The Brain is Cantina’s shared context and memory layer for AI security agents. It connects the people and systems in your environment with operating context and prior investigations.
Security work depends on knowing which device belongs to a user, how a repository connects to production, and what the team established during a previous investigation. We’re launching The Brain to make that knowledge available to Cantina’s agents.

The Brain’s asset catalog and a selected identity in the demo workspace. Recreated from the supplied screenshot, with text edited for readability.
Investigating an impossible-travel alert
In our demo environment, Microsoft Sentinel and Defender XDR surface an impossible-travel alert after sign-ins appear from locations a person could not realistically move between in the available time. The alert includes the user, locations, IPs and timestamps. A VPN or a change between Wi-Fi and cellular service can account for a location change, so the agent needs to check what happened.
The triage agent starts by pulling the user’s context from The Brain: a finance identity, payment-approver group memberships and one managed, compliant Windows laptop. It then checks live Entra sign-ins and sees that the user’s successful sign-ins came from that device in Stockholm.

The agent retrieves the user’s identity, managed device and group memberships. Edited demo view.
When it checks the risky source IP, The Brain returns another relevant memory: the IP had already been recorded as attacker infrastructure during a prior investigation.

The Brain retrieves an IP recorded as attacker infrastructure during a prior demo investigation. Edited demo view.
The stored context gives the agent a starting point; the live Entra checks provide evidence about the current activity. In impossible-travel cases where the evidence cannot rule out compromise, the agent escalates by default for human input.
How The Brain works
Knowledge of an environment is distributed across the stack. SIEMs hold events and investigation data. CNAPPs map cloud resources and security posture. CMDBs record ownership and dependencies. Tickets, docs and conversations can explain why a change happened or how a team reached a decision.
The difficult part is connecting their records to the same person or service and carrying relevant knowledge into the next task.
The Brain is a shared context and memory layer. Its current implementation includes identities, cloud assets such as AWS and Vercel, MDM-managed devices, repositories, vulnerabilities and their relationships. Agents can begin with a single entity and discover the people and systems they are connected to.
That knowledge takes two forms. Structured records connect entities through stable identifiers: the repository, the service and its cloud resources. Agentic memory holds context that doesn’t fit neatly into an edge, such as why a team considered a pattern benign or which operational constraint shaped a decision.

An excerpt from the demo workspace’s security policies and linked reference documents. Edited demo view.
The Brain captures high-level knowledge to help agents find their way through an environment, and individual data points when precise values are required. An agent can use that map to identify the source system it should check before acting.
Connecting records
A user has an Okta name, a GitHub username, an AWS IAM role, a Slack username and a hostname in an endpoint console. Service accounts sometimes look like users. People leave teams, but their accounts remain. These records need to be connected to the right person or asset.
Matching is deterministic today. The Brain uses an email address for a user and the natural key for other asset types. Entities are validated as they are extracted. If an investigation encounters an entity that isn’t in The Brain, it is added as inferred. When a stable identifier is missing or unclear, the record stays inferred until it is corrected or merged.
An inferred record lets an agent carry a possible relationship into an investigation while keeping its status visible. Ownership relationships may also need reconciliation when records from different systems disagree.
Agents can write information to The Brain, with that behaviour configured at the agent level. Humans and agents can correct or merge records as more information becomes available, so knowledge captured during an investigation can be used in subsequent work.
Investigating an application
Another captured investigation shows this in application security. Apex, Cantina’s autonomous OffSec agent, begins with a GitHub repository, and The Brain hands over the surrounding topology: its load balancer, database, cache, jobs, Datadog service, other repositories and AWS resources.
Apex can see where request parsing happens, which edge controls sit in front of the service and which connected systems belong in the attack path.

