Back to mobile site

ThreatHunter.ai Releases MILBERT 2.1

September 2, 2026 8:31 AM EDT

The identity engine now reasons across users, sessions, and attack sequences — including the login that already succeeded

BREA, Calif., Sept. 2, 2026 /PRNewswire/ -- ThreatHunter.ai, a Service-Disabled Veteran-Owned Small Business, today released MILBERT 2.1 for hybrid Active Directory and Entra ID. Version 2.1 adds continuous user-behavior tracking and is built to catch identity attacks that start after a successful login: adversary-in-the-middle phishing, session theft, and token replay.

MILBERT 2.1 does not treat a completed MFA challenge as proof of a legitimate user. It scores the principal, the session, and the sequence around both.

Two models, one decision

A gradient-boosted model scores each authentication event. A fine-tuned language model reads a window of events for a user or session. The language model may label an attack chain, write a short rationale, and recommend Allow, Monitor, Investigate, or Block. It does not revoke sessions or change directory state. Session kill, token revocation, and related actions stay with policy and with hunt analysts when the customer is on ARGOS.

Training used production authentication telemetry, MFA session-theft cases, and live user-behavior observations. Raw corpus counts are not being published.

What 2.1 detects

AiTM phishing and proxy MFA bypass after a valid login; stolen cookies, refresh-token abuse, and sessions replayed from attacker infrastructure; device, network, or timing that does not match the user's baseline; backdoor accounts and service-account abuse; hybrid on-premises-to-cloud pivots; and privilege use that diverges from established behavior.

"Attackers do not break in. They log in," said James McMurry, founder and CEO of ThreatHunter.ai. "Every incident we have worked this year started with a valid credential. MFA does not catch it when the attacker steals the session after the user finishes the prompt. Version 2.1 watches the person behind the credential, and the session after the login."

In March 2026 the company published the first public documentation of an Iranian operational server used to pre-position against Stryker Corporation, five days before the March 11 wipe. The identity lesson is the same: the compromise often looks legitimate until the sequence is reconstructed.

A single MILBERT 2.1 instance scores more than 74,000 authentication events per second at 99.94 percent ROC-AUC on infrastructure ThreatHunter.ai owns and operates. That path is required for CMMC and FERPA customers who cannot send identity telemetry to public-cloud AI services. MILBERT is an analysis layer. It does not replace the identity provider, MFA, or Conditional Access.

MILBERT 2.1 is available now at threathunter.ai/milbert.

About ThreatHunter.ai

ThreatHunter.ai is a Service-Disabled Veteran-Owned Small Business in Brea, California, with offices in Washington, D.C., and Las Vegas. An MSSP Alert Top 50 firm, it provides managed threat hunting and identity detection to defense contractors, higher education, and commercial enterprises. CEO James McMurry is a U.S. Coast Guard veteran and co-founder of VETCON. threathunter.ai

Media contact

ThreatHunter.ai Press Desk • [email protected] • +1 888 674 9001 • [email protected]

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/threathunterai-releases-milbert-2-1--302867698.html

SOURCE ThreatHunter.ai



Serious News for Serious Traders! Try StreetInsider.com Premium Free!

You May Also Be Interested In





Related Categories

PRNewswire, Press Releases