Armadin: Kevin Mandia's AI Agent Swarm That Attacks You First

Rachid Idali

by Rachid Idali

Two years ago, 20 people a month typed "armadin" into Google. As of August 2026 it is 5,400, and the word did not exist as a company until March. The thing people are looking up is a swarm of AI agents that breaks into your network on purpose, finds the exact route an attacker would take, and hands you the map before anyone else gets there.

Here is what makes the curve worth reading rather than just reporting. In the same two years that Armadin went from nothing to a $2.5 billion valuation, searches for "pentester", the job title its product replaces part of, fell 87%. Nobody ranking for the company name has either number. The funding stories have the round size. We have the demand behind it, month by month, and the search terms it is eating.

Key takeaways:

  1. "armadin" grew from 20 to 5,400 US monthly searches in two years, up 26,900%, classified as EXPONENTIAL in the Rising Trends database (data as of August 2026).
  2. The company raised $255.5 million in a Series B on October 1, 2026 at a valuation over $2.5 billion, co-led by Andreessen Horowitz and Accel, taking total funding to $445 million seven months after it left stealth.
  3. Armadin is Kevin Mandia's second act. He founded Mandiant, the incident response firm Google bought, and his new founding team is three more Mandiant alumni plus CrowdStrike founder George Kurtz on the board.
  4. The product is a swarm, not a scanner. In a single three-day engagement the company says it ran 26,000 agents and 17 million offensive actions, chaining 38 validated attack paths.
  5. The job title is shrinking while the machine category climbs. "pentester" is 18,100 searches a month and down 87% in two years. Over the same window "ai security platform" is up 6,400% and "ai pentest" is up 555%.
  6. Distribution is already borrowed, not built: Armadin Red ships inside CrowdStrike's Falcon ecosystem and inside Palo Alto Networks' Unit 42 service.

Let's get into it.

The numbers

Here is the monthly search volume for "armadin" over the last two years, straight from our database. Until late 2025 the line is flat on the floor.

Bar chart of monthly Google search volume for armadin from Sep 2024 to Aug 2026, 20 to 5,400, peak 6,600 in Mar 2026

Source: Rising Trends database, data as of Aug 2026

The breakout month is March 2026, the month the company left stealth, and it is also the all-time peak at 6,600. What happens next is the part that matters. Most launch spikes give the volume back within a quarter. This one settled onto a plateau and then stepped up again in August to 5,400, which is 252 times the three-month average from two years earlier. A year ago the term did 30 searches a month.

The second chart is the reason this company exists. These are two-year changes for the terms around it in our database.

Horizontal bar chart: The pentester is shrinking, the robot is not. ai security platform +6,400%, agentic security +3,100%, mindfort +2,500%, ai pentest +555%, ai red teaming +233%, xbow +125%, pentester -87%

Source: Rising Trends database, data as of Aug 2026

Read it as one sentence: the thing you hire is falling and the thing you subscribe to is rising. Searches for "pentester" are down 87% over two years. Searches for "ai pentest" are up 555% and agentic security is up 3,100%. Armadin did not create that substitution. It raised $445 million to stand in the middle of it.

What Armadin actually does

The pitch on the company's own platform page is four words: know all paths in, all the time. The product is an offensive one. You point it at your own estate and it attacks you, continuously, the way a competent human adversary would.

Armadin platform page headline reading Know all paths in, all the time, above a banner saying Armadin safely executes the largest recorded autonomous AI attack

Source: armadin.com, captured 2026-10-07

The company describes three phases. Reconnaissance charts the attack surface and profiles the people on it. Adaptive scouting probes in parallel and learns from each failed attempt. Precision strike turns the validated routes into real kill chains. Armadin's own counters on that page claim 443,000 agents launched against real targets, zero false positive findings, and 119 seconds as the fastest path to full domain compromise.

