign-In Location333247316,499claude-opus-4-8benign
ComparisonISS-2321Sign-In Location339246920,633claude-opus-4-8benign
ComparisonISS-2305Sign-In Location217154313,416claude-opus-4-8benign
ComparisonISS-2299Sign-In Location18714409,223claude-opus-4-8benign
ComparisonISS-2298Sign-In Location195174612,477claude-opus-4-8benign
ComparisonISS-2223MFA Deactivated318257322,203claude-opus-4-8benign

Workspace context and controls

All Brain data resides within individual workspaces. Because it brings together identity, infrastructure and investigation context, access to the workspace, agents and underlying integrations forms part of its security boundary.

The Brain draws on connected systems and recorded investigation history. Humans and agents can correct or merge records, while live source checks provide current evidence during an investigation.

Knowledge records support topic locks and review of proposed facts.

See The Brain in your environment

To explore how The Brain can connect your systems and investigation history, get in touch.