I've spent my career on one side of a simple question: what can an adversary see, and how fast can they act on it? At Intrigue, at Mandiant, at Kenna, Bugcrowd, and Rapid7 before that, the answer kept changing, but it changed at human speed. A new vulnerability dropped, researchers dug in, exploit code circulated, and defenders had a window measured in days or weeks to get ahead of it.
That window is gone. AI has collapsed the cost and time of finding exploitable flaws. What used to require a skilled researcher and a few weeks now takes a model and a few hours. When a working exploit can land the same day a weakness becomes known, the entire rhythm defenders build their programs around (scan, score, ticket, patch) stops making sense. The clock those tools were designed for no longer exists.
Intelligence was never the problem
Security teams are not short on intelligence. They are drowning in it. Threat feeds, vulnerability scanners, attack surface tools, and cloud posture products all do their jobs, and the result is a thousand-item backlog ranked by a severity score that has no idea who is attacking you.
That is the real gap in security operations today. Call it the context-action gap: the distance between everything your tools can tell you and the handful of things your team can actually act on this week. Every hour an analyst spends manually correlating a new CVE against your environment, or pivoting between a threat report and an asset inventory, is an hour the adversary's timeline no longer grants you.
Point tools can't close that gap, because it sits underneath them. Hunting threats, prioritizing exposures, and building detections all start from the same raw material: stories, TTPs, vulnerabilities, and IOCs, correlated against what you actually run. Today that correlation happens in an analyst's head, across three tools, one investigation at a time. The intelligence is shared. The work shouldn't take three products and a swivel chair.
Why now is different
Here's the part that keeps me optimistic. The same shift that armed attackers also handed defenders something genuinely new: reasoning systems that can do the analyst correlation step at machine speed, on a standing basis, across everything at once.
But speed alone isn't the answer, and neither is autonomy for its own sake. An agent that acts without context creates noise. An agent that acts without governance creates risk. For AI to actually carry the load in a security program, three things have to exist together: context that unifies attack surface, threat, and vulnerability intelligence into one picture; reasoning that determines whether a given signal reaches your environment and how much it matters given live adversary activity; and policy that keeps every action scoped, auditable, and under your rules.
Miss any one of the three, and you get what the market has plenty of already: chatbots bolted onto old queues, or automation nobody trusts enough to turn on.
How Mallory is built to close it
This is the thesis behind Mallory, and behind the architecture we're introducing this week: a unified context and intelligence layer built from the ground up to feed action.
Mallory is architected around a context graph, fusing your entire attack surface with current threat and vulnerability intelligence, so every new CVE or adversary technique is checked against your actual exposure in minutes. A reasoning layer, the agentic harness, determines what matters and why, anchored to who is actually attacking you, not a static score. A policy and governance layer lets your team decide exactly how much autonomy the agents get, from routing a prioritized case into the ticketing tool you already use to handing routine exposure remediation to agents at scale.
The layers are fully separable on purpose. Some teams want a contextual intelligence source feeding workflows they already trust. Others are ready to let agents carry routine work end to end. Both run on the same context and reasoning underneath. What changes is how far your policy layer lets it go.

Adversaries got faster, and they got cheaper this year. Matching them is about closing the distance between knowing and acting, once, at the layer where the work actually happens.
Understand the threat. Eliminate exposure. It's time our architecture reflected it.
- jcran
Prioritize with context. Act with governance.
Mallory unifies your attack surface with live threat and vulnerability intelligence, then lets your team decide how far agents can act on it.
Start Free Trial