MARS
How it works

Evidence in, checked answer out.

Every case follows the same path, and the last step decides whether an analyst sees a verdict at all.

  1. 01

    A case arrives

    Reported mail, an uploaded message file, an XDR incident
  2. 02

    Evidence is gathered

    Sender, links, attachments, threat intelligence
  3. 03

    The AI judges

    A verdict, its reasons, the next steps
  4. 04

    The answer is checked

    Each claim must rest on evidence MARS collected
Passes: publishedThe analyst sees the verdict, the reasoning and the suggested steps.
Fails: needs reviewNo verdict is shown. The case goes to an analyst as it is.

Two kinds of case, one standard.

Mail and XDR incidents are prepared differently and judged by the same rules.

Reported mail

Employees forward suspicious mail to a reporting mailbox. MARS picks it up automatically.

  • Is the sender who they claim to be?Authentication results, the sending domain, brand impersonation, lookalike domains.
  • Where do the links lead?Every link is scored and can be opened in an isolated browser.
  • What is inside the attachments?Documents, archives and PDFs are examined without being run.
  • Has this been seen before?Threat intelligence, past analyses, first-time senders.
  • The AI weighs the evidenceA verdict, the reasons for it, the recommended steps.
Verdict PhishingSuspiciousLegitimate

XDR incidents

MARS syncs incidents from Microsoft Defender XDR and prepares each one before an analyst opens it.

  • The incident itselfAlerts and the devices, accounts and files involved.
  • Links to mailRelated mail MARS has analysed, and who else received it.
  • Endpoint and account contextDevice activity, sign-in history, known vulnerabilities.
  • What the organisation knowsWhat is normal in this environment and what is not.
  • The AI weighs the evidenceA classification, its reasons, the evidence still missing.
Classification True positiveInformationalFalse positiveNeeds review

What lands on the analyst's desk

  • A verdict with its reasons and evidence
  • Recommended investigation and response steps
  • Indicators to pursue: links, domains, file hashes
  • Ready-to-run hunting queries for XDR incidents
  • A draft reply to the person who reported the mail
  • Response-time (SLA) tracking for incidents

Where the data goes

Everything MARS keeps stays on your host. Two kinds of traffic leave it, and you decide whether either does.

Comes in

Reporting mailboxMail your employees report, read from Microsoft 365.
Uploaded filesMessage files an analyst submits by hand.
Defender XDRIncidents and their alerts.
Defender for Endpoint and Entra IDDevice, email and sign-in activity MARS looks up for a case.
Your host
MARS
Gather evidenceAsk the modelCheck the answerPublish or hold for review
Local databaseAnalysis records, the signed audit log and settings. Nothing here is stored anywhere else.
Threat intelligenceOnly the sources you configure.Sends indicators such as domains, URLs and file hashes.Returns reputation and context.
AI modelA hosted model, a company gateway or a local model. The host sets which endpoints are allowed.Sends the evidence for one case, with internal names replaced if you choose.Returns a structured answer, which MARS then checks.

Goes out

Analyst consoleVerdicts, evidence and recommended steps, in the browser.
NotificationsEmail, Teams or Slack, if you set them up.
Approved actionsResponse steps a person has approved, sent through Microsoft's own interfaces.

The controls on each of these paths are on the Security page.