Offense as a Business Model: Mandiant Founder's Armadin Raises $255.5M Series B at $2.5B+ Valuation
Kevin Mandia's AI-native offensive security startup Armadin raised $255.5M co-led by a16z and Accel, reaching a $2.5B+ valuation just seven months after emerging from stealth.
Seven months. That is all the time it took Kevin Mandia’s second act in cybersecurity to go from stealth debut to a $2.5 billion-plus valuation. Armadin, the AI-native offensive security company founded by the man who built Mandiant and sold it to Google for $5.4 billion, announced today a $255.5 million Series B co-led by Andreessen Horowitz and Accel, with participation from new investors Bain Capital Ventures and Redpoint alongside returning backers 8VC, Ballistic Ventures, Google Ventures, In-Q-Tel, Kleiner Perkins, and Menlo Ventures. The round brings the Palo Alto company’s total funding to $445 million.
The raise lands at a moment when the argument Armadin was built to make has stopped being controversial. Frontier AI models are compressing the time between vulnerability disclosure and a working exploit from weeks to hours, and attackers chaining individually low-severity weaknesses into full kill chains now operate at machine speed. The old cadence of the industry — a penetration test once a year, a vulnerability scanner scoring each finding in isolation — was designed for adversaries who needed humans in the loop. Those adversaries are retiring.
What Armadin actually sells
The company’s pitch is “effective autonomous security,” and the product mechanics are straightforwardly adversarial. Armadin deploys what it calls AI Hyperattacks: an autonomous swarm of specialized agents that reason like a skilled adversary across an organization’s entire attack surface. Unlike a scanner, which evaluates a misconfiguration or an outdated library on its own and assigns it a severity score, the swarm tries to chain findings together the way a real attacker would — from an unauthenticated remote code execution bug at the perimeter, through lateral movement, to full cloud compromise.
What the customer buys is not a list of vulnerabilities. It is the exact attack paths an adversary could use in production today, along with the blast radius of each path, and the ability to sever them before anyone exploits them. In a market drowning in thousands of disconnected security findings, the framing resonates: defenders do not need more alerts, they need to know which five alerts combine into a catastrophe.
Mandia’s own framing is blunter. “Offense is uniquely advantaged right now,” he said in the announcement. “AI lets an attacker find and chain weaknesses faster than any human team can respond. The only way to build a defense that keeps pace is to train it against the best offense available, every day. That is what we built.”
The proof point: 17 million offensive actions
Skeptics of agentic security demos have long had a fair objection: controlled exercises are staged, credentials are often handed over, and controls are quietly whitelisted to let the agent succeed. Armadin’s answer is a live-fire exercise it ran in August with TENEX.ai, an agentic security operations provider, which the companies describe as the largest controlled live AI cyberattack on record.
The numbers from the three-day exercise are worth sitting with. Armadin launched 1,300 attacks involving roughly 26,000 agents and approximately 17 million offensive actions against more than 25,000 services. The exercise produced 238 security findings, 98 of them classified as significant, and chained those findings into 38 validated attack paths. Critically, the agents operated without privileged credentials, without source code access, and without whitelisting of security controls — and every action passed through a control layer overseen by a safety model trained on feedback from human security experts.
That safety layer matters as much as the raw numbers. An autonomous system executing millions of offensive actions inside a production enterprise needs guardrails that are demonstrably more than marketing. The stakes of getting this wrong are not a bad report card; they are an outage, or worse, caused by your own security tooling.
Why the valuation is defensible
A $2.5 billion valuation seven months post-launch invites skepticism, but the context softens it. Armadin is not a concept raise: it says it is already running agentic attack campaigns in production for Fortune 500 enterprises and government customers. The buyer side of this market is demonstrably anxious — Microsoft’s disclosure last week of Storm-3168/JadePuffer, the first documented agentic ransomware operation that wiped 100+ Azure storage accounts in seven minutes, gave every CISO in the world a concrete answer to “why would I need this now.”
The investor logic tracks the founding team. Beyond Mandia himself, the co-founders include CTO Travis Lanham, chief offensive security officer Evan Peña, and chief architect David Slater. Accel’s Ping Li, who led the Series A, called the company’s progress “the standard for AI-powered offensive security” in less than a year. a16z’s David George went further: “Kevin has been on the front lines of the most consequential breaches in history, and he has built a team that pairs elite red teamers with world-class AI engineers. We invested because we believe Armadin will become the defining security company of the AI era.”
That phrase — the defining security company of the AI era — is a bet that security undergoes a generational platform shift, and that the winner of the shift is built AI-first rather than retrofitted. It is the same logic that produced a long line of “X for the AI era” theses, but security has a property most categories lack: the adversary is genuinely changing behavior, not just the tooling. When both sides of a conflict adopt a new technology, spending on the defensive side rarely stays flat.
The deeper trend: agentic vs. agentic
The raise is also a data point in a broader reordering of the cybersecurity industry. If attackers are moving to autonomous agents — and the evidence from JadePuffer to the rising deception rates documented in Chinese agent studies suggests they are — then defense built around human-paced analysis loses by construction. The industry’s answer is converging on symmetrical escalation: deploy your own agents to find and fix what their agents would find and exploit.
This is why the “continuous” framing in Armadin’s pitch is doing real work. A penetration test is a snapshot; a scanner is a periodic census; an autonomous adversary simulation is a running process. The companies that internalize the difference — treating attack-path validation as an always-on workload rather than an annual compliance event — are the ones building for the threat model that actually exists in late 2026.
There are open questions, of course. Regulators and insurers have not decided how to treat autonomous offensive actions inside regulated environments, and the line between “validated kill chain” and “we ran an exploit in your production” is thinner than either side admits. The market will also have to see whether chaining low-severity findings into dramatic kill chains remains a differentiator, or whether every incumbent — from Rapid7 to CrowdStrike — ships a credible agentic red-team module within eighteen months and compresses the category.
But for now, the vote of confidence is unambiguous. Nearly half a billion dollars in total funding, every existing investor returning, and a valuation that took most security companies a decade to reach — delivered in a single fiscal quarter. Mandia built Mandiant over eighteen years and sold it twice, once to FireEye for $1 billion and then to Google for $5.4 billion. The third build appears to be running on a considerably faster clock, because the threat it counters is too.
Sources
- [1] https://www.prnewswire.com/news-releases/armadin-raises-255-5-million-series-b-to-scale-effective-autonomous-security-302895278.html
- [2] https://www.securityweek.com/kevin-mandias-armadin-raises-255-million-at-2-5-billion-valuation/
- [3] https://www.wsj.com/pro/cybersecurity/ai-cyber-startup-armadin-raises-255-million-f5e8f52a
- [4] https://www.helpnetsecurity.com/2026/10/01/armadin-raises-255-5-million-funding/