As new intelligence becomes available, Mars extracts the relevant indicators, techniques and infrastructure, maps them to MITRE ATT&CK, and writes the detection in the native query language of whichever telemetry can actually see the threat: CrowdStrike Falcon, Wiz, Splunk, firewall logs, Linux Sysmon, identity providers, AWS telemetry, or data lakes such as Snowflake and Databricks. Each rule carries a severity rating and lands in the team’s queue for review. Accept Rule pushes it live. Dismiss clears it.
Nothing ships untested. Before a rule is offered, Mars runs the exact query against the customer’s previous 30 days of data and shows how many events it would have matched and how many of those would have been false positives. Teams can rerun the backtest over any window they choose. The same scrutiny applies to the underlying indicators: domains, IP addresses and hashes are scored against their false-positive history, and anything too broad, too old or historically noisy is dropped before it ever reaches a rule.
“We spent years on the offensive side, and the thing that surprised us most was how rarely anyone saw us, even when the intel on our tradecraft was already public. Threat intelligence has always told security teams what is happening in the world. It never handed them the detection to find it in their own environment. Mars does that now, and it tests the detection against your data before it goes anywhere near production.” – Shahaf Galili, Co-Founder and CEO, Mars Security.