AI SOC, Detection & Security Operations Blog | Panther
NEW
Panther joins Databricks to build the future of the security lakehouse. Read more →
close
Platform
Solutions
Resources
Company
InsightsfromthefrontlinesofSecOps
Ideas, lessons, and tactics from the team behind Panther.
\ \ Threat Research\ \ A Patient Trojan Dropper: polymarket-stake-math Steals Wallet Keys, Browser Sessions, and Telegram from Crypto Developers\ \ Read more\ \ Ariel\ \ Ropek](/content/blog/a-patient-trojan-dropper-polymarket-stake-math-steals-wallet-keys-browser-sessions-and-telegram-from-crypto-developers/index.html)
All
Threat Research
Detection & Response
Customer Stories
Thought Leadership
Cloud Security
Product
Company Culture
Data Engineering
Compliance
Press Release
\ \ 10 Best AI SOC Platforms: Features & Use Cases\ \ Michelle\ \ Dufty](/content/blog/best-ai-soc-platforms/index.html) \ \ Product\ \ Google Threat Intelligence Now Available in Panther Detections\ \ Kostas\ \ Papageorgiou](/content/blog/google-threat-intelligence-now-available-in-panther-detections/index.html) \ \ Best SIEM Tools (2026): Detection, Deployment Options & Real Trade-offs\ \ Michelle\ \ Dufty](/content/blog/best-siem-tools/index.html) \ \ AI governance implementation: A practical guide for security teams\ \ Michelle\ \ Dufty](/content/blog/ai-governance-implementation-guide/index.html) \ \ AI governance challenges: what security teams need to solve first\ \ Michelle\ \ Dufty](/content/blog/ai-governance-challenges/index.html) \ \ AI governance responsibilities: Who owns what in an AI-powered security operations center?\ \ Michelle\ \ Dufty](/content/blog/ai-governance-responsibilities/index.html) \ \ AI governance monitoring: How to track AI actions, approvals, and risk\ \ Michelle\ \ Dufty](/content/blog/ai-governance-monitoring/index.html) \ \ AI Incident Response: Where Agents Help and Where Analysts Still Lead\ \ Michelle\ \ Dufty](/content/blog/ai-incident-response/index.html) \ \ How To Measure AI SOC ROI: The Metrics That Actually Matter to Leadership\ \ Michelle\ \ Dufty](/content/blog/measure-ai-soc-roi/index.html) \ \ AI for Log Analysis: What It Speeds Up and What to Validate\ \ Michelle\ \ Dufty](/content/blog/ai-for-log-analysis/index.html) \ \ What Is an Audit Trail? Why AI SOC Tools Need One\ \ Michelle\ \ Dufty](/content/blog/what-is-an-audit-trail/index.html) \ \ What Is AI Threat Detection? Where It Helps Most and Where It Still Needs Human Review\ \ Michelle\ \ Dufty](/content/blog/ai-threat-detection/index.html) \ \ AI Security Operations Center (SOC) Evaluation: 28 Questions to Ask Before You Trust a Vendor\ \ Michelle\ \ Dufty](/content/blog/ai-soc-vendor-evaluation-questions/index.html) \ \ Predictive Threat Intelligence: What It Actually Means for Security Operations\ \ Michelle\ \ Dufty](/content/blog/predictive-threat-intelligence/index.html) \ \ What Is Shadow AI? Why Security Teams Need to See It Early\ \ Michelle\ \ Dufty](/content/blog/what-is-shadow-ai/index.html) \ \ Agentic AI vs. Generative AI: What the Difference Means for SOC Teams\ \ Michelle\ \ Dufty](/content/blog/agentic-ai-vs-generative-ai-soc-teams/index.html) \ \ Threat Research\ \ Lend Me Your Claude: The Cost of Borrowed AI Compute\ \ Zaynah\ \ Smith-DaSilva](/content/blog/lend-me-your-claude-the-cost-of-borrowed-ai-compute/index.html) \ \ Threat Research\ \ Through the Looking Glass: Simulating an Adversary in Okta\ \ Zaynah\ \ Smith-DaSilva](/content/blog/through-the-looking-glass-simulating-an-adversary-in-okta/index.html) \ \ Product\ \ Cloud Infrastructure Monitoring: Best Practices for Modern SOC Teams\ \ Katie\ \ Campisi](/content/blog/cloud-infrastructure-monitoring-best-practices-for-modern-soc-teams/index.html) \ \ Threat Research\ \ Mini Shai-Hulud Supply-Chain Compromise of @redhat-cloud-services npm Packages via GitHub Actions OIDC Abuse\ \ Alessandra\ \ Rizzo](/content/blog/mini-shai-hulud-supply-chain-compromise-of-redhat-cloud-services-npm-packages-via-github-actions-oidc-abuse/index.html) \ \ AI Detection Engineering: How AI Helps Write, Test, and Tune Detection Rules\ \ Michelle\ \ Dufty](/content/blog/ai-detection-engineering/index.html) \ \ Prompt Injection Security: How to Test for It and Reduce the Risk\ \ Michelle\ \ Dufty](/content/blog/prompt-injection-security/index.html) \ \ Agentic Security Orchestration: Where Agents Fit and Where Humans Still Matter\ \ Michelle\ \ Dufty](/content/blog/agentic-security-orchestration/index.html) \ \ 7 Best AI Tools for Security Alert Triage\ \ Michelle\ \ Dufty](/content/blog/ai-tools-security-alert-triage/index.html) \ \ 8 Best Tools for Automating EDR Alert Triage\ \ Michelle\ \ Dufty](/content/blog/tools-for-automating-edr-alert-triage/index.html) \ \ Threat Research\ \ FragMiner: A Triple Threat Hiding in npm, Kernel Exploit, Supply Chain Worm, and Cryptomining from a Single Package\ \ Michael\ \ Baker](/content/blog/fragminer-a-triple-threat-hiding-in-npm-kernel-exploit-supply-chain-worm-and-cryptomining-from-a-single-package/index.html) \ \ Product\ \ Identity Threat Detection: Best Practices for Modern SOC Teams\ \ Katie\ \ Campisi](/content/blog/identity-threat-detection-best-practices-for-modern-soc-teams/index.html) \ \ Threat Research\ \ Crate Expectations: NastyC2 Ships Rust Post-Exploitation Framework Through NPM\ \ Alessandra\ \ Rizzo](/content/blog/crate-expectations-nastyc2-ships-rust-post-exploitation-framework-through-npm/index.html) \ \ Threat Research\ \ Mapping The Contagious Trader Delivery Network\ \ Alessandra\ \ Rizzo](/content/blog/mapping-the-contagious-trader-delivery-network/index.html) \ \ AI Case Triage: How to Prioritize Security Cases Without Burning Out Your Team\ \ Michelle\ \ Dufty](/content/blog/ai-case-triage/index.html) \ \ Alert Triage Automation: How to Reduce Manual Review Without Missing Real Threats\ \ Michelle\ \ Dufty](/content/blog/alert-triage-automation/index.html) \ \ AI-Enabled Incident Triage: How Teams Investigate Faster With Better Context\ \ Michelle\ \ Dufty](/content/blog/ai-enabled-incident-triage/index.html) \ \ What Is a SIEM Agent? How Agentic SIEM Changes Triage and Investigation\ \ Michelle\ \ Dufty](/content/blog/what-is-a-siem-agent/index.html) \ \ AI Agents for Incident Triage and Prioritization: What Actually Works\ \ Michelle\ \ Dufty](/content/blog/ai-agents-incident-triage-prioritization/index.html) \ \ How to Secure an MCP Server: Practical Controls for Security Teams\ \ Michelle\ \ Dufty](/content/blog/how-to-secure-an-mcp-server/index.html) \ \ AI Threat Investigation: Where AI Helps and Where Analysts Still Lead\ \ Michelle\ \ Dufty](/content/blog/ai-threat-investigation/index.html) \ \ AI False Positives in the SOC: Why They Happen and How to Reduce Them\ \ Michelle\ \ Dufty](/content/blog/ai-false-positives-soc/index.html) \ \ Agentic AI Security Risks: What Changes When AI Can Take Action\ \ Michelle\ \ Dufty](/content/blog/agentic-ai-security-risks/index.html) \ \ What Is AI SecOps? Use Cases, Benefits, and What Good Looks Like\ \ Michelle\ \ Dufty](/content/blog/what-is-ai-secops/index.html) \ \ Adversarial AI: Attacks, Risks, and Defenses for Security Teams\ \ Michelle\ \ Dufty](/content/blog/adversarial-ai/index.html) \ \ Machine Learning in Cybersecurity: Applications and Benefits\ \ Michelle\ \ Dufty](/content/blog/machine-learning-in-cybersecurity/index.html) \ \ What Is AI TRiSM? Framework, Use Cases, and Security Implications\ \ Michelle\ \ Dufty](/content/blog/what-is-ai-trism/index.html) \ \ AI Security Risks: The Practical Threats Security Teams Should Prioritize\ \ Michelle\ \ Dufty](/content/blog/ai-security-risks-prioritization/index.html) \ \ Human in the Loop: Why AI Security Operations Center (SOC) Tools Still Need Analyst Approval\ \ Michelle\ \ Dufty](/content/blog/human-in-the-loop/index.html) \ \ Product\ \ Tuning Detections Without a Backlog\ \ Katie\ \ Campisi](/content/blog/tuning-detections-without-a-backlog/index.html) \ \ Product\ \ Autonomous Threat Hunting\ \ Katie\ \ Campisi](/content/blog/autonomous-threat-hunting/index.html) \ \ Threat Research\ \ 4 Years, 51 Packages, 3 organizations: How npm Became a Gambling Ring's Config Server\ \ Panther Threat Research Team](/content/blog/4-years-51-packages-3-organizations-how-npm-became-a-gambling-ring-s-config-server/index.html) \ \ Threat Research\ \ Frankly Malicious: Inside a 38-Package NPM Supply Chain Campaign Targeting Tech Giants\ \ Zaynah\ \ Smith-DaSilva](/content/blog/frankly-malicious-inside-a-38-package-npm-supply-chain-campaign-targeting-tech-giants/index.html) \ \ What is SecDevOps? A Security-First Development Guide\ \ Michelle\ \ Dufty](/content/blog/what-is-secdevops/index.html) \ \ What Is Threat Detection and Response (TDR)?\ \ Michelle\ \ Dufty](/content/blog/threat-detection/index.html) \ \ What Is Threat Hunting? Process, Tools, and Techniques\ \ Michelle\ \ Dufty](/content/blog/what-is-threat-hunting-process-tools-and-techniques/index.html) \ \ What Is Lateral Movement? Prevention, Detection, & Examples\ \ Michelle\ \ Dufty](/content/blog/lateral-movement-meaning/index.html) \ \ AI SOC Agents: What They Can Do Today and What They'll Do Next\ \ Michelle\ \ Dufty](/content/blog/ai-soc-agents-capabilities-today-and-next/index.html) \ \ Where AI Actually Fits in Your SOC Workflow (and Where It Creates More Problems)\ \ Michelle\ \ Dufty](/content/blog/ai-soc-workflow-benefits-risks/index.html) \ \ Will AI Replace SOC Analysts? The Honest Answer Is More Complicated\ \ Michelle\ \ Dufty](/content/blog/will-ai-replace-soc-analysts/index.html) \ \ AI SOC Analysts: What They Actually Do (and Where They Still Need Humans)\ \ Michelle\ \ Dufty](/content/blog/ai-soc-analysts-capabilities/index.html) \ \ What Are Query Languages? Definition, Examples, & Uses\ \ Michelle\ \ Dufty](/content/blog/what-are-query-languages/index.html) \ \ What Is Centralized Logging? Benefits, Architecture, and Best Practices\ \ Michelle\ \ Dufty](/content/blog/what-is-centralized-logging/index.html) \ \ What Is an Incident Response Retainer? Benefits, Costs, and When You Need One\ \ Michelle\ \ Dufty](/content/blog/incident-response-retainer/index.html) \ \ What Is QBot Malware? Detection and Removal Guide\ \ Michelle\ \ Dufty](/content/blog/qbot-malware-detection/index.html) \ \ What Is Credential Stuffing? How It Works and How to Prevent It\ \ Michelle\ \ Dufty](/content/blog/what-is-credential-stuffing/index.html) \ \ Product\ \ Investigating Alerts Without Switching Tools\ \ Katie\ \ Campisi](/content/blog/investigating-alerts-without-switching-tools/index.html) \ \ Threat Research\ \ Inside DPRK’s npm malware factory: 108 packages, 261 versions, and a 31-day campaign wave\ \ Michael\ \ Baker](/content/blog/inside-dprk%E2%80%99s-npm-malware-factory-108-packages-261-versions-and-a-31-day-campaign-wave/index.html) \ \ What Is SIEM as a Service? Benefits and Pricing\ \ Michelle\ \ Dufty](/content/blog/siem-as-a-service/index.html) \ \ What Is Security Analytics? Benefits, Tools, & Use Cases\ \ Michelle\ \ Dufty](/content/blog/what-is-security-analytics/index.html) \ \ What Is Managed SIEM? Benefits, Costs, and How to Choose\ \ Michelle\ \ Dufty](/content/blog/what-is-managed-siem/index.html) \ \ Top SIEM Use Cases: Security Monitoring, Compliance, and More\ \ Michelle\ \ Dufty](/content/blog/siem-use-cases/index.html) \ \ What Is a Data Warehouse vs Data Lake vs Data Lakehouse? Key Differences\ \ Michelle\ \ Dufty](/content/blog/data-warehouse-vs-data-lake-vs-data-lakehouse/index.html) \ \ Data Lake Architecture: Components, Design, and Best Practices\ \ Michelle\ \ Dufty](/content/blog/data-lake-architecture-components/index.html) \ \ Top 5 Data Lake Solutions: Features, Pricing and Comparison\ \ Michelle\ \ Dufty](/content/blog/data-lake-solutions/index.html) \ \ What is Log Aggregation and How Does It Work? A Complete Guide\ \ Michelle\ \ Dufty](/content/blog/what-is-log-aggregation/index.html) \ \ What Are Security Logs? Types, Examples, and Analysis\ \ Michelle\ \ Dufty](/content/blog/what-are-security-logs/index.html) \ \ SIEM vs EDR: Critical Differences & Similarities\ \ Michelle\ \ Dufty](/content/blog/siem-vs-edr/index.html) \ \ How to Create an Incident Response Plan: Steps and Template\ \ Michelle\ \ Dufty](/content/blog/incident-response-plan/index.html) \ \ What Is Detection Engineering? A Practitioner's Guide\ \ Michelle\ \ Dufty](/content/blog/what-is-detection-engineering/index.html) \ \ What is Infrastructure as Code (IaC) Security? How it Works & Best Practices\ \ Michelle\ \ Dufty](/content/blog/iac-security/index.html) \ \ What Is a Host-Based Intrusion Detection System (HIDS)?\ \ Michelle\ \ Dufty](/content/blog/host-based-intrusion-detection-system-hids/index.html) \ \ What Is the Cyber Kill Chain? Strategies and How to Use It Effectively\ \ Michelle\ \ Dufty](/content/blog/cyber-kill-chain/index.html) \ \ What Is Cyber Threat Hunting? A Practitioner's Guide to Proactive Threat Detection\ \ Michelle\ \ Dufty](/content/blog/cyber-threat-hunting/index.html) \ \ Shai-Hulud npm Supply Chain Attack: What You Need to Know\ \ Michelle\ \ Dufty](/content/blog/shai-hulud-npm-supply-chain-attack/index.html) \ \ How to Detect Compromised Credentials: Signs and Response Steps\ \ Michelle\ \ Dufty](/content/blog/detect-compromised-credentials/index.html) \ \ What Is Threat and Vulnerability Management? A 2026 Guide\ \ Michelle\ \ Dufty](/content/blog/threat-and-vulnerability-management-guide/index.html) \ \ Automating Security Operations With AI: Where to Start When Everything Feels Manual\ \ Michelle\ \ Dufty](/content/blog/automating-security-operations-with-ai/index.html) \ \ AI Agents in Security Operations: What's Real, What's Hype, and What's Next\ \ Michelle\ \ Dufty](/content/blog/ai-agents-security-operations-real-vs-hype/index.html) \ \ Who's Leading AI-Powered SOC Automation? A Practitioner's Market Map\ \ Michelle\ \ Dufty](/content/blog/ai-soc-automation-market-map/index.html) \ \ Agentic AI Security Platforms: What to Expect and How to Evaluate Them\ \ Michelle\ \ Dufty](/content/blog/agentic-ai-security-platforms-guide/index.html) \ \ Is AI SOC Automation Worth It? An Honest Look at the Costs, Gains, and Gotchas\ \ Michelle\ \ Dufty](/content/blog/ai-soc-automation-costs-gains-gotchas/index.html) \ \ How to Build an AI-Enabled SOC: Lessons From Teams That Did It Without Ripping and Replacing\ \ Michelle\ \ Dufty](/content/blog/how-to-build-ai-soc/index.html) \ \ Everything as Code: Bringing Software Engineering