ZeroHour
Story · 1 source · 1 articlefirst updated ()

Mars Security Launches Real-Time Intel-Based Detection, Turning Live Threat Intelligence Into Backtested ATT&CK-Mapped Detections in Minutes

infoToolsimportance 24
What's new: First merged story for this event (no previous summary). The change is a product launch on 2026-09-08: Mars Security added Real-Time Intel-Based Detection, an automated advisory-to-detection pipeline with 30-day backtesting, ATT&CK mapping, coverage-gap analysis, and AI-agent credential leak monitoring, offered free to existing customers and via AWS Marketplace. This is a product announcement,…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

On 2026-09-08, Mars Security announced Real-Time Intel-Based Detection, which converts advisories from CISA, Mandiant, Unit 42, and Microsoft Threat Intelligence into MITRE ATT&CK-mapped detection rules within minutes, each backtested against 30 days of the…

All three sources report the same launch: Mars Security announced a capability called Real-Time Intel-Based Detection that ingests newly published threat intelligence from CISA, Mandiant, Unit 42, and Microsoft Threat Intelligence, maps indicators to MITRE ATT&CK, and authors detection rules in the native query languages of connected telemetry sources, including CrowdStrike Falcon, Wiz, Splunk, firewalls, Sysmon, identity providers, AWS telemetry, and data lakes such as Snowflake and Databricks, with no data ingestion or stack changes required. Every rule is backtested against 30 days of the customer's own historical telemetry, with matched-event counts and false positives shown before deployment; rules carry severity ratings and require analyst approval before going live, with one-click deployment per CSO Online. Indicator/heuristic scoring automatically prunes noisy, stale, or overly broad indicators (Help Net Security; CSO Online). The platform also maps existing detection coverage and flags gaps, with cited examples including AWS CloudTrail tampering, Route 53 abuse, pass-the-hash movement, and Microsoft Graph activity, and extends monitoring to AI coding agents and credentials leaked into logs without new tooling. The feature is available at no additional cost to existing customers and via AWS Marketplace. The vendor claims the pipeline cuts the typical days-to-weeks SOC cycle to minutes (Help Net Security). No source conflicts on the core facts; minor variance: one report describes the Sysmon integration as "Linux Sysmon" while another says "Sysmon".

  • Product: Real-Time Intel-Based Detection, announced 2026-09-08 by Mars Security (reported by Cyber Security News at 13:20 UTC, Help Net Security at 13:43 UTC, and CSO Online at 15:05 UTC).
  • Converts newly published advisories from CISA, Mandiant, Unit 42, and Microsoft Threat Intelligence into production-ready detection rules within minutes; each rule is MITRE ATT&CK-mapped.
  • Every rule is backtested against 30 days of the customer's own telemetry before deployment, showing how many events it would have matched and its false positives.
  • Rules carry severity ratings and require analyst approval before going live; deployment is one-click (CSO Online).
  • Rules are written in native query languages across CrowdStrike Falcon, Wiz, Splunk, firewalls, Sysmon (one report specifies "Linux Sysmon"), identity providers, AWS telemetry, and data lakes including Snowflake and Databricks, with no data…
  • Indicator/heuristic scoring automatically drops noisy, stale, or overly broad indicators (Help Net Security; CSO Online).
  • Coverage-gap analysis flags gaps such as AWS CloudTrail tampering, Route 53 abuse, pass-the-hash movement, and Microsoft Graph activity/API anomalies.
  • Extends monitoring to AI coding agents and credentials leaked into logs without new tooling (Cyber Security News; Help Net Security).

Coverage timeline

  1. · 8d ago
    Cyber Security News· 24
    Mars Security Launches Real-Time Intel-to-Detection Engine That Turns Live Threat Intelligence Into Backtested Detections in Minutes

    Mars Security launched Real-Time Intel-Based Detection, converting advisories into MITRE ATT&CK-mapped, backtested detection rules for CrowdStrike, Wiz, and Splunk within minutes.