Mars Security, formed by veterans of offensive cybersecurity, has unveiled its Real-Time Intel-Based Detection feature. This innovation empowers security operations centers (SOCs) to swiftly convert up-to-date threat intelligence into actionable detection rules within minutes of their release.
Designed by a team of former military red team operators, this capability automates the ingestion of threat reports from major sources like CISA, Mandiant, Unit 42, and Microsoft Threat Intelligence. The platform effectively interprets raw threat indicators and techniques, translating them into detection logic aligned with the MITRE ATT&CK framework, which is then applied across an organization’s security infrastructure. This includes integration with solutions like CrowdStrike Falcon, Wiz, and data lakes such as Snowflake and Databricks.
Streamlining Threat Response
Organizations typically invest significantly in threat intelligence feeds, but effectively implementing this information into active detection has been a long-standing issue. Traditional methods involve extensive manual processes where security analysts must sift through advisories, extract relevant indicators, and craft custom queries. This cumbersome approach can take days or even weeks, while adversaries adapt their strategies within hours. Mars Security’s automation significantly reduces this exposure time by fast-tracking the intelligence-to-deployment pipeline:
- Automated Query Creation: Upon the arrival of new advisories, Mars composes queries by identifying key indicators and mapping them to relevant MITRE ATT&CK nodes.
- Historical Validation: The platform validates the generated queries against 30 days of historical telemetry before they are sent for team approval, assessing potential matches and estimating false-positive rates.
- Noise Reduction: Through automated scoring, irrelevant indicators—such as outdated or overly broad domain names—are filtered out before becoming part of a rule.
- Efficient Review and Implementation: Validated detection rules are readily accessible for security analysts, who can quickly review matches and deploy rules with a single click.
Shahaf Galili, Co-Founder and CEO of Mars Security, emphasizes that threat intelligence has often outlined what’s happening globally without sufficiently enabling detection within organizations. “Mars converts threat intel into actionable detection that’s validated against your data,” he asserts.
Proactive Defense Mechanism
Mars not only processes external threat information but also analyzes existing security measures to pinpoint gaps in defenses. Recent automated insights have highlighted potential vulnerabilities, such as AWS CloudTrail log alterations and suspicious Microsoft Graph API interactions. For security teams utilizing detection-as-code practices, Mars provides actionable insights directly as open pull requests, facilitating rapid code reviews and deployment.
By focusing on behavioral detection rather than static signatures, Mars ensures its defenses remain effective even while adversaries evolve their tactics. This architecture also allows for monitoring new operational risks, including the scrutiny of AI-driven code agents and the identification of exposed credentials in logs.
Co-Founder and CTO, Ran Lerer, argues that SOC teams shouldn’t be delayed by lengthy backlogs. When intel arrives, the corresponding detection should already be prepared, tested, and ready for immediate implementation.
Andy Ellis, former CISO of Akamai Technologies, cites the ease of using Mars: “Previously, an advisory could languish for days until it became a trusted rule. Now, it’s instantly mapped and tested against relevant environments, maintaining a proactive stance against threats.”
Immediate Availability
The Real-Time Intel-Based Detection capability is now accessible to current Mars Security customers without any added costs. Mars can be deployed within a few hours, requiring no central data collection and retaining all existing security tools. The solution is also listed on the AWS Marketplace.
About Mars Security
Mars Security specializes in autonomous threat detection and response, continuously transforming threat intelligence into verified detections across an organization’s security stack. Founded by offensive security authorities Shahaf Galili, Ran Lerer, and Matan Caspi, who carry over 50 years of combined cybersecurity experience, Mars integrates directly with existing telemetry without data ingestion requirements. The company actively identifies coverage gaps and offers a threat hunting library informed by years of offensive experience. Mars holds SOC 2 compliance, is available on the AWS Marketplace, and is backed by notable investors including TLV Partners and Jibe Ventures.
For more information, visit marssec.ai.