Mars Security Automates Threat Intel to Detection in Minutes
Mars Security launches a new capability that automatically converts threat intelligence into validated, deployable detection rules, drastically reducing the time from advisory to defense.

Mars Security has unveiled a new capability called Real-Time Intel-Based Detection, designed to bridge the critical gap between the release of threat intelligence and the deployment of effective security detections. This platform, built by former offensive security professionals, aims to automate the entire process of translating advisories from sources like CISA and Mandiant into actionable detection rules.
The core innovation lies in its ability to rapidly convert threat intelligence into MITRE ATT&CK-mapped rules. These rules are then automatically backtested against 30 days of a customer's own data before being presented for review. This rigorous validation process is intended to ensure that the detections are effective against real-world threats within the specific customer environment and to minimize the risk of false positives, a common challenge in security operations.
Traditionally, the cycle from a threat advisory being published to a functional detection rule being deployed can take days or even weeks. This delay is often exploited by attackers who can change their infrastructure and tactics rapidly. Mars Security claims its new capability closes this gap, enabling security teams to respond to emerging threats in minutes rather than days.
The platform works by extracting relevant indicators, techniques, and infrastructure from new intelligence feeds. It then maps these to the MITRE ATT&CK framework and generates detection rules tailored to the specific telemetry sources available in a customer's environment, such as CrowdStrike Falcon, Wiz, Splunk, and various cloud logs. Each rule is assigned a severity rating and presented to the security team for approval or dismissal.
Before any rule is deployed, Mars Security subjects it to a backtesting process. The system runs the proposed detection query against the customer's historical data from the past 30 days, providing insights into how many events it would have matched and the potential rate of false positives. Indicators like domains and IP addresses are also scored for their historical noise levels, with problematic ones being filtered out.
Beyond generating new detections, the Real-Time Intel-Based Detection engine also assesses existing detection coverage within a customer's environment. It identifies gaps against known threat behaviors and provides recommendations for improvement, sometimes even delivering these as open pull requests for teams using detection-as-code practices.
Mars Security emphasizes that its platform integrates seamlessly with existing security stacks, requiring no data ingestion or replacement of current tools. The company states that its approach focuses on behavior rather than signatures, aiming to provide more resilient detection coverage as adversary tactics evolve. The capability is available immediately to all Mars Security customers at no additional cost.
This new article from Help Net Security provides further detail on Mars Security's Real-Time Intel-Based Detection capability, highlighting its development by former offensive operators and its integration with platforms such as CrowdStrike, Wiz, and Splunk. It also emphasizes the system's unique approach of testing rules against 30 days of customer data before deployment to ensure efficacy and minimize false positives.