Armadin
An AI-native offensive security platform rebuilt by the founder of Mandiant — re-priced to $2.5B+ roughly seven months after exiting stealth
- Revenue, ARR and customer count are undisclosed. The Series B release contains no financial metrics beyond valuation and capital raised. The statement that campaigns run in production for Fortune 500 and government customers is company-reported and cannot be independently verified.
- Pre- vs. post-money status of the “$2.5B+” valuation is not specified. Dilution and step-up figures in this report assume post-money and are our estimates. The $650M post-money figure for the Series A rests on a third-party post (Arfur Rock on X) and is unofficial.
- The Seed / Series A split is our derivation. The official figure is a combined $189.9M. Subtracting the $24M seed (per WSJ reporting) implies a Series A of roughly $165.9M, which is our arithmetic. A separate report based on an SEC filing (Cybersecurity Pulse) cites about $165M raised; directionally consistent but not confirmed.
- Hyperattack result figures differ by source. For the same engagement, Armadin’s blog cites “98 significant findings,” while the TENEX.ai release and The Register cite 238 security findings. The difference may reflect different counting bases, but this is unconfirmed, and all figures are self-reported.
- Headquarters location is reported inconsistently. Recent press-release datelines read Palo Alto; earlier coverage said San Francisco; Crunchbase lists Menlo Park. This report follows the most recent official dateline (Palo Alto, CA).
- Beware mis-described business profiles. Some databases and outlets describe Armadin as a “real-time threat hunting” company; the company’s own positioning is agentic offensive security (autonomous red teaming). This report follows the company’s description. Crunchbase also lists the name as “Armadin Security,” which differs from the official legal name “Armadin.”
- Mandiant–FireEye deal timing varies. Some outlets cite 2014; most sources confirm the $1B acquisition in December 2013. This report uses December 2013.
Armadin is a U.S. AI-native offensive security company founded in September 2025. Its platform deploys swarms of agents that attack an enterprise’s attack surface the way real adversaries do, validating and proving exploitable paths. The core underwriting argument for this investment is founder-market fit: the founder has spent more than two decades on the front lines of breach response and is a repeat founder with a completed large exit.
Joined the U.S. Air Force in 1992 and served as a computer security officer with the 7th Communications Group at the Pentagon, then as a special agent with the Air Force Office of Special Investigations (AFOSI, 1996–1998) investigating cybercrime. In the private sector he was Director of Information Security at Sytex (1998–2000; later acquired by Lockheed Martin) and Director of Computer Forensics at Foundstone (2000–2003; later acquired by McAfee). He holds a B.S. in computer science from Lafayette College. In 2004 he founded Mandiant (originally Red Cliff Consulting, renamed in 2006), building it into a leading incident-response and threat-intelligence firm, and gained industry-wide prominence with a report exposing cyber-espionage activity by a People’s Liberation Army unit. After FireEye acquired Mandiant for $1B in December 2013, he served as FireEye COO and President, and as CEO from June 2016. Following FireEye’s 2021 sale of its products business, the company reverted to the Mandiant name, and Google acquired it for $5.4B in 2022 (closed September 2022). He then co-founded and served as General Partner at security-focused VC Ballistic Ventures, sat on the CISA Cybersecurity Advisory Committee, and founded Armadin in September 2025. He joined Amazon’s board on September 8, 2026.
Former Principal Engineer, Google Cloud Security. Led technical strategy for large-scale security systems at Google after the Mandiant acquisition. Runs product and engineering at Armadin.
Former global red-team lead at Mandiant. Reported to have led a globally distributed team of about 210. Owns the offensive methodology used as the training standard for Armadin’s agents.
Former Google SecOps engineer. Responsible for agent orchestration and platform architecture.
COO Barbara Massa (ex-Mandiant EVP and Chief of Business Operations; ex-NightDragon COO; Jun 2026), CRO Brian Gumbel (ex-Dataminr President/COO; ex-Armis President/CRO; Jul 2026), CFO Frank Verdecanna (ex-Mandiant CFO; Sep 2026). George Kurtz, founder and CEO of CrowdStrike, joined as an independent director in April 2026.
Armadin sells its agentic attack platform, “Armadin Red,” to enterprise and government customers on a subscription basis. It exited stealth on March 10, 2026 with more than 60 employees. At the Series B announcement the company said it runs agentic attack campaigns in production for Fortune 500 and government customers, but customer count, ARR and contract sizes have not been disclosed (see Data Integrity Notice #1).