The distinction the company keeps drawing is against two incumbents at once. A scheduled penetration test is a snapshot, and a snapshot ages badly when frontier models can turn a disclosure into a working exploit in hours. A vulnerability scanner runs constantly but scores each finding on its own, so it never tells you that three medium-severity issues add up to a route to your backups. Armadin's answer is chaining: the Hyperattack page describes a knowledge graph of the whole attack surface, tens of thousands of agents executing in parallel against it, and a safety model trained on human feedback sitting over every action.

The clearest look at the output is a joint engagement with TENEX.ai at an unnamed global institution, written up on August 3, 2026. Over three days the swarm generated 17 million offensive actions, launching 1,300 attacks through 26,000 agents against more than 25,000 services, with no credentials and no whitelisting. It produced 238 findings, 98 of them significant, and chained 38 validated attack paths. On the defending side, TENEX.ai triaged all 101,169 alerts the exercise threw off, across 231 billion raw events. Attacker activity was one event in every 13,338. The release estimates the same forensic work would have taken five people about 2,400 hours.

Why it's suddenly everywhere

Three dated events sit under the curve.

March 10, 2026: the launch. Armadin came out of stealth with $189.9 million in combined Seed and Series A funding led by Accel, which the company called the largest combined Seed and Series A in cybersecurity history. Searches went from 1,600 in February to 6,600 that month. CTO Travis Lanham's line in the announcement is the product in one sentence: "Before Armadin, you could not put a nation-state level adversary inside every network 24/7."

April 30, 2026: two distribution deals in one day. Armadin Red went into CrowdStrike's Falcon ecosystem through its Project QuiltWorks coalition, and into Palo Alto Networks' Unit 42 Frontier AI Defense service as its external attack validation layer. George Kurtz, CrowdStrike's founder, put the case plainly: "Frontier AI has collapsed the exploit window, the era of point-in-time assessments is over."

October 1, 2026: the Series B. $255.5 million at a valuation over $2.5 billion, co-led by a16z and Accel. Mandia's quote is the thesis: "Offense is uniquely advantaged right now. AI lets an attacker find and chain weaknesses faster than any human team can respond."

That round is what pushed the name past the security trade press and into general finance and tech feeds. This clip from @silicontrades, posted on October 4, 2026, is the version most people outside the industry saw.

The practitioner reaction is less generous. A widely read r/cybersecurity thread titled "hot take: 90% of AI pentesting tools can't do anything a competent operator can't" has operators saying they run autonomous pentesting internally and still find that "Burp plus a good operator still beats most AI pentest platforms on web apps." That is what people say, not a measurement, but it is the objection Armadin's zero-false-positive claim is aimed at.

The people and money behind it

This is a Mandiant reunion with a venture-scale balance sheet. Kevin Mandia founded Mandiant, ran it through its sale to FireEye and then to Google, and is now building the offensive mirror image of it. Three of his co-founders came with him: Travis Lanham as CTO, Evan Pena as Chief Offensive Security Officer, David Slater as Chief Architect. The company page also lists Barbara Massa as COO and Frank Verdecanna as CFO, both Mandiant veterans, and puts George Kurtz, the CEO and founder of CrowdStrike, on the board alongside Accel's Ping Li and Ballistic Ventures co-founder Jake Seid.

DateEventFigureSource
Mar 10, 2026Seed plus Series A, led by Accel$189.9M combinedArmadin release
Apr 30, 2026CrowdStrike and Palo Alto Networks partnershipsTerms not disclosedArmadin releases
Aug 3, 2026Hyperattack with TENEX.ai26,000 agents, 38 attack pathsArmadin release
Oct 1, 2026Series B, co-led by a16z and Accel$255.5M at over $2.5B, $445M totalArmadin release

Two caveats belong here. Every figure in that table comes from the company's own announcements, including the valuation, which is a priced round rather than a filing. And Armadin has published no revenue, no customer count and no logo wall. It says it runs campaigns for Fortune 500 enterprises and government customers, and In-Q-Tel's presence in both rounds supports the second half of that, but the commercial scale behind a $2.5 billion price is not public.

