Helpnetsecurity
Mars Security Launches Real-Time Threat Detection Engine
Article Content
Mars Security has unveiled a new capability called Real-Time Intel-Based Detection, which converts newly published threat intelligence into validated detection rules within minutes. This system automates the process of creating detection rules from advisories issued by organizations like CISA and Mandiant, mapping them to the MITRE ATT&CK framework. The detection rules are tested against the customer's data for 30 days before deployment, ensuring they are effective and minimizing false positives. The platform supports various telemetry sources, including CrowdStrike, Wiz, and Splunk, and aims to close the gap between threat awareness and detection capabilities. This innovation is particularly significant as it addresses the time lag that often allows attackers to exploit vulnerabilities before organizations can respond. Mars Security's CEO, Shahaf Galili, emphasizes that the platform provides actionable detection based on real-time intelligence, which has historically been a challenge for security teams.
Key Points: • Mars Security's new tool automates detection rule creation from threat intelligence. • Detection rules are validated against customer data for 30 days before deployment. • The platform supports multiple telemetry sources, enhancing detection capabilities.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.