# The Brain: giving security agents knowledge of your environment Author: Cantina Published: September 29, 2026 Topics: The Brain, AI Security, Security Operations Canonical URL: https://www.cantina.security/blog/the-brain-security-agents The Brain is Cantina's shared context and memory layer for AI security agents. It connects the people and systems in your environment with operating context and prior investigations. Security work depends on knowing which device belongs to a user, how a repository connects to production, and what the team established during a previous investigation. We're launching The Brain to make that knowledge available to Cantina's agents. ![The Brain asset catalog with a selected identity](./the-brain-security-agents/01-brain-demo.png) *The Brain's asset catalog and a selected identity in the demo workspace. Recreated from the supplied screenshot, with text edited for readability.* ## Investigating an impossible-travel alert In our demo environment, Microsoft Sentinel and Defender XDR surface an impossible-travel alert after sign-ins appear from locations a person could not realistically move between in the available time. The alert includes the user, locations, IPs and timestamps. A VPN or a change between Wi-Fi and cellular service can account for a location change, so the agent needs to check what happened. The triage agent starts by pulling the user's context from The Brain: a finance identity, payment-approver group memberships and one managed, compliant Windows laptop. It then checks live Entra sign-ins and sees that the user's successful sign-ins came from that device in Stockholm. ![Identity, managed device and group context retrieved by the triage agent](./the-brain-security-agents/02-brain-demo.png) *The agent retrieves the user's identity, managed device and group memberships. Edited demo view.* When it checks the risky source IP, The Brain returns another relevant memory: the IP had already been recorded as attacker infrastructure during a prior investigation. ![Prior investigation memory for a risky source IP](./the-brain-security-agents/03-brain-demo.png) *The Brain retrieves an IP recorded as attacker infrastructure during a prior demo investigation. Edited demo view.* The stored context gives the agent a starting point; the live Entra checks provide evidence about the current activity. In impossible-travel cases where the evidence cannot rule out compromise, the agent escalates by default for human input. ## How The Brain works Knowledge of an environment is distributed across the stack. SIEMs hold events and investigation data. CNAPPs map cloud resources and security posture. CMDBs record ownership and dependencies. Tickets, docs and conversations can explain why a change happened or how a team reached a decision. The difficult part is connecting their records to the same person or service and carrying relevant knowledge into the next task. The Brain is a shared context and memory layer. Its current implementation includes identities, cloud assets such as AWS and Vercel, MDM-managed devices, repositories, vulnerabilities and their relationships. Agents can begin with a single entity and discover the people and systems they are connected to. That knowledge takes two forms. Structured records connect entities through stable identifiers: the repository, the service and its cloud resources. Agentic memory holds context that doesn't fit neatly into an edge, such as why a team considered a pattern benign or which operational constraint shaped a decision. ![Demo security policy knowledge and linked reference documents](./the-brain-security-agents/04-brain-demo.png) *An excerpt from the demo workspace's security policies and linked reference documents. Edited demo view.* The Brain captures high-level knowledge to help agents find their way through an environment, and individual data points when precise values are required. An agent can use that map to identify the source system it should check before acting. ### Connecting records A user has an Okta name, a GitHub username, an AWS IAM role, a Slack username and a hostname in an endpoint console. Service accounts sometimes look like users. People leave teams, but their accounts remain. These records need to be connected to the right person or asset. Matching is deterministic today. The Brain uses an email address for a user and the natural key for other asset types. Entities are validated as they are extracted. If an investigation encounters an entity that isn't in The Brain, it is added as inferred. When a stable identifier is missing or unclear, the record stays inferred until it is corrected or merged. An inferred record lets an agent carry a possible relationship into an investigation while keeping its status visible. Ownership relationships may also need reconciliation when records from different systems disagree. Agents can write information to The Brain, with that behaviour configured at the agent level. Humans and agents can correct or merge records as more information becomes available, so knowledge captured during an investigation can be used in subsequent work. ## Investigating an application Another captured investigation shows this in application security. [Apex, Cantina's autonomous OffSec agent](https://www.cantina.security/apex), begins with a GitHub repository, and The Brain hands over the surrounding topology: its load balancer, database, cache, jobs, Datadog service, other repositories and AWS resources. Apex can see where request parsing happens, which edge controls sit in front of the service and which connected systems belong in the attack path. ![Application topology with 13 connected resources](./the-brain-security-agents/05-brain-demo.png) *Apex retrieves the repository and its 13 connected resources across GitHub, AWS and Datadog. Edited demo view.* ## What we observed in alert triage In an observational comparison of 40 low-severity Okta alerts, with 20 per workspace and equal counts by alert type, the Brain-enabled workspace averaged **170.8 seconds** from alert creation to closure, versus **220.4 seconds** in the comparison workspace: **22.5% less time**. It also averaged **12.15 tool calls** per alert, versus **19**. Example traces in the evaluation illustrate how stored context can reduce discovery work: one agent retrieved a user baseline from The Brain, while the other queried identity and device data across more systems. [Interactive figures: overall averages, alert types, individual alerts and same-model comparison](#what-we-observed-in-alert-triage) Median time: 159.5 vs 191 seconds; mean time: 170.8 vs 220.4 seconds. Median tool calls: 11.5 vs 16; mean tool calls: 12.15 vs 19. Brain enabled first. Observational comparison of 20 low-severity alerts per workspace. The source records 18 Brain read calls in the comparison workspace. ## Workspace context and controls All Brain data resides within individual workspaces. Because it brings together identity, infrastructure and investigation context, access to the workspace, agents and underlying integrations forms part of its security boundary. The Brain draws on connected systems and recorded investigation history. Humans and agents can correct or merge records, while live source checks provide current evidence during an investigation. Knowledge records support topic locks and review of proposed facts. ## See The Brain in your environment To explore how The Brain can connect your systems and investigation history, [get in touch](https://www.cantina.security/get-a-demo).