Mars Security has introduced Real-Time Intel-Based Detection, an enterprise security platform designed to automatically convert threat advisories into validated production rules within minutes.
The newly unveiled capability translates intelligence reports from sources including CISA, Mandiant, Unit 42, and Microsoft Threat Intelligence into MITRE ATT&CK-mapped detection rules. Built by former offensive operators, the system automatically writes queries in the native languages of various monitoring platforms without requiring data ingestion changes to the existing security stack.
The platform supports a broad array of enterprise infrastructure, including CrowdStrike Falcon, Wiz, Splunk, firewall logs, Linux Sysmon, identity providers, AWS telemetry, and data lakes such as Snowflake and Databricks. Before any detection rule goes live, the system backtests it against the customer’s previous 30 days of data to gauge event matches and filter out historical false positives.
“Threat intelligence has always told security teams what is happening in the world. It never handed them the detection to find it in their own environment. Mars does that now, and it tests the detection against your data before it goes anywhere near production,” said Shahaf Galili, CEO of Mars Security.
In addition to rule generation, the engine maps existing detection coverage against connected telemetry to flag operational gaps, such as AWS CloudTrail logging tampering, Route 53 domain transfer abuse, pass-the-hash lateral movement, and suspicious Microsoft Graph API activity. The platform also extends coverage to modern attack surfaces by monitoring AI coding agents and identifying leaked credentials in log files.
“A SOC should not need a two-week backlog to act on a report that took an attacker two hours to make obsolete. When the intel lands, the detection should already be written, already tested against your data, and waiting for a click,” stated Ran Lerer, CTO of Mars Security.