Skip to content
TrackPodcasts
technologySep 8, 20266:38

Mars Security Launches Real-Time Intel-to-Detection Engine

About this episode

This story was originally published on HackerNoon at: https://hackernoon.com/mars-security-launches-real-time-intel-to-detection-engine.
Built by former offensive operators, the new capability converts advisories from CISA, Mandiant
Check more stories related to undefined at: https://hackernoon.com/c/undefined. You can also check exclusive content about #cybersecurity, #mars, #cybernewswire, #press-release, #cyber-threats, #cyber-security-awareness, #cybercrime, #good-company, and more.

This story was written by: @cybernewswire. Learn more about this writer by checking @cybernewswire's about page, and for more stories, please visit hackernoon.com.

Interactive timestamps

Jump to segment

Get every episode summarized

Each time The Good Tech Companies publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

74 searchable segments. Every word is indexed and playable.

Mars Security Launches Real-Time Intel-to-Detection Engine

The Good Tech Companies

0:00
6:38

Full transcript

The Good Tech CompaniesMars Security Launches Real-Time Intel-to-Detection Engine. Machine-transcribed; use the interactive transcript above to jump the player to any line.

0:00This audio is presented by Hacker Noon, where anyone can learn anything about any technology. Mars Security launches real-time intel to Detection Engine by Cyber Newswire. New York, New York, United States, September 8, 2026, Cyber Newswire, Mars Security. The autonomous threat hunting and detection engineering platform founded by offensive security veterans. Today announced real-time intel-based detection, a capability that turns newly published threat intelligence into validated, ready to deploy detection rules within minutes of release. Built by former offensive operators, the new capability converts advisories from CISA, Mandient, and other intelligence sources into Miter ATT and CK-MAP detection rules across CrowdStrike, Wiz, Splunk, and Cloud Telemetry. Each one tested against 30 days of the customer's own data before it goes live. Mars believes it is the first platform to automate the complete path from threat advisory to production detection, including backtesting against the customer's own environment, with no data ingestion and no changes to the existing

1:03security stack. Every security team already pays for threat intelligence. Very little of it becomes a working detection. When CISA, Mandient, Unit 42 or Microsoft threat intelligence publishes a report on a new campaign, malware family or app group. A detection engineer still has to read it, pull the indicators and techniques. Work out which log source can see them, write the query, test it, tune it and deploy it. Across most SOCs that cycle takes days to weeks, attackers rotate infrastructure in hours. That delay, the gap between knowing about a threat and being able to detect it, is where most successful intrusions sit. Mars now closes that gap automatically. How would WORKSA's new intelligence becomes available? Mars extracts the relevant indicators, techniques and infrastructure, maps them to Miter ATT and CK, and writes the detection in the native query language of whichever telemetry can actually see the threat. Crowdstrike Falcon, Wiz, Splunk, Firewall logs, Linux Sysmin, Identity providers, AWS telemetry, or data lakes such as

2:08Snowflake and Data Bricks. Each rule carries a severity rating and lands in the team's queue for review. Except rule pushes it live, dismiss clears it, nothing ships untested, before a rule is offered. Mars runs the exact query against the customer's previous 30 days of data and shows how many events it would have matched and how many of those would have been false positives. Team scan rerun the back test over any window they choose. The same scrutiny applies to the underlying indicators. Domains, IP addresses and hashes are scored against their false positive history, and anything too broad, too old or historically noisy is dropped before it ever reaches a rule. Greater than, we spent years on the offensive side, and the thing that surprised us most greater than was how rarely anyone saw us, even when the intel on our trade craft was greater than already public. Fred Intelligence has always told security teams what is greater than happening in the world. It never handed them the detection to find it in their greater than own environment. Mars does that now, and it tests the detection against your greater than data before it goes

3:10anywhere near production. Shahaf Ghalili, co-founder and greater than CEO, Mars Security. Coverage, not just alerts the engine also works in the other direction. Mars continuously maps the customer's existing detection coverage against the telemetry already connected and flags the gaps that matter. Recent recommendations include a WS Cloud Trail logging tampering, Route 53 domain transfer abuse, pass the hash lateral movement and suspicious Microsoft Graph API activity. For teams running detection as code, select recommendations arrive as an open pull request, ready to review and merge. That matters because static rules break the moment attacker trade craft shifts. Mars was built by people who spent years watching detections fail from the other side, and its hunt library targets behavior rather than signatures so coverage holds as adversaries change tools. The same engine now extends to newer attack surfaces, including monitoring AI coding agents and the credentials they leak into logs, without buying another tool to watch them. Greater than, a SOC should not need a two-week

4:14backlog to act on a report that took in greater than attacker two hours to make obsolete. When the Intel lands, the detection greater than should already be written, already tested against your data, and waiting for a greater than click. Ran Learer, co-founder and CTO, Mars Security. A campaign advisory greater than used to sit in a queue for days before it became a rule anyone trusted. With, Mars, it shows up already mapped, already tested against the environment it's greater than meant to protect, and it actually holds up. That is the first time detection greater than has fell to head of the threat instead of behind it. Andy Ellis, former CISO, greater than Akamai technologies. Availability real-time Intel-based detection is available now to all Mars security customers at no additional cost. Mars deploys in hours, requires no data ingestion, no tool replacement and no additional detection engineering headcount, and is available on a WS marketplace. Security teams can request a demo or read the technical documentation on the Mars website. About Mars security Mars security

5:18is the autonomous threat hunting and detection engineering platform that continuously converts threat intelligence into validated detections across an organization's existing security stack. Founded by offensive security veterans Sha'af Galeili, Ran Learer and Madden Kaspie, who bring more than 50 years of combined hands on cyber-offense experience. Mars queries Seem, EDR, Identity, Cloud and Data Lake telemetry in place, with no ingestion and no rip and replace, and turns advisories into Miter ATT and CK mapped, back-tested detection rules in minutes. Mars maps detection coverage gaps, delivers a behavior-based threat hunting library built from years of offensive operations, and replaces the patch treadmill with continuous detection engineering. Mars is SOC 2 compliant, available on a WS marketplace, and backed by TLV ventures, GYB ventures, Bull Adventures, CCL and XPS. Learn more at Marsick. I, download the Mars One-Pager, read the Mars blog or follow Mars Security on LinkedIn. Contact near Learer Mars Security near at Marsick.

6:23AI This Story was published as a press release by Cyber Newswire under HackerNune Business blogging program Thank You for Listening to this HackerNune Story, read by artificial intelligence. Visit HackerNune.com to read, write, learn and publish.

More episodes

More from The Good Tech Companies

View all episodes →