Note: Figures above come from the August 2026 joint engagement with TENEX.ai (customer undisclosed) and the Palo Alto Networks blog; all are self-reported.
Specialized agent swarms chain external reconnaissance, unauthenticated remote code execution, lateral movement and full cloud compromise into validated kill chains. Every action passes through a control layer overseen by a safety model trained on human expert feedback, alongside human oversight.
Massively parallel attack simulation. In a three-day engagement with TENEX.ai in August 2026, the swarm executed about 17 million offensive actions across 1,300 attacks, reportedly without credentials, source-code access or whitelisting. It was the centerpiece of the Black Hat 2026 demonstrations.
Series A lead Accel described a real-time knowledge graph of the attack surface, a cyber system of record answering “are we secure right now?” Remediation is prioritized by which fixes sever entire attack chains; automated remediation is being expanded cautiously given operational-disruption risk.
Channel and commercialization progress: In April 2026, Armadin’s External AI Hyperattack Assessment was added to Palo Alto Networks Unit 42’s “Frontier AI Defense” service (passive discovery → agent-swarm attack → post-exploitation simulation → decision-grade evidence logging). Since general availability of Armadin Red in June 2026, the company has added a COO (June), CRO (July) and CFO (September) to build out its commercial organization. It expanded visibility at RSAC (April) and Black Hat (August).
Armadin raised a cumulative $445M in about 13 months from founding. The capital structure features (1) a seed led by a fund affiliated with the founder (Ballistic Ventures), (2) consecutive participation from top-tier security and growth VCs (Accel, a16z, Kleiner Perkins, GV, Menlo), and (3) a strategic investor tied to the intelligence community (In-Q-Tel). All existing investors returned for the Series B, which confirms insider conviction but also means pricing was formed within an established shareholder network.
A seed round closed shortly after the September 2025 founding. The seed lead, Ballistic Ventures, is the fund Mandia co-founded and where he is General Partner, making it a related-party lead. An SEC filing reportedly showed total capital raised of about $165M around the same time, far larger than the WSJ figure (Data Integrity Notice #3).
Arfur Rock posted, citing a WSJ article, that a roughly $160M Series A with Accel, Kleiner Perkins, GV and others closed at $650M post-money. This figure lacks company confirmation and should be used only as a limited reference point for step-up calculations.
Announced alongside the exit from stealth, the company claims the largest combined seed and Series A in cybersecurity history. Accel led the Series A, with GV, Kleiner Perkins, Menlo Ventures and In-Q-Tel participating; 8VC and Ballistic followed on. At the time the company said it had 60+ employees and had begun working with Fortune 100 customers (company-reported).
Round structure: Andreessen Horowitz and Accel co-led, with new investors Bain Capital Ventures and Redpoint joining; existing investors 8VC, Ballistic, GV, In-Q-Tel, Kleiner Perkins and Menlo all returned. Total funding reaches $445M.
Use of proceeds (company-stated): scale the agentic security platform, research and training, and go-to-market.
Investor rationale: a16z’s David George cited Mandia’s front-line breach experience and a team pairing elite red teamers with AI engineers, and said Armadin could become the defining security company of the AI era. Accel’s Ping Li said the Series A conviction, that the best defense against agentic adversaries is AI-powered offense, has only strengthened.
Armadin’s defensibility derives less from a single technical moat than from the combination of productized real-world adversary know-how, a proven executive network, demonstrated large-scale operation, and capital plus distribution. Most technical-superiority claims below are company-sourced and should be treated as provisional until independent benchmarks exist.
Mandia and Peña bring decades of experience confronting nation-state-level threat actors in breach response and red teaming. The company says it trains AI agents to the standard of world-class red-team operators. This tacit knowledge is hard for newer AI-native entrants to replicate quickly, but whether it translates into measurable model performance requires external validation.
Within a year of founding, Armadin added Mandiant’s former CFO (Verdecanna; reported 14 years as CFO, two public companies, two IPOs, 15+ acquisitions), a COO (Massa) and a CRO who helped scale Armis to unicorn status (Gumbel). CrowdStrike’s founder joining as an independent director signals top-tier industry access. We read this as a “listing-ready” management build consistent with a future IPO or M&A path.
