待翻譯:Databricks Completes Acquisition of Panther: Accelerating the Security Lakehouse Era
AI 服務暫時不可用,以下為來源摘要,待恢復後補全翻譯:Today, we are thrilled to announce that Databricks has officially completed the acquisition...
AI 服務暫時不可用,以下為來源正文,待恢復後補全翻譯。
Accelerating the Security Lakehouse | Databricks Blog What it is: Databricks has officially completed the acquisition of Panther, combining its mature SOC workflows and software-driven detection engine with Lakewatch’s open security lakehouse foundation. The challenge it solves: Traditional SIEMs force security teams to compromise between high storage costs and limited data retention, creating data silos and analyst burnout from manual alert triage. Results and outcomes: Security teams can now retain petabytes of telemetry in open formats, deploy autonomous AI agents for real-time triage, and execute detections-as-code to accelerate incident response. Today, we are thrilled to announce that Databricks has officially completed the acquisition of Panther, an AI SOC platform built for modern security operations. Cybersecurity has fundamentally transformed into a data management and AI problem. The ability to collect, retain, and analyze data at scale and in real time is now the limiting factor in how fast a SOC can detect and respond. Attackers are leveraging automation and AI to move faster, hide within massive volumes of complex data, and launch increasingly sophisticated, multi-stage attacks across cloud, identity, and SaaS environments. To defend modern enterprises, security teams require an architecture capable of processing petabytes of telemetry with continuous context and automated intelligence. Legacy SIEMs were built more than a decade ago around limited data ingestion, strict sampling trade-offs, rigid compute architectures, and manual alert triage. Constrained by high compute costs and inflexible processing power, this legacy approach simply cannot scale to defend against AI-driven threats and rapid zero-day attacks. The industry needs a new paradigm. Databricks established that paradigm with the security lakehouse: an open, governed lakehouse that unifies security, IT, and business data in one place so SOC teams can run detection, investigation, and response directly on top of that data. Earlier this year, Databricks introduced Lakewatch as our agentic SIEM built on the security lakehouse. Today, the addition of Panther dramatically accelerates the security lakehouse vision by bringing mature, proven operational SOC workflows and 100+ out-of-the-box integrations directly on top of Lakewatch’s open data foundation. Why Legacy SIEM Falls Short in the Agentic Era For years, security teams have been forced into an impossible compromise. Ingest everything and absorb escalating SIEM costs and noisy output, or ingest less to control cost and leave gaps in coverage. When alerts do trigger, analysts are left jumping between disconnected tools, manually stitching together logs from cloud services, endpoints, identity providers, and SaaS applications. The security lakehouse eliminates this compromise by breaking down data silos and uniting security, IT, and business telemetry in an open, governed architecture. With Lakewatch and Panther, security teams no longer have to choose between rich data scale and fast, actionable workflows. They get both on day one. Lakewatch: The Open Data Foundation Lakewatch is the core product powering the security lakehouse foundation, providing the high-fidelity, open-data ecosystem required to operationalize an agentic SOC. It enables organizations to seamlessly collect, govern, and analyze petabyte-scale security telemetry alongside IT and business data in an open lakehouse format. With Lakewatch and Panther working in tandem, security teams no longer just collect data. They deploy proven autonomous AI agents that actively triage alerts, conduct threat hunts, and continuously refine detection logic. By running natively on the Databricks Data + AI platform, Lakewatch provides: Petabyte-Scale Retention: Retain months or years of high-fidelity telemetry without cost-prohibitive SIEM licensing penalties or forced data sampling, giving AI agents the complete historical depth required to detect complex, multi-stage attacks. Unified Context: Correlate security events directly with enterprise context such as HR records, asset inventories, and business data. By integrating Panther’s AI agents directly into Lakewatch, this rich context powers deep, automated triage, delivering higher signal quality and fewer false positives. Open Standards: Maintain ownership and governance of your organization's security data using OCSF, Spark, Unity