AI & ML

Mars Security Enhances Threat Detection with Real-Time Intel Automation

Mars Security's new Real-Time Intel-Based Detection automates the conversion of threat intelligence into actionable security rules, streamlining defense operations.

Sep 08, 2026 3 min read
Sign in to save

Automated Threat Detection Revolutionized

Mars Security has unveiled a significant upgrade to its platform: Real-Time Intel-Based Detection. This new functionality transforms how enterprise security operations centers (SOCs) manage threat intelligence, allowing them to turn newly released advisories into validated detection rules almost instantaneously.

Streamlining the Process

Developed by experienced professionals from the military's red team, this capability integrates incoming threat reports from notable organizations like CISA, Mandiant, and Microsoft Threat Intelligence. The platform does not simply track threats; it processes raw data and converts it into actionable detection logic that aligns with the MITRE ATT&CK framework. This functionality spans various security tools, including popular solutions like CrowdStrike Falcon, Splunk, and various data lakes.

One standout feature is the automatic benchmarking of each generated rule against 30 days of historical telemetry from the organization. This preemptive analysis eliminates the need for extensive data ingestion or significant adjustments to existing infrastructure.

Closing the Gap Between Intelligence and Action

SOCs typically allocate substantial resources to threat intelligence feeds. However, the challenge lies in operationalizing the insights gleaned from these feeds. Traditional workflows demand the time-consuming manual parsing of advisories, extracting indicators of compromise (IOCs), and meticulous creation of custom queries. This process can span several days or even weeks, creating a disadvantage as attackers adapt and evolve their strategies in real-time.

Mars Security specifically targets this critical delay by automating the transition from intelligence collection to practical application:

  • Automated Query Generation: As new advisories are released, Mars extracts relevant indicators and tactically maps them to the MITRE ATT&CK framework, creating tailored queries for connected log collectors.
  • Historical Backtesting: Before rules are shared for approval, the generated queries are run against 30 days of historical data to assess efficacy and predict false-positive occurrences.
  • Noise Reduction: Indicators such as domain names and IP addresses are evaluated against historical data to weed out untrustworthy or irrelevant markers.
  • Efficient Review Process: Rules that have passed validation head into an analyst queue, where security teams can review telemetry matches and launch them into production with a single click.

Proactive Security Measures

"While operating offensively, we observed the immense gap between threat intelligence and actual detection," stated Shahaf Galili, Co-Founder and CEO of Mars Security. "Now, security teams receive guidance on what is happening in the cyber landscape, along with tested detection solutions tailored for their specific environment."

Besides reacting to external threats, Mars also conducts reverse assessments of existing security measures to highlight gaps. The platform has made real-time recommendations concerning CloudTrail logging and anomalies in Microsoft Graph API interactions, among other examples. For those employing detection-as-code practices, Mars offers actionable insights as open pull requests for easier integration into existing systems.

Staying Ahead of Evolving Threats

The approach taken by Mars focuses on behavioral mechanics rather than static indicators, ensuring that detection adapts alongside threat actor methodologies. Its architecture even addresses cutting-edge operational challenges, including monitoring potential vulnerabilities arising from AI tools and credential leaks in security logs.

Ran Lerer, Co-Founder and CTO, emphasizes the urgency of the issuance timeline: "There’s no need for an SOC to wait days to act on a threat that an adversary can adapt to within hours. Our system ensures that when intel arrives, the detection mechanisms are not only ready but already validated against real data."

Immediate Availability

The Real-Time Intel-Based Detection feature is available to all current Mars Security clients at no extra charge. The deployment is rapid, integrates effortlessly with existing security setups, and can be accessed through the AWS Marketplace.

About Mars Security

Mars Security stands at the forefront of automated threat detection and hunting, continuously translating threat intelligence into actionable insights across various security platforms. Founded by veterans with extensive offensive security experience, Mars enables organizations to query their existing telemetry without needing to overhaul their current systems. With ongoing detection updates and a focus on behavior-based response mechanisms, Mars is paving the way for proactive defense strategies.

To learn more, visit marssec.ai.

Source: William Smith · www.csoonline.com

Comments

Sign in to join the discussion.