Apex retrieves the repository and its 13 connected resources across GitHub, AWS and Datadog. Edited demo view.
What we observed in alert triage
In an observational comparison of 40 low-severity Okta alerts, with 20 per workspace and equal counts by alert type, the Brain-enabled workspace averaged 170.8 seconds from alert creation to closure, versus 220.4 seconds in the comparison workspace: 22.5% less time. It also averaged 12.15 tool calls per alert, versus 19. Example traces in the evaluation illustrate how stored context can reduce discovery work: one agent retrieved a user baseline from The Brain, while the other queried identity and device data across more systems.
Average time to close and tool calls per alert
Comparison: 220.4 seconds
Brain enabled: 170.8 seconds
Comparison: 19 calls
Brain enabled: 12.15 calls
Time to close by alert type
- Sign-In Location (10 per group): comparison 240.7 s; Brain enabled 164.4 s.
- Sign-In Time (7 per group): comparison 162.4 s; Brain enabled 163.4 s.
- MFA Deactivated (2 per group): comparison 325.5 s; Brain enabled 218.5 s.
- Impossible Travel (1 per group): comparison 213.0 s; Brain enabled 191.0 s.
About the data
The sample contains 20 low-severity alerts from each of two workspaces. The Brain-enabled sample spans September 14–16, 2026; the comparison spans September 11–16. Each workspace has 10 sign-in-location alerts, seven sign-in-time alerts, two MFA-deactivation alerts and one impossible-travel alert. All 40 were closed as benign or false positive without human action.
Elapsed time runs from alert creation to closure, including pickup. The evaluation records each workspace’s own alerts, history and integrations. Two comparison alerts use gpt-5.6-terra; the other 38 use claude-opus-4-8. The source also records 18 Brain read calls in the comparison workspace.
Every alert’s time to close
Comparison: median 191 s, range 140–349 s.
Brain enabled: median 159.5 s, range 106–282 s. All individual times are in the source table below.
Using the same model
This view includes the 18 comparison alerts and 20 Brain-enabled alerts run with claude-opus-4-8.
Comparison (18 alerts): 220.28 seconds
Brain enabled (20 alerts): 170.8 seconds
Comparison (18 alerts): 16.83 calls
Brain enabled (20 alerts): 12.15 calls
Bars show arithmetic means. For an even number of alerts, the median is the average of the two middle values.
Explore all 40 source rows
All 40 alert records are shown below. Time values are seconds; tokens are output tokens.
| Workspace | Alert | Type | Time (s) | Tools | Steps | Output tokens | Model | Outcome |
|---|---|---|---|---|---|---|---|---|
| Brain enabled | ISS-1272 | Sign-In Time | 107 | 7 | 23 | 5,455 | claude-opus-4-8 | benign |
| Brain enabled | ISS-1271 | Sign-In Time | 141 | 8 | 26 | 6,810 | claude-opus-4-8 | benign |
| Brain enabled | ISS-1268 | Sign-In Location | 106 | 9 | 28 | 6,029 | claude-opus-4-8 | benign |
| Brain enabled | ISS-1267 | Sign-In Location | 141 | 11 | 33 | 8,533 | claude-opus-4-8 | benign |
| Brain enabled | ISS-1266 | Sign-In Time | 181 | 10 | 31 | 8,472 | claude-opus-4-8 | benign |
| Brain enabled | ISS-1264 | Sign-In Time | 143 | 12 | 36 | 8,006 | claude-opus-4-8 | benign |
| Brain enabled | ISS-1262 | Sign-In Location | 175 | 11 | 34 | 7,628 | claude-opus-4-8 | false positive |
| Brain enabled | ISS-1261 | Sign-In Location | 192 | 13 | 38 | 8,925 | claude-opus-4-8 | benign |
| Brain enabled | ISS-1260 | Sign-In Location | 143 | 10 | 30 | 7,570 | claude-opus-4-8 | benign |
| Brain enabled | ISS-1259 | Sign-In Location | 258 | 16 | 50 | 10,524 | claude-opus-4-8 | benign |
