Databricks Acquires Panther to Enhance Security Lakehouse Capabilities
Databricks has completed its acquisition of Panther, integrating Panther's AI SOC workflows and detection engine with Databricks' Lakewatch open security lakehouse. This move aims to address the limitations of traditional SIEMs by enabling security teams to retain petabytes of telemetry in open formats, utilize AI for real-time triage, and deploy detections-as-code. The combined offering provides enhanced security operations capabilities for enterprises facing increasingly sophisticated AI-driven threats.
- →Petabyte-Scale Data Retention and Unified Context
- →Detections-as-Code and AI-Native Workflows
- →Accelerated Signal-to-Context Triage with AI Agents
- →Accelerating the Security Lakehouse Vision
- →Seamless Ingestion and Security-Centric Detection
Features (3) ›
- Petabyte-Scale Data Retention and Unified Context
The combined platform enables security teams to retain petabyte-scale telemetry for extended periods without prohibitive costs, providing AI agents with the historical depth needed to detect complex attacks. It also offers unified context by correlating security events with enterprise data for improved, automated triage.
- Detections-as-Code and AI-Native Workflows
Panther brings 'detections-as-code' capabilities, allowing security engineers to author, test, and deploy detections via CI/CD pipelines. The platform also features AI-native triage and investigation workflows, with agents that automate incident analysis and learn from feedback.
- Accelerated Signal-to-Context Triage with AI Agents
When a threat is detected, native agentic SOC capabilities automatically trigger across the security lakehouse. AI triage agents directly on the data foundation correlate various signals and business context, delivering fully enriched, actionable incidents to analysts.
Enhancements (2) ›
- Accelerating the Security Lakehouse Vision
The acquisition aims to accelerate Databricks' security lakehouse vision by bringing Panther's operational SOC workflows and over 100 integrations directly onto Lakewatch's open data foundation. This provides a unified platform for security, IT, and business data.
- Seamless Ingestion and Security-Centric Detection
Security teams can leverage over 100 out-of-the-box connectors for seamless ingestion and normalization of telemetry into Lakewatch. Detections run as code directly against petabytes of data, managed through automated CI/CD pipelines, reducing the burden of proprietary SIEM languages.
https://www.databricks.com/blog/databricks-completes-acquisition-panther-accelerating-security-lakehouse-era
Related releases
- Databricks SDK for Go v0.172.0 Enhances IAMv2 and Job Cluster Management Databricks Go SDK Releases ·
- Databricks Java SDK v0.146.0 Adds IAM V2 API, Updates Job Cluster Field Databricks Java SDK Releases ·
- Databricks SDK for Python v0.128.0 Adds Account and Workspace IAM V2 API Methods Databricks Python SDK Releases ·
- Amtrak Builds Unified Data Backbone with Databricks for Rail Network Transformation Databricks Blog ·
- Databricks Re-architects Serverless Network Config Delivery for 97.5% Latency Cut Databricks Blog ·
- How a Major Freight Railroad Scaled Pipeline Creation with Databricks Genie Code Databricks Blog ·