Mars Security Launches Tool That Turns Threat Advisories Into Live Detection Rules in Minutes

A new platform feature promises to close the gap between a published hacking report and an actual working defence, automatically, and tested against a company's own data before anyone clicks deploy.

ThreatVectr Newsdesk· 4 min read
Full-frame photoreal editorial shot of a dimly lit server rack in a utility control room, focus on a network router with blinking amber status LEDs and tangled
Share

Key points

  • Mars Security, founded by former military offensive-security operators, launched Real-Time Intel-Based Detection in 2025.
  • The platform reads advisories from bodies such as CISA and Microsoft Threat Intelligence, then writes and tests detection rules automatically.
  • Every generated rule runs against 30 days of a customer's own historical log data before a human sees it.
  • The feature works across tools already in use, including CrowdStrike Falcon, Splunk, and Wiz, with no need to move or copy data.
  • Existing Mars customers get the feature at no extra cost, and the platform is available on AWS Marketplace.

Security teams have a persistent, embarrassing problem. A government agency or a respected research firm publishes a detailed report about how a criminal group is breaking into companies. The report names the exact techniques, the exact digital fingerprints to look for. And then, days or weeks later, a company's security analysts are still manually turning that report into an actual detection, a rule that tells their monitoring software what to watch for. By that point, the criminals have already changed their methods.

Mars Security, a startup built by veterans of military offensive-security units, says it has automated that entire gap.

What does the platform actually do?

When an advisory lands from sources like CISA (the US Cybersecurity and Infrastructure Security Agency), Mandiant, or Microsoft Threat Intelligence, Mars reads it automatically. It pulls out the relevant indicators, such as suspicious IP addresses, domain names, and file fingerprints, maps them to a standard catalogue of attacker techniques called MITRE ATT&CK (a publicly maintained reference list of how hackers operate), and writes detection rules in whatever query language each of a company's existing tools requires.

Before any rule reaches an analyst's queue, the platform runs it silently against 30 days of the company's own historical log data. That step quantifies how often the rule would have fired, and filters out rules likely to generate too many false alarms. Indicators that are too broad or historically noisy get pruned automatically.

The analyst then sees a rule that is already mapped, already tested, and deployable with a single click.

Why does the speed gap matter?

It matters because attackers move faster than manual workflows allow. Traditional detection engineering, where a human reads a report, extracts the relevant details, writes a custom query, and tunes it against live data, routinely takes days. Researchers and security teams have long noted that criminal groups rotate their infrastructure and retool within hours of a public disclosure.

"A SOC should not need a two-week backlog to act on a report that took an attacker two hours to make obsolete," said Ran Lerer, co-founder and CTO. "When the intel lands, the detection should already be written, already tested against your data, and waiting for a click."

Andy Ellis, former chief information security officer at Akamai Technologies, described the shift in practical terms: "A campaign advisory used to sit in a queue for days before it became a rule anyone trusted. With Mars, it shows up already mapped, already tested against the environment it's meant to protect."

Step Traditional workflow Mars Security
Advisory published Day 0 Day 0
Indicators extracted 1 to 3 days Minutes
Detection rule written 3 to 7 days Minutes
Rule tested against real data Manual, variable Automatic, 30-day backtest
Rule deployed Days to weeks Single click

The platform also runs continuous gap analysis in the background, mapping what a company's existing tools can and cannot see, and surfacing blind spots as actionable recommendations or, for teams that manage detection rules as code, as open pull requests ready for review.

What should security teams do with this information?

If your organisation runs a security operations centre and currently relies on manual detection engineering, this announcement is worth evaluating against your own advisory-to-deployment timeline. Request a live demonstration using a recent CISA advisory as the test case; the backtest output will tell you quickly whether the rule quality holds up against your actual environment.

For end users and customers of organisations using Mars, there is no direct action required. The product is an internal security tool, not a consumer product.

© 2026 Threat Vectr