Armadin, the AI-native cybersecurity startup founded by Mandiant founder Kevin Mandia, has raised $255.5 million in Series B funding at a valuation topping $2.5 billion.
The company has now raised a total of $445 million only seven months after its public launch.
Mandia founded Mandiant in 2004 and sold the incident response and threat intelligence firm to FireEye in a $1 billion deal in 2014 before its later $5.4 billion acquisition by Google
Andreessen Horowitz and existing investor Accel co-led the round, with participation from new investors Bain Capital Ventures and Redpoint.
The new investment comes just months after Armadin formally launched with $189.9 million in funding in March 2026.
Armadin had previously surfaced quietly in late 2025 with an initial $24 million seed investment.
The Palo Alto, California-based company will use the latest funding to expand its agentic security platform and scale its research, model training, and go-to-market operations.

Armadin was founded to address what Mandia sees as a growing mismatch between AI-powered attackers and conventional security defenses. As frontier models reduce the time and expertise required to discover and exploit vulnerabilities, the company argues that periodic penetration tests and vulnerability scanners cannot provide an accurate, continuously updated picture of an organization’s exploitable risk.
“AI lets an attacker find and chain weaknesses faster than any human team can respond,” Mandia said in the company’s funding announcement.
Rather than assess individual vulnerabilities in isolation, Armadin deploys swarms of specialized AI agents designed to behave like skilled adversaries. The agents probe an organization’s attack surface, attempt to exploit weaknesses, and combine seemingly minor security issues into validated attack paths.
Those paths can extend from an internet-facing vulnerability through lateral movement and ultimately to the compromise of cloud resources or sensitive systems. The company says its platform shows customers the paths that attackers could use, along with the potential blast radius, allowing defenders to address exploitable risks instead of responding to thousands of disconnected security findings.
The company says it is already running agentic attack campaigns in production for Fortune 500 companies and government customers.
In August, Armadin and agentic security operations provider TENEX.ai conducted a live AI cyberattack during a three-day exercise. During the exercise, Armadin launched 1,300 attacks involving 26,000 agents and approximately 17 million offensive actions against more than 25,000 services. The exercise produced 238 security findings, including 98 described as significant, and chained them into 38 validated attack paths.
The agents operated without privileged credentials, source code access, or whitelisting of security controls, according to the company. Armadin says each action passed through a control layer overseen by a safety model trained using feedback from human security experts.
Mandia serves as Armadin’s chief executive. His co-founders include CTO Travis Lanham, chief offensive security officer Evan Peña, and chief architect David Slater.
Existing backers 8VC, Ballistic Ventures, GV, In-Q-Tel, Kleiner Perkins, and Menlo Ventures also participated in the funding.
Related: Island Raises $400 Million at $6.4 Billion Valuation
Related: Cyera Raises $400 Million at $12+ Billion Valuation
