AI phishing analysis and incident response

AI triage your SOC can check.

MARS reads the suspicious mail your employees report and the incidents Microsoft Defender XDR raises. It gathers the evidence, asks an AI model for a judgement, and publishes only the answers that evidence supports.

Self-hostedBring your own modelVersion 1.5MIT licence
AI verdictPhishingSubject: Action required: your mailbox is almost full
  • The sending domain does not belong to the brand shownEvidence · header check
  • The link opens a copy of a sign-in pageEvidence · sandbox
  • The domain was registered this weekEvidence · domain age
Proposed: block the sender domainAwaiting approval
Needs reviewAnother case: the AI cited evidence that was never collected.
Illustration, not a screenshot

AI triage is easy to build and hard to trust.

Security teams want a model to take the first pass. Four things get in the way.

Too much to read

Reported mail and XDR incidents arrive faster than a small team can open them.

Confident is not correct

A model can sound certain and be wrong. A wrong "safe" is expensive.

The input is hostile

The mail was written by an attacker, sometimes with text aimed at the AI.

The data is sensitive

Reported mail holds internal correspondence. It cannot go to just any cloud service.

Evidence in, checked answer out.

Every case follows the same path, and the last step decides whether an analyst sees a verdict at all.

A case arrivesReported mail, an uploaded message file, an XDR incident
Evidence is gatheredSender, links, attachments, threat intelligence
The AI judgesA verdict, its reasons, the next steps
The answer is checkedEach claim must rest on evidence MARS collected
Passes: publishedThe analyst sees the verdict, the reasoning and the suggested steps.
Fails: needs reviewNo verdict is shown. The case goes to an analyst as it is.
Why MARS

The model is one step in a pipeline MARS controls.

Checks sit on both sides of it.

It can decline to answer

When evidence is thin, the case stays undecided and goes to a person.

Claims are checked against evidence

If the AI cites something MARS never collected, the conclusion does not stand.

Unfinished never looks final

A case still in progress shows its progress and nothing else.

People approve every action

MARS proposes remediation, never runs it alone, and verifies the outcome afterwards.

Attacker text stays data

Mail bodies, file names and links reach the model as material to examine, never as instructions.

You choose where the AI runs

A hosted model, a company gateway or a local model. The host decides which endpoints are allowed.

Two kinds of case, one standard.

Mail and XDR incidents are prepared differently and judged by the same rules.

Reported mail

Employees forward suspicious mail to a reporting mailbox. MARS picks it up automatically.

  1. Is the sender who they claim to be?Authentication results, the sending domain, brand impersonation, lookalike domains.
  2. Where do the links lead?Every link is scored and can be opened in an isolated browser.
  3. What is inside the attachments?Documents, archives and PDFs are examined without being run.
  4. Has this been seen before?Threat intelligence, past analyses, first-time senders.
  5. The AI weighs the evidenceA verdict, the reasons for it, the recommended steps.
Verdict PhishingSuspiciousLegitimate

XDR incidents

MARS syncs incidents from Microsoft Defender XDR and prepares each one before an analyst opens it.

  1. The incident itselfAlerts and the devices, accounts and files involved.
  2. Links to mailRelated mail MARS has analysed, and who else received it.
  3. Endpoint and account contextDevice activity, sign-in history, known vulnerabilities.
  4. What the organisation knowsWhat is normal in this environment and what is not.
  5. The AI weighs the evidenceA classification, its reasons, the evidence still missing.
Classification True positiveInformationalFalse positiveNeeds review

What lands on the analyst's desk

  • A verdict with its reasons and evidence
  • Recommended investigation and response steps
  • Indicators to pursue: links, domains, file hashes
  • Ready-to-run hunting queries for XDR incidents
  • A draft reply to the person who reported the mail
  • Response-time (SLA) tracking for incidents

Built around the model, not on faith in it.

The model reads and reasons. MARS decides what it sees and what becomes of its answer.

A fixed answer format

The model answers within defined fields and options. Anything else is discarded.

A model for each job

Mail, XDR incidents, sandbox results and the analyst assistant can each use a different one.

Budgets

Every call is counted against a daily budget before it is sent.

Tested before any change

Before a model or its instructions change, known cases are replayed. A drop in quality blocks the change.

Two languages

Answers are produced in English and translated into Traditional Chinese in the background.

An audit trail

Who did what, and when, is written to a signed log.

A working console, not a demo.

Eleven pages cover the analyst's day, in Traditional Chinese and English, light and dark.

Mail report overview
Report volume, results and mail waiting for a person.
Mail analysis
Upload a message file and analyse it now.
Mail history
Search and filter completed analyses.
Mailbox monitoring
Bring in new mail from the reporting mailbox.
AI processing
Cases being analysed, with their progress.
XDR incident queue
Review and triage incidents.
Advanced analysis
Exposure, hotspots and risk across incidents.
Remediation
Review proposed actions, run them, confirm the result.
IOC database
Manage indicators and sync outside intelligence.
Sandbox
Open suspicious links in isolation.
AI quality
Manage validation cases and track judgement quality.

MICROSOFT

Microsoft 365 mailDefender XDRDefender for EndpointEntra ID

THREAT INTELLIGENCE

VirusTotalAbuseIPDBURLhausThreatFoxMalwareBazaarPhishTankSTIX/TAXIICISA KEV

AI MODELS

AnthropicOpenAIGeminiLocal modelsCompany gateways

NOTIFICATIONS

EmailTeamsSlack

Your host, your data.

MARS is built for teams that cannot hand their mail to someone else.

Self-hosted

Analysis records and audit logs stay on the organisation's own host.

Controlled AI endpoints

The host administrator sets which AI endpoints may be reached. The console cannot widen the list.

Four roles

Read-only, analyst, SOC analyst, administrator. Secrets never appear in the console.

Offline updates

A host with no internet access can still be updated, with verification, a dry run and a backup first.

Little to operate

One instance with an embedded database, sized for one security team.

Open source

Released under the MIT licence.