MARS
AI phishing analysis and incident response

AI triage
your SOC
can check.

MARS reads the suspicious mail your employees report and the incidents Microsoft Defender XDR raises. It gathers the evidence, asks an AI model for a judgement, and publishes only the answers that evidence supports.

Self-hostedBring your own modelVersion 1.5AGPL-3.0
MARS AI verdict card for a phishing email
A real MARS screen. The email is a synthetic example.
The problem

AI triage is easy to build and hard to trust.

Security teams want a model to take the first pass. Four things get in the way.

Too much to read

Reported mail and XDR incidents arrive faster than a small team can open them.

Confident is not correct

A model can sound certain and be wrong. A wrong "safe" is expensive.

The input is hostile

The mail was written by an attacker, sometimes with text aimed at the AI.

The data is sensitive

Reported mail holds internal correspondence. It cannot go to just any cloud service.

Keep exploring