The following content is a press release provided by a third-party.

Mars Security Launches Real-Time Intel-to-Detection Engine That Turns Live Threat Intelligence Into Backtested Detections in Minutes


Mars Security, the autonomous threat hunting and detection engineering platform founded by offensive security veterans, today announced Real-Time Intel-Based Detection, a capability that turns newly published threat intelligence into validated, ready-to-deploy detection rules within minutes of release.

Built by former offensive operators, the new capability converts advisories from CISA, Mandiant, and other intelligence sources into MITRE ATT&CK-mapped detection rules across CrowdStrike, Wiz, Splunk, and cloud telemetry, each one tested against 30 days of the customer’s own data before it goes live.

Mars believes it is the first platform to automate the complete path from threat advisory to production detection, including backtesting against the customer’s own environment, with no data ingestion and no changes to the existing security stack.

Every security team already pays for threat intelligence. Very little of it becomes a working detection. When CISA, Mandiant, Unit 42 or Microsoft Threat Intelligence publishes a report on a new campaign, malware family or APT group, a detection engineer still has to read it, pull the indicators and techniques, work out which log source can see them, write the query, test it, tune it and deploy it. Across most SOCs that cycle takes days to weeks. Attackers rotate infrastructure in hours. That delay, the gap between knowing about a threat and being able to detect it, is where most successful intrusions sit.

ADVERTISEMENT

Mars now closes that gap automatically.

How it works

As new intelligence becomes available, Mars extracts the relevant indicators, techniques and infrastructure, maps them to MITRE ATT&CK, and writes the detection in the native query language of whichever telemetry can actually see the threat: CrowdStrike Falcon, Wiz, Splunk, firewall logs, Linux Sysmon, identity providers, AWS telemetry, or data lakes such as Snowflake and Databricks. Each rule carries a severity rating and lands in the team’s queue for review. Accept Rule pushes it live. Dismiss clears it.

Nothing ships untested. Before a rule is offered, Mars runs the exact query against the customer’s previous 30 days of data and shows how many events it would have matched and how many of those would have been false positives. Teams can rerun the backtest over any window they choose. The same scrutiny applies to the underlying indicators: domains, IP addresses and hashes are scored against their false-positive history, and anything too broad, too old or historically noisy is dropped before it ever reaches a rule.

Coverage, not just alerts

The engine also works in the other direction. Mars continuously maps the customer’s existing detection coverage against the telemetry already connected and flags the gaps that matter. Recent recommendations include AWS CloudTrail logging tampering, Route 53 domain transfer abuse, pass-the-hash lateral movement and suspicious Microsoft Graph API activity. For teams running detection-as-code, select recommendations arrive as an open pull request, ready to review and merge.

Availability

Real-Time Intel-Based Detection is available now to all Mars Security customers at no additional cost. Mars deploys in hours, requires no data ingestion, no tool replacement and no additional detection engineering headcount, and is available on AWS Marketplace.

ADVERTISEMENT

Security teams can request a demo or read the technical documentation on the Mars website.

About Mars Security

Mars Security is the autonomous threat hunting and detection engineering platform that continuously converts threat intelligence into validated detections across an organization’s existing security stack. Founded by offensive security veterans Shahaf Galili, Ran Lerer and Matan Caspi, who bring more than 50 years of combined hands-on cyber offense experience.

Contact

Nir Lerer

Mars Security

[email protected]

Disclaimer

ADVERTISEMENT