Mars Security automates threat intelligence
Mars Security has launched a real-time detection capability that automatically converts threat advisories from sources like CISA and Mandiant into tested

Mars Security has announced a new capability that automatically turns newly published threat intelligence into validated detection rules within minutes. The Real-Time Intel-Based Detection feature converts advisories from sources like CISA and Mandiant into MITRE ATT&CK-mapped rules for CrowdStrike Falcon, Wiz, Splunk, and cloud telemetry, testing each one against 30 days of a customer's own data before deployment.
According to the company, this is the first platform to fully automate the path from threat advisory to production detection, including backtesting, without requiring data ingestion or changes to the existing security stack. The typical delay between a threat report's publication and a security team's ability to detect it can span days or weeks, a gap where many successful intrusions occur. Mars Security aims to close that gap automatically.
How the automated detection works
When new intelligence is published, Mars extracts relevant indicators, techniques, and infrastructure. It maps these to the MITRE ATT&CK framework and writes a detection rule in the native query language of the telemetry source that can see the threat. Supported sources include CrowdStrike Falcon, Wiz, Splunk, firewall logs, Linux Sysmon, identity providers, AWS telemetry, and data lakes like Snowflake and Databricks. Each rule carries a severity rating and is placed in a queue for review, where an analyst can either accept it to push it live or dismiss it.
No rule is offered without testing. Before presenting a rule, Mars runs the exact query against the customer's previous 30 days of data. It shows how many events the rule would have matched and how many of those would have been false positives. Teams can rerun this backtest over any time window they choose. The underlying indicators, such as domains, IP addresses, and hashes, are also scrutinized. They are scored against their false-positive history, and anything deemed too broad, too old, or historically noisy is dropped before it reaches a rule.
Shahaf Galili, CEO of Mars Security, explained the motivation. "We spent years on the offensive side, and the thing that surprised us most was how rarely anyone saw us, even when the intel on our tradecraft was already public," he said. "Threat intelligence has always told security teams what is happening in the world."
Coverage mapping and behavioral focus
The engine also operates in reverse, continuously mapping a customer's existing detection coverage against connected telemetry to flag critical gaps. Recent recommendations generated by the system have included detection for AWS CloudTrail logging tampering, Route 53 domain transfer abuse, pass-the-hash lateral movement, and suspicious Microsoft Graph API activity. For teams using detection-as-code practices, select recommendations arrive as an open pull request, ready for review and merging.
This focus on coverage is important because static rules often fail when attacker methods change. Built by former offensive operators, Mars targets behavior rather than signatures, aiming to maintain detection coverage as adversaries evolve their tools. The platform's hunt library is designed for this behavioral approach. The same engine now extends coverage to newer attack surfaces, such as monitoring AI coding agents and the credentials they might leak into logs, without requiring additional tools.
Ran Lerer, CTO of Mars Security, emphasized the operational impact. "A SOC should not need a two-week backlog to act on a report that took an attacker two hours to make obsolete," he said. "When the intel lands, the detection should already be written, already tested against your data, and waiting for a click." The platform's automated workflow is designed to make that ideal a practical reality for security teams.