| Brain enabled | ISS-1257 | Impossible Travel | 191 | 13 | 36 | 11,502 | claude-opus-4-8 | false positive |
| Brain enabled | ISS-1256 | Sign-In Location | 137 | 11 | 31 | 7,351 | claude-opus-4-8 | benign |
| Brain enabled | ISS-1254 | Sign-In Time | 282 | 21 | 64 | 14,848 | claude-opus-4-8 | benign |
| Brain enabled | ISS-1253 | Sign-In Time | 140 | 11 | 32 | 7,176 | claude-opus-4-8 | false positive |
| Brain enabled | ISS-1251 | Sign-In Location | 162 | 11 | 32 | 9,637 | claude-opus-4-8 | benign |
| Brain enabled | ISS-1250 | Sign-In Time | 150 | 12 | 34 | 7,333 | claude-opus-4-8 | benign |
| Brain enabled | ISS-1248 | Sign-In Location | 157 | 13 | 35 | 8,758 | claude-opus-4-8 | benign |
| Brain enabled | ISS-1244 | MFA Deactivated | 239 | 16 | 42 | 17,734 | claude-opus-4-8 | benign |
| Brain enabled | ISS-1242 | Sign-In Location | 173 | 14 | 38 | 10,104 | claude-opus-4-8 | benign |
| Brain enabled | ISS-1239 | MFA Deactivated | 198 | 14 | 39 | 12,273 | claude-opus-4-8 | benign |
| Comparison | ISS-2364 | Sign-In Time | 178 | 43 | 93 | 8,630 | gpt-5.6-terra | benign |
| Comparison | ISS-2362 | Sign-In Location | 265 | 34 | 75 | 11,485 | gpt-5.6-terra | benign |
| Comparison | ISS-2357 | Sign-In Time | 140 | 11 | 34 | 8,271 | claude-opus-4-8 | benign |
| Comparison | ISS-2356 | Sign-In Location | 170 | 13 | 36 | 11,064 | claude-opus-4-8 | benign |
| Comparison | ISS-2351 | Sign-In Time | 144 | 12 | 37 | 8,933 | claude-opus-4-8 | false positive |
| Comparison | ISS-2350 | Sign-In Time | 156 | 13 | 38 | 9,578 | claude-opus-4-8 | benign |
| Comparison | ISS-2349 | Sign-In Time | 154 | 11 | 33 | 7,758 | claude-opus-4-8 | benign |
| Comparison | ISS-2347 | Impossible Travel | 213 | 17 | 49 | 14,319 | claude-opus-4-8 | false positive |
| Comparison | ISS-2346 | MFA Deactivated | 333 | 25 | 75 | 22,016 | claude-opus-4-8 | benign |
| Comparison | ISS-2343 | Sign-In Location | 169 | 13 | 38 | 10,820 | claude-opus-4-8 | benign |
| Comparison | ISS-2340 | Sign-In Time | 201 | 17 | 57 | 13,144 | claude-opus-4-8 | benign |
| Comparison | ISS-2339 | Sign-In Time | 164 | 13 | 42 | 10,284 | claude-opus-4-8 | benign |
| Comparison | ISS-2330 | Sign-In Location | 349 | 26 | 77 | 20,920 | claude-opus-4-8 | benign |
| Comparison | ISS-2326 | Sign-In Location | 183 | 13 | 38 | 8,825 | claude-opus-4-8 | benign |
| Comparison | ISS-2325 | Sign-In Location | 333 | 24 | 73 | 16,499 | claude-opus-4-8 | benign |
| Comparison | ISS-2321 | Sign-In Location | 339 | 24 | 69 | 20,633 | claude-opus-4-8 | benign |
| Comparison | ISS-2305 | Sign-In Location | 217 | 15 | 43 | 13,416 | claude-opus-4-8 | benign |
| Comparison | ISS-2299 | Sign-In Location | 187 | 14 | 40 | 9,223 | claude-opus-4-8 | benign |
| Comparison | ISS-2298 | Sign-In Location | 195 | 17 | 46 | 12,477 | claude-opus-4-8 | benign |
| Comparison | ISS-2223 | MFA Deactivated | 318 | 25 | 73 | 22,203 | claude-opus-4-8 | benign |
Workspace context and controls
All Brain data resides within individual workspaces. Because it brings together identity, infrastructure and investigation context, access to the workspace, agents and underlying integrations forms part of its security boundary.
The Brain draws on connected systems and recorded investigation history. Humans and agents can correct or merge records, while live source checks provide current evidence during an investigation.
Knowledge records support topic locks and review of proposed facts.
See The Brain in your environment
To explore how The Brain can connect your systems and investigation history, get in touch.