databricks Databricks Blog ·

Databricks Acquires Panther to Enhance Security Lakehouse Capabilities

blogaisecuritydatabricksengineer
feature announcement

Databricks has completed its acquisition of Panther, integrating Panther's AI SOC workflows and detection engine with Databricks' Lakewatch open security lakehouse. This move aims to address the limitations of traditional SIEMs by enabling security teams to retain petabytes of telemetry in open formats, utilize AI for real-time triage, and deploy detections-as-code. The combined offering provides enhanced security operations capabilities for enterprises facing increasingly sophisticated AI-driven threats.

  • Petabyte-Scale Data Retention and Unified Context
  • Detections-as-Code and AI-Native Workflows
  • Accelerated Signal-to-Context Triage with AI Agents
  • Accelerating the Security Lakehouse Vision
  • Seamless Ingestion and Security-Centric Detection
Features (3)
  • Petabyte-Scale Data Retention and Unified Context

    The combined platform enables security teams to retain petabyte-scale telemetry for extended periods without prohibitive costs, providing AI agents with the historical depth needed to detect complex attacks. It also offers unified context by correlating security events with enterprise data for improved, automated triage.

  • Detections-as-Code and AI-Native Workflows

    Panther brings 'detections-as-code' capabilities, allowing security engineers to author, test, and deploy detections via CI/CD pipelines. The platform also features AI-native triage and investigation workflows, with agents that automate incident analysis and learn from feedback.

  • Accelerated Signal-to-Context Triage with AI Agents

    When a threat is detected, native agentic SOC capabilities automatically trigger across the security lakehouse. AI triage agents directly on the data foundation correlate various signals and business context, delivering fully enriched, actionable incidents to analysts.

Enhancements (2)
  • Accelerating the Security Lakehouse Vision

    The acquisition aims to accelerate Databricks' security lakehouse vision by bringing Panther's operational SOC workflows and over 100 integrations directly onto Lakewatch's open data foundation. This provides a unified platform for security, IT, and business data.

  • Seamless Ingestion and Security-Centric Detection

    Security teams can leverage over 100 out-of-the-box connectors for seamless ingestion and normalization of telemetry into Lakewatch. Detections run as code directly against petabytes of data, managed through automated CI/CD pipelines, reducing the burden of proprietary SIEM languages.

Read the original announcement →

https://www.databricks.com/blog/databricks-completes-acquisition-panther-accelerating-security-lakehouse-era

Related releases