Discipline to Security Operations\ \ Michelle\ \ Dufty](/content/blog/everything-as-code/index.html) \ \ Threat Research\ \ Sober Up! npm Typosquat Delivers Winos4.0 Implant via Multi-Stage PowerShell Dropper\ \ Alessandra\ \ Rizzo](/content/blog/sober-up-npm-typosquat-delivers-winos4.0-implant-via-multi-stage-powershell-dropper/index.html) \ \ Threat Research\ \ Mapping the Infrastructure Behind the kube-health-tools Supply Chain Malware\ \ Alessandra\ \ Rizzo](/content/blog/mapping-the-infrastructure-behind-the-kube-health-tools-supply-chain-malware/index.html) \ \ Threat Research\ \ Enrichment Baselines: A Statistical Framework for Threat Detection\ \ Zaynah \ \ Smith-DaSilva](/content/blog/enrichment-baselines-a-statistical-framework-for-threat-detection/index.html) \ \ Threat Research\ \ False Claims: An npm Supply Chain Campaign Impersonates Known US Insurance Provider\ \ Alessandra\ \ Rizzo](/content/blog/false-claims-an-npm-supply-chain-campaign-impersonates-insurance-provider/index.html) \ \ Threat Research\ \ Tracking an OtterCookie Infostealer Campaign Across npm\ \ Alessandra\ \ Rizzo](/content/blog/tracking-an-ottercookie-infostealer-campaign-across-npm/index.html) \ \ Threat Research\ \ Polymarket Trader Funds at Risk: DPRK npm Package Steals Wallet Keys and Installs SSH Backdoor\ \ Michael\ \ Baker](/content/blog/polymarket-trader-funds-at-risk-dprk-npm-package-steals-wallet-keys/index.html) \ \ Threat Research\ \ jsonspack: Multi-Tenant Node.js RAT — DPRK Supply Chain Campaign\ \ Michael \ \ Baker](/content/blog/jsonspack-multi-tenant-node.js-rat-%E2%80%94-dprk-supply-chain-campaign/index.html) \ \ Threat Research\ \ Tunnel Vision: Supply Chain Attack Targets Kubernetes via npm and PyPI\ \ Alessandra\ \ Rizzo](/content/blog/tunnel-vision-supply-chain-attack-targets-kubernetes-via-npm-and-pypi/index.html) \ \ Threat Research\ \ Introducing Unique Value Thresholds\ \ Ariel\ \ Ropek](/content/blog/introducing-unique-value-thresholds/index.html) \ \ Product\ \ AI-Powered Alert Triage\ \ Katie\ \ Campisi](/content/blog/ai-powered-alert-triage/index.html) \ \ Thought Leadership\ \ Defining the AI SOC Platform\ \ Jack\ \ Naglieri](/content/blog/defining-the-ai-soc-platform/index.html) \ \ Agentic AI Architecture: Components and Design Patterns for Security Teams\ \ Michelle\ \ Dufty](/content/blog/agentic-ai-architecture-security-teams/index.html) \ \ Building an AI-Powered SOC: Architecture, Trade-offs, and What to Prioritize\ \ Michelle\ \ Dufty](/content/blog/ai-powered-soc/index.html) \ \ How to Integrate AI Into Your SOC Without Disrupting Existing Workflows\ \ Michelle\ \ Dufty](/content/blog/ai-security-operations/index.html) \ \ Agentic AI in Cybersecurity: What It Actually Does (and Doesn't Do)\ \ Michelle\ \ Dufty](/content/blog/agentic-ai-cybersecurity/index.html) \ \ MCP Tools for Security Teams: Using the MCP Ecosystem to Orchestrate AI SOC Agents\ \ Michelle\ \ Dufty](/content/blog/mcp-tools/index.html) \ \ What Is LLM Security? Risks, Vulnerabilities, and Best Practices\ \ Michelle\ \ Dufty](/content/blog/llm-security/index.html) \ \ Product\ \ The Complete AI SOC: What We Built and Why\ \ Jack\ \ Naglieri](/content/blog/the-complete-ai-soc-what-we-built-and-why/index.html) \ \ Threat Research\ \ Detecting and Hunting for Cloud Ransomware Part 3: Azure Storage\ \ Alessandra\ \ Rizzo](/content/blog/detecting-and-hunting-for-cloud-ransomware-part-3-azure-storage/index.html) \ \ Managed Detection and Response (MDR): How It Works, Key Components, and When You Need It\ \ Michelle\ \ Dufty](/content/blog/managed-detection-response/index.html) \ \ Intrusion Detection