New York, September 29th / PRNewswire / -- Cantina Today, we are launching The Brain, which is a layer that shares context and memory, providing persistent knowledge of each customer's environment for its autonomous security agents. The Brain connects people and systems with the operational context and past investigations, helping the agents of Cantina to understand what a certain issue means within a particular organization, and carries relevant knowledge from one investigation to the next.
Security investigations rely on information scattered across various components of the technology stack. For example, an alarm may point to a AWS role, a GitHub repository, a Okta user, or a production service, while the information necessary to understand its significance may be found in SIEM, cloud platforms, terminal consoles, tickets, documentation, or previous investigations. Security teams must piece together these records to determine who is responsible for the affected systems, understand what they support, and assess whether similar activities have occurred before.
The Brain integrates this information to enable the agent of Cantina to have a grasp of the alert-related environment from the start of the investigation. The current implementation includes identities, AWS and Vercel among other cloud assets, MDM management devices, code repositories, vulnerabilities, as well as the relationships between them. The agent can start from a single entity and identify related personnel and systems.
The Brain combines structured records with agentic and memory. Structured records connect entities through stable identifiers, such as warehouses, services, and their cloud resources. agentic and memory on the other hand, retain contexts that are not easily categorized into relational structures, including why a certain team considers a pattern to be benign, which operational constraints influenced a particular decision, or what conclusions were drawn from a previous investigation regarding a suspicious IP.
"Autonomous security staff need to know far more than what is displayed in the alerts," said Hari Mulackal, CEO and co-founder of Cantina. "Experienced security engineers accumulate years of knowledge about how the environment operates, which systems are important, who is responsible, and what has happened in the past. The Brain enables the staff at Cantina to continuously access this organizational knowledge, so they can use it every time they investigate and solve problems."
The Brain How it works
Knowledge about an organization is scattered across systems that have been built for different purposes. SIEM stores event and investigation data, CNAPP creates maps of cloud resources and security landscapes, CMDB records ownership and dependencies, while tickets, documents, and conversations can explain why a change occurred or how a team made a decision. The Brain links relevant records to the same person, service, or asset, making this context available for use by the agents of Cantina.
- A connected environment map. The Brain maps identities, code repositories, services, cloud resources, managed devices, vulnerabilities, and other assets, as well as the relationships between them.
- Structured context and memory. Stable identifiers connect technical records, while agentic and memory retain investigation findings, known patterns, operational context, and other knowledge that can provide references for future work.
- Entity alignment. The Brain currently uses deterministic matching, including users' email addresses and natural keys for other asset types. When a stable identifier is missing or unclear, the record can remain in an inferred state until it is corrected or merged.
- Knowledge from investigations. When the configuration permits, agents can write information to The Brain; as more information becomes available, both humans and agents can correct or merge records.
- Workspace control. Brain Data is retained within its respective workspaces, and knowledge records support topic locking and review of proposed facts. Real-time source checking can provide current evidence during investigations.
The Brain reduced alarm diversion time and the number of tool calls in observational comparisons.
Cantina compared 40 low-severity Okta alerts between two workspaces, of which 20 were in the workspace with Brain enabled, and 20 were in the comparison workspace. The average time from alert creation to closure in the workspace with Brain enabled was 170.8 seconds, while in the comparison workspace it was 220.4 seconds, which means a 22.5% reduction in time. The average number of tool calls per alert was 12.15 times in that workspace, compared to 19 times in the comparison workspace, representing a 36.1% reduction.
The median closure time in the workspace with Brain enabled is 159.5 seconds, while in the comparison workspace it is 191 seconds. All 40 alerts are of low severity Okta, and they have been categorized as benign or false positives, thus no manual intervention is required; both workspaces have the same number of alerts of each type.
To account for the differences in models used, Cantina also compared 20 alarms that enabled Brain with 18 comparative alarms running on the same model Claude Opus version 4.8. From this perspective, the average time taken for samples with Brain enabled was reduced by 22.5%, and the number of tool calls was decreased by 27.8%. This assessment is an observational comparison, not a random test, and each workspace used its own alarms, history, and integrations.
Provide lasting understanding for autonomous security staff
Cantina was launched in July in stealth mode and received $8 million in financing led by Framework Ventures. The total financing amount has reached $16.5 million. The company has built an in-house security team that can identify security issues, facilitate repairs, and verify the results of those repairs before attackers can succeed.
The Brain is situated beneath this work team, serving as a source of shared context and memory. In a recorded application security investigation, the autonomous OffSec of Cantina acted as an agent, starting from a GitHub repository and utilizing The Brain to retrieve its surrounding topology, which included load balancers, databases, caches, tasks, Datadog services, other repositories, and AWS resources. This context allowed the agent to obtain a system map of the attack path before beginning a more in-depth investigation.
About Cantina
Cantina is a community-driven agentic security team that helps organizations identify, prioritize, fix, and verify security risks at machine speed. Founded by senior security researchers, the team combines autonomous security professionals with an understanding of the continuous evolution of each customer's environment, transforming security efforts from discovery to resolution.
For more information, please visit cantina.security.
Correction: The website mentioned in the first sentence has been updated.











