Term
Foundation-Sec-8B
Foundation-Sec-8B is Cisco Foundation AIs open, cybersecurity-specialized language model (2025). It extends Llama-3.1-8B via continued pretraining on about 5 billion security tokens and is available under the permissive Apache-2.0 license.
Foundation-Sec-8B — explained in more detail
Foundation-Sec-8B is the first open model from Cisco Foundation AI, a group building AI infrastructure specifically for cybersecurity. It is an 8-billion-parameter base language model built on Llama-3.1-8B and specialized through continued pretraining on a curated security corpus — threat intelligence reports, vulnerability databases, incident response documentation and security standards, roughly 5.1 billion tokens.
The focus pays off measurably: on security-specific benchmarks Foundation-Sec-8B scores around 3 to 9 points above the generic Llama-3.1-8B and, on cyber threat intelligence tasks, reaches the level of the much larger Llama-3.1-70B in places. The weights and tokenizer are published under the permissive Apache-2.0 license on Hugging Face — enabling customization and self-hosting without vendor lock-in. Additional variants include Foundation-Sec-8B-Instruct (instruction-tuned) and Foundation-Sec-8B-Reasoning.
Example / In practice
In a Security Operations Center (SOC), Foundation-Sec-8B can triage alerts, classify vulnerabilities, translate attacker behavior into readable investigation narratives and suggest playbook steps. Because it is small and open, it can run on-premise — relevant when sensitive log and incident data must not leave your own network.
Distinction from similar terms
Unlike a generic frontier model, Foundation-Sec-8B is deliberately trained for one domain. It is a model, not a finished product like Microsoft Security Copilot (which combines a model with tooling and data). The security focus is a cross-vendor use case — comparable to Googles Sec-Gemini.