Mars Security, an autonomous threat hunting and detection engineering platform founded by offensive cybersecurity veterans, today announced Real-Time Intel-Based Detection. The milestone expansion equips enterprise security operations centers (SOCs) to convert newly published threat intelligence advisories into production-ready, validated detection rules within minutes of release.Developed by former military red team operators, the capability systematically ingests threat reports from organizations such as CISA, Mandiant, Unit 42, and Microsoft Threat Intelligence. The platform translates raw indicators and adversary techniques into native, MITRE ATT&CK-mapped detection logic across an enterprise’s active security infrastructure—including CrowdStrike Falcon, Wiz, Splunk, firewall logs, Linux Sysmon, identity providers, and data lakes like Snowflake and Databricks. Every generated rule is automatically benchmarked against 30 days of the organization’s historic telemetry prior to deployment, eliminating the need for data ingestion or infrastructure changes.Accelerating the Pipeline From Threat Advisory to Active DefenseEnterprises invest heavily in threat intelligence feeds, yet operationalizing that data into active detection logic remains a persistent industry challenge. Traditional detection engineering workflows require security analysts to manually parse advisory briefs, extract indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs), identify corresponding log sources, write custom queries, and execute manual tuning cycles.Across most security organizations, this manual workflow consumes days or weeks. In contrast, threat actors rotate infrastructure and modify tools within hours. Mars Security closes this critical exposure window by automating the complete transition from intelligence ingestion to production deployment:Automated Native Query Authoring: As advisories land, Mars extracts pertinent indicators and tactics, maps them to MITRE ATT&CK framework nodes, and authors native query logic tailored to whichever connected log collector maintains visibility over the threat.Empirical Historical Backtesting: Prior to presenting a rule for team approval, Mars executes the generated query against 30 days of historical customer telemetry to quantify event matches and project false-positive rates.Heuristic Noise Reduction: Indicators such as domain names, IP addresses, and file hashes undergo automated scoring against historical noise baselines. Stale, overly broad, or historically noisy indicators are pruned automatically before reaching a rule.Streamlined Review & Deployment: Validated rules populate an analyst queue where security teams can inspect telemetry matches, rerun backtests over custom windows, and deploy rules into production with a single click.“We spent years on the offensive side, and the thing that surprised us most was how rarely anyone saw us, even when the intel on our tradecraft was already public. Threat intelligence has always told security teams what is happening in the world. It never handed them the detection to find it in their own environment. Mars does that now, and it tests the detection against your data before it goes anywhere near production.” – Shahaf Galili, Co-Founder and CEO, Mars Security.Continuous Defensive Gap Analysis and Behavioral Threat HuntingIn addition to processing external threat streams, Mars operates continuously in reverse—mapping existing defensive coverage against connected telemetry sources to surface critical blind spots. Recent automated recommendations include detecting AWS CloudTrail logging tampering, Route 53 domain transfer abuse, pass-the-hash lateral movement, and anomalous Microsoft Graph API interactions. For teams utilizing detection-as-code workflows, Mars delivers actionable recommendations directly as open pull requests for seamless code review and deployment.By prioritizing behavioral mechanics over static signatures, Mars ensures detection integrity persists even as threat actors alter their tools or infrastructure. The underlying architecture also addresses emerging operational surfaces, including monitoring AI coding agents and identifying credentials inadvertently leaked into security logs.“A SOC should not need a two-week backlog to act on a report that took an attacker two hours to make obsolete. When the intel lands, the detection should already be written, already tested against your data, and waiting for a click.” – Ran Lerer, Co-Founder and CTO, Mars Security.“A campaign advisory used to sit in a queue for days before it became a rule anyone trusted. With Mars, it shows up already mapped, already tested against the environment it’s meant to protect, and it actually holds up. That is the first time detection has felt ahead of the threat instead of behind it.” – Andy Ellis, Former CISO, Akamai Technologies.AvailabilityReal-Time Intel-Based Detection is immediately available to all existing Mars Security customers at no additional cost. Mars deploys within hours, requires no centralized data ingestion, preserves existing security tooling, and is available on the AWS Marketplace.About Mars SecurityMars Security is the autonomous threat hunting and detection engineering platform that continuously converts threat intelligence into validated detections across an organization’s existing security stack. Founded by offensive security veterans Shahaf Galili, Ran Lerer, and Matan Caspi—who bring more than 50 years of combined hands-on cyber offense experience—Mars queries SIEM, EDR, identity, cloud, and data lake telemetry in place, with no ingestion and no rip-and-replace. Mars maps detection coverage gaps, delivers a behavior-based threat hunting library built from years of offensive operations, and replaces the patch treadmill with continuous detection engineering. Mars is SOC 2 compliant, available on AWS Marketplace, and backed by TLV Partners, Jibe Ventures, Bullet Ventures, CCL, and XPS.Learn more at marssec.ai.