A three-day Hyperattack with 26,000 agents and 1,300 attacks against 25,000+ services without credentials is the largest publicly disclosed example in the category (company claim). The architecture routing every action through a safety-model control layer addresses the biggest barrier to production adoption, destructive behavior, and chaining low-severity weaknesses into proven kill chains differentiates it from scanners.
Cumulative funding of $445M is in the same range as the category leader Horizon3.ai (reported $428.5M cumulative). In-Q-Tel provides intelligence-community access, Palo Alto Unit 42 offers a vendor channel, and the GV, a16z and Accel networks may shorten enterprise and government sales cycles. Channel reliance, however, also brings path dependency and potential margin dilution.
Next growth driver — a closed offense-defense loop: The joint engagement with TENEX.ai demonstrated offensive AI training and refining defensive AI (the defender reportedly triaged all 101,169 alerts and reconstructed attacker activity across 231 billion events). The company’s stated goal of “effective autonomous security” reads as an intention to extend beyond detection and proof into remediation and defense automation. That expands the addressable market, but it is also a head-on competitive zone with large platform vendors.
Capital has flowed rapidly into autonomous pentesting in 2026, lifting valuations across the category. Armadin is a late entrant that has nonetheless been assigned one of the highest valuations, while public financial metrics are weaker than, or not comparable to, those of incumbents.
| Company | Latest Round / Valuation | Disclosed Key Metrics | Notes |
|---|---|---|---|
| Armadin | Series B $255.5M (Oct 2026) / $2.5B+ | Revenue and customer count undisclosed. $445M total raised | ~13 months old; offensive agent swarm with human oversight |
| Horizon3.ai | Series E $250M (Aug 2026) / $2B+ | 6,500–7,000+ customers (reports differ); ARR growth ~120% (company); ARR ~$100M (media) | Cumulative funding differs by outlet ($428.5M vs. $678.5M) |
| XBOW | Series C $120M (Mar 2026; DFJ Growth, Northzone) + $35M strategic (May 2026) / $1B+ | Reached #1 on HackerOne’s global leaderboard | Agentic pentesting focused on web applications |
| Pentera | ~$250M total raised / $1B+ | ARR $100M+ (Jan 2026); 1,200+ enterprise customers | Established agentless security validation vendor |
| RunSybil | Seed $40M (Mar 2026; Khosla-led) | Founded by former OpenAI and Meta security / red-team talent | Continuous black-box testing with no human in the loop |
Note: Competitor figures come from third-party outlets and comparison blogs, some authored by competing vendors (e.g., MindFort). The characterization of Armadin as “not truly autonomous because humans are involved” comes from a competitor’s perspective.
A $2.5B+ valuation was set without revenue disclosure. Comps (Horizon3.ai, Pentera) earn $1–2B valuations at roughly $100M ARR, so price justification in a future round or exit depends entirely on how fast ARR becomes visible. Commercialization failure makes a down round the largest exposure.
Mandia is Armadin CEO, Ballistic Ventures GP, and since September 2026 an Amazon director. Brand dependence on one individual and bandwidth are risks; the related-party seed lead and an executive bench drawn largely from the Mandiant network raise counterparty circularity. GV (Alphabet) as a shareholder alongside a CEO who sits on Amazon’s board is also worth monitoring from a neutrality standpoint (analyst observation, not a confirmed issue).
Well-funded incumbents (Horizon3.ai, XBOW, Pentera, RunSybil) abound, and low-cost AI pentesting tools starting at $199 per month have appeared. Platform vendors such as CrowdStrike and Palo Alto could internalize similar capabilities. The Palo Alto partnership is both a distribution advantage and a displacement risk.
A single Hyperattack consumed tens of billions of tokens, implying substantial compute cost per campaign. Which foundation models are used, and how much is self-trained, has not been disclosed. If frontier labs expand directly into code and security agents, pricing power and gross margin could come under pressure.
Operating autonomous attack agents in production means a single destructive malfunction or false exploit could severely damage customer trust. As Axios reported in late September 2026 on frontier AI agents escaping sandboxes and control issues, regulatory and public scrutiny is rising, leaving autonomous offensive agents exposed to headline, regulatory and liability risk. The safety control layer’s effectiveness is currently supported only by company claims.
The company hired 60+ people within six months, and the Series B arrived roughly two months after the CRO joined. Large capital has entered before the sales organization, pricing structure and software-versus-services revenue mix have been validated. Human oversight aids trust but, if services labor grows, could burden software margin profiles.

