Mars SecurityNEW YORK, Sept. 08, 2026 (GLOBE NEWSWIRE) — Mars Security, the autonomous threat hunting and detection engineering platform founded by offensive security veterans, today announced Real-Time Intel-Based Detection, a capability that turns newly published threat intelligence into validated, ready-to-deploy detection rules within minutes of release.

Built by former offensive operators, the new capability converts advisories from CISA, Mandiant, and other intelligence sources into MITRE ATT&CK-mapped detection rules across CrowdStrike, Wiz, Splunk, and cloud telemetry, each one tested against 30 days of the customer’s own data before it goes live.

Mars believes it is the first platform to automate the complete path from threat advisory to production detection, including backtesting against the customer’s own environment, with no data ingestion and no changes to the existing security stack.

Every security team already pays for threat intelligence. Very little of it becomes a working detection. When CISA, Mandiant, Unit 42 or Microsoft Threat Intelligence publishes a report on a new campaign, malware family or APT group, a detection engineer still has to read it, pull the indicators and techniques, work out which log source can see them, write the query, test it, tune it and deploy it. Across most SOCs that cycle takes days to weeks. Attackers rotate infrastructure in hours. That delay, the gap between knowing about a threat and being able to detect it, is where most successful intrusions sit.

Mars now closes that gap automatically.

How it works

As new intelligence becomes available, Mars extracts the relevant indicators, techniques and infrastructure, maps them to MITRE ATT&CK, and writes the detection in the native query language of whichever telemetry can actually see the threat: CrowdStrike Falcon, Wiz, Splunk, firewall logs, Linux Sysmon, identity providers, AWS telemetry, or data lakes such as Snowflake and Databricks. Each rule carries a severity rating and lands in the team’s queue for review. Accept Rule pushes it live. Dismiss clears it.

Nothing ships untested. Before a rule is offered, Mars runs the exact query against the customer’s previous 30 days of data and shows how many events it would have matched and how many of those would have been false positives. Teams can rerun the backtest over any window they choose. The same scrutiny applies to the underlying indicators: domains, IP addresses and hashes are scored against their false-positive history, and anything too broad, too old or historically noisy is dropped before it ever reaches a rule.

“We spent years on the offensive side, and the thing that surprised us most was how rarely anyone saw us, even when the intel on our tradecraft was already public. Threat intelligence has always told security teams what is happening in the world. It never handed them the detection to find it in their own environment. Mars does that now, and it tests the detection against your data before it goes anywhere near production.” – Shahaf Galili, Co-Founder and CEO, Mars Security.

Coverage, not just alerts

The engine also works in the other direction. Mars continuously maps the customer’s existing detection coverage against the telemetry already connected and flags the gaps that matter. Recent recommendations include AWS CloudTrail logging tampering, Route 53 domain transfer abuse, pass-the-hash lateral movement and suspicious Microsoft Graph API activity. For teams running detection-as-code, select recommendations arrive as an open pull request, ready to review and merge.

That matters because static rules break the moment attacker tradecraft shifts. Mars was built by people who spent years watching detections fail from the other side, and its hunt library targets behavior rather than signatures so coverage holds as adversaries change tools. The same engine now extends to newer attack surfaces, including monitoring AI coding agents and the credentials they leak into logs, without buying another tool to watch them.

“A SOC should not need a two-week backlog to act on a report that took an attacker two hours to make obsolete. When the intel lands, the detection should already be written, already tested against your data, and waiting for a click.” – Ran Lerer, Co-Founder and CTO, Mars Security. “A campaign advisory used to sit in a queue for days before it became a rule anyone trusted. With Mars, it shows up already mapped, already tested against the environment it’s meant to protect, and it actually holds up. That is the first time detection has felt ahead of the threat instead of behind it.” – Andy Ellis, Former CISO, Akamai Technologies.

Availability

Real-Time Intel-Based Detection is available now to all Mars Security customers at no additional cost. Mars deploys in hours, requires no data ingestion, no tool replacement and no additional detection engineering headcount, and is available on AWS Marketplace.

Security teams can request a demo or read the technical documentation on the Mars website.

About Mars Security

Mars Security is the autonomous threat hunting and detection engineering platform that continuously converts threat intelligence into validated detections across an organization’s existing security stack. Founded by offensive security veterans Shahaf Galili, Ran Lerer and Matan Caspi, who bring more than 50 years of combined hands-on cyber offense experience, Mars queries SIEM, EDR, identity, cloud and data lake telemetry in place, with no ingestion and no rip-and-replace, and turns advisories into MITRE ATT&CK-mapped, backtested detection rules in minutes. Mars maps detection coverage gaps, delivers a behavior-based threat hunting library built from years of offensive operations, and replaces the patch treadmill with continuous detection engineering. Mars is SOC 2 compliant, available on AWS Marketplace, and backed by TLV Ventures, Jibe Ventures, Bullet Ventures, CCL and XPS.

Learn more at marssec.ai, download the Mars one-pager, read the Mars blog or follow Mars Security on LinkedIn.

Contact

Nir Lerer

Mars Security

Nir@Marssec.ai

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/7e78c9b9-f762-4c77-9c95-86d9d45b7a85


Primary Logo

About The Author