Business#Security scan#AI safety

Mandia’s Armadin raises $255.5M at $2.5B for always-on agentic-swarm security

Mandia’s Armadin announced a $255.5M Series B (a16z, Accel; $2.5B+ valuation) for always-on agentic swarms attacking enterprise systems.

TechCrunch art: red-eyed mechanical agents swarming a dark network

Armadin, the new company from Kevin Mandia (who founded Mandiant and sold it to Google for $5.4B in 2022), announced a $255.5M Series B on October 1 — seven months after a $190M Series A, taking total funding past $445M.

The facts

  • Round: $255.5M Series B co-led by Andreessen Horowitz and Accel, with Bain Capital Ventures, Redpoint, 8VC, Ballistic Ventures, GV, In-Q-Tel, Kleiner Perkins and Menlo Ventures participating; valuation above $2.5B.
  • Product: always-on “agentic swarms” — multiple security agents chaining vulnerabilities and continuously attacking the enterprise, replacing one-off penetration tests, finding holes before attackers (including rogue AI agents) do.
  • Founder: Mandia is the reference name in incident response; Mandiant led attribution on multiple nation-state incidents.
  • The pitch: Mandia says “offense is uniquely advantaged right now”; product availability timing was not announced.

This week’s security arc

The raise lands as regulators start chasing runaway agents and companies discover their own agents leaking (PixelLeak). Armadin’s pitch rides exactly that chain — your adversary is already an agent, so defense has to be one too. In-Q-Tel (the CIA’s venture arm) in the cap table is worth a pause.

Editorial take

Commercially viable always-on attack agents turn the “penetration test report” into a “continuous threat-surface map” — a budget reshuffle for CISOs and one more role being automated for pentesters. It also answers the regulators’ question with a method: if agents go rogue, the most honest test is letting another swarm try to break in every day.

What “always-on attack” changes

Classic pentesting is episodic: a week of testing, a report, a remediation sprint, then twelve months of drift. A resident swarm inverts the cadence — every new asset, dependency or cloud change meets an attacker the day it ships. The commercial question is false-positive economics: continuous offense only works if the swarm’s findings survive a triage call, and Mandia’s incident-response pedigree is the bet that they will. The In-Q-Tel participation signals government demand for the same capability.

The market context

Armadin is the third large agentic-security bet this quarter, after a wave of “AI SOC analyst” startups and the traditional vendors bolting copilots onto existing consoles. The differentiator Mandia is selling is provenance: offense at Mandiant-grade attribution depth, run continuously, with the findings feeding the same response playbooks enterprises already use. Seven months between A and B at a doubled valuation says the defense market’s fear of rogue agents — regulators now among the buyers of that narrative — is doing the selling.

The unresolved question is permissioning: who authorizes a swarm to attack production, and what happens when it finds a hole no one can fix inside the sprint. Armadin’s answer will define whether this becomes a product category or a very expensive research project.

A second-order effect worth pricing: resident attack swarms generate their own disclosure obligations — every confirmed finding is evidence of an exploitable state that someone knew about. Security teams adopting this model should write the finding-handling policy before the swarm lands, not after the first liability letter.

The name matters too: Armadin deliberately echoes neither Mandiant nor any incident-response vocabulary — a clean slate for a company whose product would have been unrecognizable as “security” five years ago, when offense meant people and defense meant appliances rather than two fleets of agents hunting each other inside a customer’s network.

For buyers calibrating expectations: agentic offense finds the known-unpatched class of problems quickly and the novel-logic class slowly, so the first quarter of an Armadin deployment will look like a vulnerability scanner on steroids and the differentiation arrives in year two. Budget accordingly and demand the false-positive curve in writing.

The markets have already voted; the systems will take longer to be convinced.