Catalog, Delta, Parquet, and SQL. This avoids proprietary lock-in while ensuring your telemetry is instantly accessible across your AI tooling. Agent-Ready: Security, IT, and business data live together in open formats, making governed, real-time data immediately actionable for Panther’s production-ready AI agents to automate investigations, generate detection-as-code, and streamline SOC operations today. Panther: Accelerating the Security Lakehouse Vision Panther bridges the gap between raw lakehouse data and real-time security execution. Engineered specifically for modern, cloud-native teams, Panther pairs software engineering practices and deep detection logic with native AI workflows embedded directly into the data layer. Instead of basic alert summarization, security teams can deploy intelligent agents that actively investigate incidents, draft detection rules, and execute response actions at machine speed. Key Capabilities Panther Brings to the Security Lakehouse: Detections-as-Code: Replace manually managed SIEM rules and ungoverned, UI-centric workflows with detection engineering. Security engineers author, test, version-control, and deploy detections-as-code through standard CI/CD pipelines, bringing software-engineering rigor to threat detection. 100+ Out-of-the-Box Integrations: Deeply parsed connectors across major cloud providers (AWS, Microsoft Azure, Google Cloud), identity systems (Okta, Entra ID), SaaS apps, and endpoints ensure immediate time to value. AI-Native Triage & Investigation: Automated, agentic triage workflows enrich alerts in real time, turning raw telemetry signals into actionable context before an analyst even opens a ticket. While other security tools treat AI as a bolted-on chatbot, Lakewatch delivers true, native agentic workflows: AI agents that continuously learn from analyst feedback, automate rule optimization, and elevate your team from alert handlers to strategic engineers. Better Together: Reimagining Security Operations When you pair Lakewatch's open, petabyte-scale data foundation with Panther's software-driven workflow layer, the practical impact on day-to-day security operations is transformative. Together, Databricks and Panther will streamline the entire lifecycle of detection and response: Seamless Ingestion and Normalization: Rather than managing complex, custom ETL pipelines, security teams can now leverage 100+ out-of-the-box connectors to immediately feed normalized telemetry straight into Lakewatch's open data storage. Security-Centric Detection Engineering: Detections run as code directly against petabytes of telemetry stored in Lakewatch. Security teams can write, unit-test, version-control, and deploy detections through automated CI/CD pipelines, eliminating the maintenance burden of proprietary SIEM languages. Accelerated Signal-to-Context Triage: When a threat is detected, native agentic SOC capabilities automatically trigger across the security lakehouse. By deploying AI triage agents directly on top of a petabyte-scale data foundation, the platform instantly correlates cloud logs, identity signals, and business context. Analysts receive fully enriched, actionable incident summaries instead of alert floods, dramatically cutting dwell time and analyst burnout. Anchored in Openness and Customer Control Beyond capabilities, Databricks and Panther share a foundational belief: customers must own their data. Legacy SIEM providers maintain business models built on proprietary data formats and steep ingestion fees. Databricks and Panther are committed to an open ecosystem. Security telemetry stored in the security lakehouse remains accessible, governed, and interoperable across the entire enterprise stack. Security teams retain complete ownership of their data in open formats, enabling them to analyze their telemetry with best-of-breed tools without friction or artificial barriers. Building the Future of Security Together Together, Databricks and Panther deliver the complete blueprint for the modern agentic SOC. Lakewatch provides the open, petabyte-scale data foundation, while Panther delivers the agentic automation engine to act on it. The result is a self-improving security organization ready for the speed and scale of modern threats. By bringing native agentic workflows directly onto the security lakehouse, Databricks gives defenders the scale, automation, and speed needed to outpace modern threats. We are excited to welcome the Panther team to Databricks as together we redefine security operations for the agentic era. Get the latest posts in your inbox Subscribe to our blog and get the latest posts delivered to your inbox. Sign up View all blogs