Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Mars Security Launches Real-Time Intel-Based Detection Engine - News Directory 3

Mars Security Launches Real-Time Intel-Based Detection Engine

September 8, 2026 Lisa Park Tech
News Context
At a glance
  • When organizations read reports from CISA, Mandiant, Unit 42, or Microsoft Threat Intelligence about a new malware family or adversary group, a detection engineer usually has to manually...
  • To prevent broken rules from hitting production environments, Mars runs every generated query against the customer's previous 30 days of data before deployment.
  • Threat intelligence has always told security teams what is happening in the world.
Original source: cio.com

<>

Automating Threat Advisory to Production Detection

When organizations read reports from CISA, Mandiant, Unit 42, or Microsoft Threat Intelligence about a new malware family or adversary group, a detection engineer usually has to manually extract indicators, write queries, and test them. According to the sources, that manual cycle typically takes security teams days or weeks. Mars Security automates this entire path by extracting relevant indicators and techniques from fresh advisories and mapping them directly to the MITRE ATT&CK framework.

The platform writes rules in the native query language of whichever security tool or data store can observe the threat. Supported telemetry sources include CrowdStrike Falcon, Wiz, Splunk, firewall logs, Linux Sysmon, identity providers, AWS telemetry, Snowflake, and Databricks. Each generated rule receives a severity rating before landing in a review queue where operators can click to accept or dismiss it, as noted in the platform’s release details.

Backtesting Against Customer Data and Eliminating Noise

To prevent broken rules from hitting production environments, Mars runs every generated query against the customer’s previous 30 days of data before deployment. The system reports how many historical events the rule would have matched and calculates potential false positives. As stated by Mars Security Co-Founder and CEO Shahaf Galili, threat intelligence has traditionally told defenders what is happening globally without handing them specific detections for their own networks.

Threat intelligence has always told security teams what is happening in the world. It never handed them the detection to find it in their own environment. Mars handles this functionality currently, evaluating detections against your data well ahead of any production deployment.

Shahaf Galili, Co-Founder and CEO, Mars Security

Beyond testing queries, the platform screens underlying indicators such as domains, IP addresses, and file hashes against their false-positive histories. Items deemed too broad, outdated, or historically noisy are dropped automatically before reaching a rule queue. Akamai Technologies Former CISO Andy Ellis noted that the capability makes detection engineering feel proactive rather than reactive.

With Mars, it shows up already mapped, already tested against the environment it’s meant to protect, and it actually holds up. That is the first time detection has felt ahead of the threat instead of behind it.

Andy Ellis, Former CISO, Akamai Technologies

Coverage Gaps and Availability

The detection engineering engine also audits existing security coverage in reverse by scanning connected telemetry to flag missing visibility. The engine has recently generated recommendations that feature detections for suspicious Microsoft Graph API activity, pass-the-hash lateral movement, AWS CloudTrail logging tampering, and Route 53 domain transfer abuse. For teams utilizing detection-as-code workflows, selected recommendations are delivered as open pull requests ready for review.

According to the company announcement, the real-time intel-based detection capability is available immediately to all Mars Security customers at no additional cost. The software deploys in hours through the AWS Marketplace without requiring data ingestion changes, tool replacements, or additional headcount. Founded by offensive security veterans Shahaf Galili, Ran Lerer, and Matan Caspi, Mars Security maintains SOC 2 compliance across its autonomous detection engineering platform.

Mars Security Launches Real-Time Intel-Based Detection Engine
Photo: cybersecurity-insiders.com

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Keep reading

  • LG Smart TVs Caught Eavesdropping on Users Even When Powered Off
  • Sony A7V Review: Testing Unusual Lenses and Creative Video Gear

Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com