Mars Security automates threat-intel-to-detection in minutes

Mars Security's new engine converts CISA and Mandiant advisories into MITRE ATT&CK-mapped, backtested detection rules within minutes of publication.

Mars Security automates threat-intel-to-detection in minutes

Mars Security, a New York-based detection engineering platform founded by offensive security veterans, has launched Real-Time Intel-Based Detection, a capability designed to collapse the time between a published threat advisory and a live, validated detection rule. The company says the engine can convert intelligence from sources including CISA, Mandiant and Microsoft Threat Intelligence into production-ready rules within minutes, tested against the customer's own historical data before deployment.

The platform reads incoming advisories, extracts indicators, techniques and infrastructure, maps them to the MITRE ATT&CK framework, and writes detection queries in the native language of whichever telemetry source is relevant: CrowdStrike Falcon, Wiz, Splunk, AWS CloudTrail, Linux Sysmon, identity providers or data lakes such as Snowflake and Databricks. Each candidate rule is backtested against 30 days of the customer's own log data, with false-positive rates surfaced before the rule is offered for deployment. Analysts accept or dismiss with a single action.

The intelligence-to-detection gap

The release articulates a well-recognised problem in security operations: threat intelligence is widely purchased but rarely operationalised quickly. According to Mars, the conventional workflow requires a detection engineer to manually read an advisory, identify relevant log sources, write a query, test and tune it, then deploy. Across most security operations centres (SOCs), that cycle takes days to weeks. Adversaries, by contrast, rotate infrastructure within hours.

Co-founder and chief executive Shahaf Galili, a former offensive operator, said the gap between published intel and usable detections was apparent from the other side. "Threat intelligence has always told security teams what is happening in the world. It never handed them the detection to find it in their own environment," he said. "Mars does that now, and it tests the detection against your data before it goes anywhere near production."

The capability is included at no additional cost for existing Mars customers. The company says deployment takes hours, requires no data ingestion and does not necessitate replacing any existing security tooling. Mars is SOC 2 compliant and available on AWS Marketplace.

Market context and competitive positioning

The detection-engineering automation market has attracted growing interest as SOC teams face widening skill shortages alongside an accelerating threat landscape. Established SIEM vendors including Splunk (now part of Cisco) and Microsoft Sentinel offer rule libraries and threat-intelligence integrations, but the manual curation step has remained a persistent bottleneck. A number of well-funded startups are pursuing detection-as-code and AI-assisted triage approaches, making the space increasingly competitive for specialist platforms.

Mars's differentiation rests on the backtesting mechanism and the no-ingestion architecture, both of which reduce the friction typically associated with onboarding a new security tool. The coverage-gap analysis feature, which continuously maps existing detections against connected telemetry and flags blind spots, adds a posture-management dimension that pushes the product beyond simple rule generation. Recent coverage recommendations cited in the release include AWS CloudTrail logging tampering, Route 53 domain transfer abuse and pass-the-hash lateral movement, all active threat patterns in enterprise environments.

Andy Ellis, former CISO at Akamai Technologies, is quoted in the release endorsing the platform: "A campaign advisory used to sit in a queue for days before it became a rule anyone trusted. With Mars, it shows up already mapped, already tested against the environment it's meant to protect, and it actually holds up."

The company is backed by TLV Ventures, Jibe Ventures, Bullet Ventures, CCL and XPS. No funding round total has been disclosed publicly. As the platform extends to newer attack surfaces, including monitoring AI coding agents for credential leakage, Mars is positioning itself for a threat landscape that is widening faster than most security teams can manually track.