Systems: How They Work, Types, and Where Cloud-Native Detection Fits\ \ Michelle\ \ Dufty](/content/blog/intrusion-detection-systems/index.html) \ \ Threat Research\ \ Phantom Menace: The Ghost Loader Infostealer Campaign\ \ Alessandra\ \ Rizzo](/content/blog/phantom-menace-the-ghost-loader-infostealer-campaign/index.html) \ \ Threat Research\ \ Catching Salesforce Integration Breaches with Panther\ \ Zaynah\ \ Smith-DaSilva](/content/blog/catching-salesforce-integration-breaches-with-panther/index.html) \ \ Top Splunk Alternatives (2026): Features, Pricing, and Comparison\ \ Michelle\ \ Dufty](/content/blog/splunk-alternatives/index.html) \ \ Top AIOps Use Cases for Security Operations\ \ Michelle\ \ Dufty](/content/blog/aiops-use-cases/index.html) \ \ What Is AI SIEM? Features, Benefits, and Use Cases\ \ Michelle\ \ Dufty](/content/blog/ai-siem/index.html) \ \ SIEM vs. SOAR: Key Differences\ \ Michelle\ \ Dufty](/content/blog/siem-vs-soar/index.html) \ \ Threat Research\ \ Part Two: LLM Threats and Defensive Strategies\ \ Zaynah\ \ Smith-DaSilva](/content/blog/part-two-llm-threats-and-defensive-strategies/index.html) \ \ What is Alert Fatigue? And How to Reduce it in Your SOC\ \ Michelle\ \ Dufty](/content/blog/what-is-alert-fatigue/index.html) \ \ What Is Security Automation? Benefits, Tools, and Best Practices\ \ Michelle\ \ Dufty](/content/blog/security-automation/index.html) \ \ What Is AI Threat Intelligence? How AI Enhances Threat Detection\ \ Michelle\ \ Dufty](/content/blog/ai-threat-intelligence/index.html) \ \ Threat Research\ \ Part One: LLM Threats and Defensive Strategies\ \ Zaynah\ \ Smith-DaSilva](/content/blog/llm-threats-and-defensive-strategies-part-one/index.html) \ \ Detection & Response\ \ How to Build SOC Teams in 2026: A Step-by-Step Guide\ \ Dufty](/content/blog/how-to-build-soc-teams/index.html) \ \ Product\ \ Panther v1.118 Focuses on Removing Friction from Security Operations\ \ Katie\ \ Campisi](/content/blog/panther-v1.118-focuses-on-removing-friction-from-security-operations/index.html) \ \ Threat Research\ \ No Fool's Errand: The Koalemos RAT Campaign\ \ Alessandra\ \ Rizzo](/content/blog/no-fool-s-errand-the-koalemos-rat-campaign/index.html) \ \ Threat Research\ \ Building a Supply Chain Scanner for Fun and Profit\ \ Ariel\ \ Ropek](/content/blog/building-a-supply-chain-scanner-for-fun-and-profit/index.html) \ \ Threat Research\ \ Detecting and Hunting for Cloud Ransomware Part 2: GCP GCS\ \ Alessandra\ \ Rizzo](/content/blog/detecting-and-hunting-for-cloud-ransomware-part-2-gcp-gcs/index.html) \ \ Threat Research\ \ Introducing a Safer, Smarter Way to Launch Detections\ \ Panther Threat Research Team](/content/blog/introducing-a-safer-smarter-way-to-launch-detections/index.html) \ \ Panther + Expel: Bringing AI-Powered SIEM and MDR Together\ \ Katie\ \ Campisi](/content/blog/panther-expel-bringing-ai-powered-siem-and-mdr-together/index.html) \ \ Product\ \ AI in the SOC – Only as Good as the Data You Give It!\ \ Katie\ \ Campisi](/content/blog/ai-in-the-soc-%E2%80%93-only-as-good-as-the-data-you-give-it/index.html) \ \ Threat Research\ \ Detecting and Hunting for Cloud Ransomware Part 1: AWS S3\ \ Alessandra \ \ Rizzo](/content/blog/detecting-and-hunting-for-cloud-ransomware-part-1-aws-s3/index.html) \ \ Threat Research\ \ Elf on a (npm) Shelf\ \ Panther Threat Research Team](/content/blog/elf-on-a-(npm/index.html)-shelf) \ \ Compliance\ \ How to Automate Continuous SOC 2 Monitoring in Cloud Environments\ \ Katie\ \ Campisi](/content/blog/automate-soc2-cloud-monitoring/index.html) \ \ Threat Research\ \ A Data-Driven Analysis of the Sha1-Hulud 