Mars Security launches Real-Time Intel-Based Detection, turning advisories into validated rules in minutes
Mars Security announced Real-Time Intel-Based Detection, a capability that converts newly published advisories from CISA, Mandiant, Unit 42, and Microsoft into MITRE ATT&CK-mapped detection rules written in the native query languages of customer tools and…
On 2026-09-08, Mars Security, an autonomous threat hunting and detection engineering platform founded by former offensive security operators, announced Real-Time Intel-Based Detection. The capability ingests newly published threat intelligence from sources including CISA, Mandiant, Unit 42, and Microsoft Threat Intelligence, maps indicators to MITRE ATT&CK, and authors native query logic across connected infrastructure such as CrowdStrike Falcon, Wiz, Splunk, Sysmon, firewalls, identity providers, AWS, Snowflake, and Databricks. The company claims the pipeline compresses an advisory-to-detection cycle that typically takes days to weeks down to minutes. Every rule is backtested against 30 days of the customer's historical telemetry to quantify false positives before analyst approval and one-click deployment, with heuristic indicator scoring pruning noisy, stale, or overly broad indicators. The platform also maps existing detection coverage and surfaces gaps — cited examples include AWS CloudTrail tampering, pass-the-hash movement, Route 53 abuse, and Microsoft Graph API anomalies — and can deliver some recommendations as open pull requests for detection-as-code workflows. According to Help Net Security, it extends to monitoring AI coding agents and credentials leaked into logs without new tooling. Per CSO Online, the feature is free for existing customers and available via AWS Marketplace.
- Mars Security announced Real-Time Intel-Based Detection on 2026-09-08 (reports from Help Net Security at 13:43 UTC and CSO Online at 15:05 UTC).
- Ingests advisories from CISA, Mandiant, Unit 42, and Microsoft Threat Intelligence and converts them into MITRE ATT&CK-mapped detection rules.
- Rules are written in native query languages for CrowdStrike Falcon, Wiz, Splunk, Sysmon, firewalls, identity providers, AWS, Snowflake, and Databricks.
- Every rule is backtested against 30 days of customer telemetry, with false-positive counts shown before analyst approval and one-click deployment.
- Heuristic indicator scoring automatically drops noisy, stale, or overly broad indicators.
- Coverage gap analysis flags issues such as AWS CloudTrail tampering, pass-the-hash movement, Route 53 abuse, and Microsoft Graph API anomalies.
- Some recommendations are delivered as open pull requests for detection-as-code workflows.
- Mars Security says the pipeline produces rules within minutes versus a typical days-to-weeks SOC cycle; Help Net Security frames this as a company claim.
Coverage timelineoldest first · each row is one article
- · 8d agoMars Security brings threat intelligence to detection in real time
Help Net Security· 24
Mars Security launched Real-Time Intel-Based Detection, converting advisories from CISA and Mandiant into backtested MITRE ATT&CK-mapped detection rules for CrowdStrike, Wiz, and Splunk.