Loading…
Databricks Completes Acquisition of Panther: Accelerating the Security Lakehouse Era
Andrew Krioukov, Jack Naglieri, Taylor Kain, Dave Herrald
- Source
- Databricks
- Published
- Added to Yomu
Summary
Databricks says it has completed its acquisition of Panther, an AI SOC platform, to accelerate its security lakehouse strategy. The combination pairs Lakewatch’s open, governed foundation for collecting, retaining, and analyzing petabyte-scale security telemetry with Panther’s operational SOC workflows and more than 100 out-of-the-box integrations. Panther adds detections-as-code, CI/CD-based authoring and deployment, and AI-native triage and investigation that correlate cloud, identity, SaaS, IT, and business data. The announcement presents the combined platform as a way to retain high-fidelity telemetry, preserve data ownership through open standards including OCSF, Spark, Unity Catalog, Delta, Parquet, and SQL, and automate investigations, detection refinement, and response workflows for modern security operations.
Context
The announcement describes legacy SIEMs as constrained by limited ingestion, sampling trade-offs, rigid compute architectures, high costs, data silos, and manual alert triage, while attackers use automation and AI across cloud, identity, and SaaS environments.
Approach / What changed
Databricks is combining Lakewatch’s security lakehouse foundation with Panther’s operational SOC workflows, integrations, detection engineering, and agentic triage capabilities. The stated design uses open data formats and standards to run detection, investigation, and response directly on governed security, IT, and business data.
Takeaways
- Lakewatch is designed to retain months or years of high-fidelity security telemetry at petabyte scale without forced sampling or cost-prohibitive SIEM licensing penalties.
- Panther supports detections-as-code, allowing security engineers to author, test, version-control, and deploy detection logic through standard CI/CD pipelines.
- The combined platform correlates security events with HR records, asset inventories, identity signals, cloud logs, and business data to enrich triage and reduce false positives.