Who it's up against

Here is where the company sits in raw demand against the rest of its category.

Horizontal bar chart: Who people search for in AI offensive security. pentester 18,100, xbow 8,100, ai cybersecurity 6,600, armadin 5,400, ai red teaming 1,300, ai security platform 1,300, ai pentest 720, mindfort 260

Source: Rising Trends database, data as of Aug 2026

Those eight terms draw 41,780 searches a month between them, and the largest single one is still a job title. The named rival to watch is XBOW, the autonomous pentesting startup that topped a US bug bounty leaderboard and is still the most-searched brand in the set at 8,100 a month. It is also down 55% year over year while Armadin is up 17,900%, which is what a first mover looks like when a better-funded second mover arrives. Mindfort, the other AI offensive-security brand in our data, is tiny at 260 but up 2,500% in two years.

The real competition is not another startup, though. It is the services line inside the incumbents, and Armadin's answer to that was to partner rather than fight: CrowdStrike and Palo Alto Networks both resell it rather than build it. That is the same pattern we tracked across the agentic layer of the software market, where the platform buys the agent instead of growing one.

What it means for the industry

Security testing is moving from a project to a subscription. A penetration test was a thing you bought once or twice a year and received as a PDF. An agent swarm is a thing that runs while you sleep. That changes the budget line from consulting to software, which is the whole reason this category can carry venture multiples, and it is why the procurement questions in our cybersecurity trends for 2026 have shifted from "who is testing us" to "what is testing us right now".

The entry rung of offensive security is the one at risk. The 87% fall in "pentester" searches is not a measure of employment, but it is a measure of what people believe they should be learning. Senior operators who can scope an engagement and judge business context are the ones training these models. The checklist layer underneath them is what a swarm reproduces cheaply, and Armadin's own podcast has an episode called "Why AI Beats Human Pentesting", which tells you how hard the company is willing to press that argument.

Offense as a product is a governance problem waiting to happen. A tool that chains exploits autonomously is the same tool in either direction, and the industry knows it. Armadin's answer is a safety model and a hardened sandbox, and in September it joined NVIDIA's Open Agent Safety Platform alongside more than a hundred other companies, contributing offensive agents to test the runtime boundary. The same containment question runs through every self-improving AI system we have covered.

Where this is heading

Watch whether the plateau becomes a staircase. The pattern to look for on the live Armadin trend page is another step up that is not attached to a funding headline. That would mean buyers rather than readers, and it is the single cleanest signal that this is a product business rather than a founder story.

Watch the category terms, not just the brand. "ai security platform" at 6,400% growth over two years and "agentic security" at 3,100% are the generic demand Armadin is trying to own. If those keep climbing while the brand flattens, somebody else is capturing them.

Watch for the first contested result. Zero false positives is a strong claim, and the market has not yet had its public argument about what counts as a validated attack path. The first customer or researcher to dispute a finding in detail will tell you more about this category than the next round will.

The pattern underneath all of it is one we keep seeing in our data: a brand appears from nothing, absorbs the search demand of the human role it automates, and is worth billions before most of the industry has used it. That happened with micro1 in AI training data. It is happening faster here, because in security the other side is automating too.


Want to spot the next breakout company before the funding headlines? Read our guide on how to identify market trends, follow the live armadin trend page, or browse what is breaking out right now on the Rising Trends dashboard.

Unlock More Trends & Insights

Never miss a trend again!

Thousands of Emerging Trends

Thousands of Breakout Apps

Mega Trends

Trend Analysis Tool

Get Access Now
Join +5,000 happy users

Written By

Rachid Idali

Founder of Rising Trends, helping entrepreneurs identify and capitalize on emerging market opportunities through expert trend analysis and insights.

Armadin: Kevin Mandia's AI Agent Swarm That Attacks You First