Today marks another milestone in Cisco’s commitment to advancing AI-native cybersecurity. Following the success of Foundation-sec-8B and Foundation-sec-8B-Instruct, the Foundation AI team is proud to announce the public release of Llama-3.1-FoundationAI-SecurityLLM-8B-Reasoning (Foundation-sec-8B- Reasoning), now available on Hugging Face. Foundation-sec-8B-Reasoning is an 8-billion-parameter reasoning model purpose-built for cybersecurity workflows. It extends our Foundation-sec-8B and Foundation-sec-8B-Instruct models with structured reasoning capabilities that allow it to think through complex, multi-step security problems before presenting an answer.
Elevating Security Reasoning
Effective cybersecurity analysis requires deep, multi-l…
Today marks another milestone in Cisco’s commitment to advancing AI-native cybersecurity. Following the success of Foundation-sec-8B and Foundation-sec-8B-Instruct, the Foundation AI team is proud to announce the public release of Llama-3.1-FoundationAI-SecurityLLM-8B-Reasoning (Foundation-sec-8B- Reasoning), now available on Hugging Face. Foundation-sec-8B-Reasoning is an 8-billion-parameter reasoning model purpose-built for cybersecurity workflows. It extends our Foundation-sec-8B and Foundation-sec-8B-Instruct models with structured reasoning capabilities that allow it to think through complex, multi-step security problems before presenting an answer.
Elevating Security Reasoning
Effective cybersecurity analysis requires deep, multi-layered reasoning. Analysts often need to connect signals across logs, code, configurations, and threat intelligence to identify root causes, predict attacker behavior, and recommend defensive actions.
Generic reasoning models can assist, but they may lack the ability to understand the specific logic and structure of security workflows. Foundation-sec-8B-Reasoning bridges that gap by combining instruction-following with explicit reasoning traces. This enables it to explain not only ”what” it recommends, but also ”why” — helping analysts build trust in AI-assisted decisions.
Built for Security Workflows
Foundation-sec-8B-Reasoning extends Foundation-sec-8B-Instruct with reasoning fine-tuning to deliver domain-specific analytical capabilities across the security lifecycle. The model is built to support security workflows that demand logical reasoning, including tasks like threat modeling, attack path analysis, risk evaluation, and security architecture review. Foundation-sec-8B-Reasoning can be applied directly to a wide range of cybersecurity reasoning scenarios, such as:
- System and Configuration Analysis – Evaluate systems, configurations, and policies to identify vulnerabilities and improve security posture.
- **Adversary Behavior Mapping **– Correlate threat intelligence with attacker tactics to understand likely next moves and predict adversarial behavior.
- Threat Detection and Analysis – Analyze logs and telemetry to identify malicious activity and strengthen detection rules.
- Access and Privilege Management – Assess permissions and entitlements to detect over-privileged accounts and insider risks.
- **Context Enrichment and Investigation **– Connect scattered observables, provide reasoning for findings, and help analysts make confident, explainable decisions.
To explore how Foundation-sec-8b-Reasoning can be applied across real-world security workflows, check out the use case cookbook on our public Github repository. These hands-on notebooks offer practical examples to help teams get started, inspire new applications, and accelerate development on top of the model.
Reasoning That Outperforms
Foundation-sec-8B-Reasoning establishes a new benchmark for security-specific reasoning, outperforming larger general-purpose models on multi-step analytical tasks.
| Benchmark | Foundation-sec-8B-Reasoning | Llama 3.1 8B | GPT-5-Nano |
| CTI-RCM | 0.753 | 0.531 | 0.672 |
| CTI-VSP | 0.856 | 0.811 | 0.822 |
| CTI-Reasoning | 0.411 | 0.335 | 0.431 |
The model uses test-time reasoning to reach higher accuracy on complex questions. It delivers state-of-the-art performance on vulnerability root-cause mapping and reasoning benchmarks while maintaining the compact, deployable 8B footprint.
Safe, Open, and Deployable Anywhere
Like the previous Foundation AI models, Foundation-sec-8B-Reasoning is released under an open-weight license, empowering the community to customize, audit, and deploy securely:
- Foster innovation by enabling experimentation in security workflows.
- Accelerate deployment with open tooling, no API dependencies, and a 32K context window.
- Maintain control by running locally, on-prem, or in air-gapped environments.
- Stay compliant by keeping sensitive data within secure environments.
Safety remains foundational. When combined with LlamaGuard, Foundation-sec-8B-Reasoning achieves 98.25% protection on HarmBench.
Start Building Today
- Grab the weights — Download Foundation-sec-8B-Reasoning on Hugging Face and run it on-prem, in secure cloud enclaves, or in air-gapped labs — no commercial agreement required.
- Follow the recipes — The Foundation AI Cookbook offers deployment guides, retrieval templates, and agent examples.
- Join the community — Pilot new workflows, contribute prompts or fine-tunes, and feed your findings back into the open-source ecosystem.
We’d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.
Cisco Security Social Media
Authors
Yaron Singer
VP of AI and Security at Foundation
Foundation AI

Cisco Cybersecurity Viewpoints
Where security insights and innovation meet. Read the e-book, see the video, dive into the infographic and more...

Why Cisco Security?
Explore our Products & Services