Mars Security Enhances Cyber Defense with Automated Threat Detection Engine
Mars Security, a platform built by cybersecurity veterans, has unveiled Real-Time Intel-Based Detection aimed at transforming how enterprises respond to cyber threats. This new functionality empowers security operations centers (SOCs) to create validated detection rules rapidly, translating threat advisories into active defenses in mere minutes.
The system, designed by former experts in offensive security, processes threat reports from leading organizations like CISA, Mandiant, and Microsoft Threat Intelligence. By bridging the gap between raw threat intelligence and actionable security measures, Mars translates various threat indicators and tactics into specific detection protocols aligned with the MITRE ATT&CK framework. This streamlined capability integrates smoothly into an organization’s existing security infrastructure, including platforms like CrowdStrike Falcon and Splunk.
Enhancing Threat Detection Efficiency
Despite significant investments in threat intelligence feeds, operational challenges often hinder organizations from effectively utilizing this data. Traditional methods require extensive manual labor, involving analysts scouring advisory briefs for indicators of compromise (IOCs) and tactics, then crafting queries and manually tuning them. This time-consuming process can take days, while threat actors can adjust their tactics almost in real-time.
Mars Security aims to eliminate this lag with its automated approach, dramatically reducing the time from threat intelligence ingestion to active deployment:
- Automated Query Generation: As threat advisories are released, the system extracts relevant indicators and maps them to the ATT&CK framework, generating tailored queries for each log collector.
- Historical Validation: Before any rule is deployed, it’s run against the organization's data for 30 days to evaluate its effectiveness and estimate potential false positives.
- Indicator Cleaning: The automated process removes stale or irrelevant indicators, ensuring that only the most accurate data is included before rule approval.
- Simplified Rule Deployment: Once validated, rules can be easily reviewed, backtested, and deployed, often at the click of a button.
Co-Founder and CEO Shahaf Galili emphasizes the platform's unique testing feature that ensures detection rules are rigorously evaluated against an organization's specific data before production. “Threat intelligence has always informed teams of global threats; now, it's equipping them to find those threats within their own systems more effectively,” he noted.
Proactive Defense Strategies
Beyond ingestion of external threat intelligence, Mars Security continuously evaluates existing defenses. It maps current coverage against telemetry to identify significant gaps. Notable automated recommendations have included detecting anomalies in AWS CloudTrail logs and unauthorized changes in Microsoft Graph API usage.
Rather than relying on static signatures, the platform focuses on detecting behavioral patterns, ensuring that even as adversaries change tactics, the integrity of the detection remains intact. Notably, it addresses the need to monitor emerging technologies, including AI code generators, and spot inadvertent credential leaks within security logs.
As Co-Founder and CTO Ran Lerer highlights, organizations shouldn't have to wait for days to act on a security advisory that cybercriminals can exploit in mere hours. His assertion is clear: when threat intel arrives, organizations should already have detection rules in place, ready for immediate action.
Andy Ellis, former CISO of Akamai Technologies, provides further insight: with Mars, threat advisories no longer languish in a backlog. The rules appear pre-mapped and pre-tested, ensuring that SOCs can stay ahead of the curve in defense versus attack tactics.
Immediate Availability
The Real-Time Intel-Based Detection feature is available now to all Mars Security customers at no additional charge. The deployment process is quick, requiring no extensive data ingestion and integrating seamlessly with existing security tools. It is also offered on the AWS Marketplace.
About Mars Security
Mars Security serves as a pioneering platform in autonomous threat hunting and detection. It transforms threat intelligence into active detections that fit within existing security frameworks. Co-founded by experts with over five decades combined experience in cybersecurity, the platform operates without needing data ingestion or extensive infrastructure changes. Its commitment to proactive defense ensures organizations can better identify and address vulnerabilities, maintaining compliance with standards like SOC 2. For more information, visit marssec.ai.