2.0 Campaign\ \ Panther Threat Research Team](/content/blog/a-data-driven-analysis-of-the-sha1-hulud-2-0-campaign/index.html) \ \ Threat Research\ \ Detecting and Hunting for GitHub Actions Compromise\ \ Alessandra \ \ Rizzo](/content/blog/detecting-and-hunting-for-github-actions-compromise/index.html) \ \ Threat Research\ \ My Top 4 Takeaways from MITRE ATT&CKcon 6.0\ \ Ariel\ \ Ropek](/content/blog/my-top-4-takeaways-from-mitre-att-ckcon-6-0/index.html) \ \ Company Culture\ \ Doubling Down on Data: Why We're Acquiring Datable\ \ William\ \ Lowe](/content/blog/doubling-down-on-data-why-we-re-acquiring-datable/index.html) \ \ Thought Leadership\ \ Beyond SIEM: Francis Odum Highlights the Shift to Data-Driven Security\ \ Katie\ \ Campisi](/content/blog/beyond-siem-francis-odum-highlights-the-shift-to-data-driven-security/index.html) \ \ Press Release\ \ Panther Achieves the AWS Generative AI Competency\ \ Panther](/content/blog/panther-achieves-the-aws-generative-ai-competency/index.html) \ \ Product\ \ Smarter AI Workflows, Broader Coverage: What’s New in Panther v1.115\ \ Katie\ \ Campisi](/content/blog/smarter-ai-workflows-broader-coverage-what-s-new-in-panther-v1-115/index.html) \ \ Product\ \ Panther x Databricks Private Preview: AI SOC Platform on Your Security Lakehouse\ \ William\ \ Lowe](/content/blog/panther-x-databricks-private-preview-ai-soc-platform-on-your-security-lakehouse/index.html) \ \ Splunk to Panther: A Migration That Transforms Your Security Operations\ \ Mike\ \ Olsen](/content/blog/splunk-to-panther-a-migration-that-transforms-your-security-operations/index.html) \ \ Threat Research\ \ NX Threat Analysis\ \ Ariel\ \ Ropek](/content/blog/nx-threat-analysis/index.html) \ \ Thought Leadership\ \ Join the SIEM Revolution: AI-Ready Security That Scales\ \ William\ \ Lowe](/content/blog/join-the-siem-revolution-ai-ready-security-that-scales/index.html) \ \ Product\ \ New Panther Features Solving Real-World Problems in v1.114\ \ Katie\ \ Campisi](/content/blog/new-panther-features-solving-real-world-problems-in-v1-114/index.html) \ \ Detection & Response\ \ 10x Your Detection Engineering Workflows with MCP\ \ Jack\ \ Naglieri](/content/blog/10-your-detection-engineering-workflows-with-mcp/index.html) \ \ Company Culture\ \ Betting on Panther, Twice\ \ Michael\ \ Baker](/content/blog/betting-on-panther-twice/index.html) \ \ Detection & Response\ \ How Model Context Protocol Helps Security Teams Scale SecOps\ \ Jack\ \ Naglieri](/content/blog/how-model-context-protocol-helps-security-teams-scale-secops/index.html) \ \ Customer Stories\ \ Infoblox Tunes Detections 70% Faster with Panther AI\ \ Katie\ \ Campisi](/content/blog/infoblox-tunes-detections-70-faster-with-panther-ai/index.html) \ \ Product\ \ Panther AI: Transforming Alert Triage and Resolution\ \ Jack\ \ Naglieri](/content/blog/panther-ai-transforming-alert-triage-and-resolution/index.html) \ \ Customer Stories\ \ Cresta Accelerates SecOps with Panther AI, Powered by AWS & Claude\ \ Katie\ \ Campisi](/content/blog/cresta-accelerates-secops-with-panther-ai-powered-by-aws-claude/index.html) \ \ Product\ \ Panther Launches AI-Powered Security Operations\ \ Jack\ \ Naglieri](/content/blog/panther-launches-ai-powered-security-operations/index.html) \ \ Cloud Security\ \ Panther + Snowflake: Security Monitoring with Streaming Analysis for Your Enterprise Data\ \ Jack\ \ Naglieri](/content/blog/panther-snowflake-security-monitoring-with-streaming-analysis-for-your-enterprise-data/index.html) \ \ Cloud Security\ \ Centralize and Correlate Critical Security Data with Panther and Zscaler\ \ Remy\ \ Kullberg](/content/blog/centralize-and-correlate-critical-security-data-with-panther-and-zscaler/index.html) \ \ Cloud Security\ \ Panther + Wiz: Empowering SecOps Teams with Unified Context\ \ Jack\ \ Naglieri](/content/blog/panther-wiz-empowering-secops-teams-with-unified-context/index.html) \ \ Detection & Response\ \ Sigma Rules: Your Guide to Threat Detection’s Open Standard\ \ Panther Labs](/content/blog/your-guide-to-the-sigma-rules-open-standard-for-threat-detection/index.html) \ \ Data Engineering\ \ Introducing PantherFlow: Accelerate Investigations in Your Security Data Lake\ \ Bryan\ \ Peace](/content/blog/introducing-pantherflow/index.html) \ \ Detection & Response\ \ Investigating Amazon EKS Privilege Escalation with PantherFlow\ \ Panther Labs](/content/blog/investigating-amazon-eks-privilege-escalation-with-pantherflow/index.html) \ \ Cloud Security\ \ Panther Debuts as Wiz Defend Launch Partner\ \ Bryan\ \ Peace](/content/blog/panther-debuts-as-wiz-defend-launch-partner/index.html) \ \ Data Engineering\ \ How to Write Queries in PantherFlow, a Piped Search Language\ \ Doug\ \ Miller](/content/blog/how-to-write-queries-in-pantherflow-a-piped-search-language/index.html) \ \ Data Engineering\ \ Why PantherFlow: How Our Piped Query Language Simplifies Search\ \ Doug\ \ Miller](/content/blog/why-pantherflow-how-our-piped-query-language-simplifies-search/index.html) \ \ Thought Leadership\ \ How to Know You're Ready for a Dedicated Detections Team\ \ Remy\ \ Kullberg](/content/blog/how-to-know-youre-ready-for-a-dedicated-detections-team/index.html) \ \ Data Engineering\ \ Python for Cybersecurity: Key Use Cases and Tools\ \ Remy\ \ Kullberg](/content/blog/python-for-cybersecurity-key-use-cases-and-tools/index.html) \ \ Data Engineering\ \ Introducing pypanther: The Future of Code-Driven Detection and Response\ \ Jack\ \ Naglieri](/content/blog/introducing-pypanther-the-future-of-code-driven-detection-and-response/index.html) \ \ Company Culture\ \ Turn Up the Volume, Turn Down the Noise with Code-Driven Correlations at Black Hat 2024\ \ Panther Labs](/content/blog/turn-up-the-volume-turn-down-the-noise-with-code-driven-correlations-at-black-hat-2024/index.html) \ \ Detection & Response\ \ Securing Zoom: How to Detect and Mitigate Threats in Remote Collaboration Tools\ \ Remy\ \ Kullberg](/content/blog/securing-zoom-how-to-detect-and-mitigate-threats-in-remote-collaboration-tools/index.html) \ \ Data Engineering\ \ 5 Reasons Your Pipeline Is Broken‚ And How to Fix It\ \ Bryan\ \ Peace](/content/blog/5-reasons-your-pipeline-is-broken-and-how-to-fix-it/index.html) \ \ Detection & Response\ \ Enhanced Identity Attack Detection with Push Security\ \ Bryan\ \ Peace](/content/blog/enhanced-identity-attack-detection-with-push-security/index.html) \ \ Data Engineering\ \ How to Turn Security Pipelines Into Gold Mines\ \ Bryan\ \ Peace](/content/blog/how-to-turn-security-pipelines-into-gold-mines/index.html) \ \ Detection & Response\ \ Regarding the Recent Campaign Targeting Snowflake Customers\ \ Panther Labs](/content/blog/regarding-the-recent-campaign-targeting-snowflake-customers/index.html) \ \ Data Engineering\ \ Make Your SecOps Pipe Dreams a Reality\ \ Bryan\ \ Peace](/content/blog/make-your-secops-pipe-dreams-a-reality/index.html) \ \ Cloud Security\ \ Why You Should Be Ingesting AWS VPC Flow Logs\ \ Remy\ \ Kullberg](/content/blog/why-you-should-be-ingesting-aws-vpc-flow-logs/index.html) \ \ Detection & Response\ \ Drowning in False Positives? Your Detections Probably Suck\ \ Katie\ \ Campisi](/content/blog/drowning-in-false-positives-your-detections-probably-suck/index.html) \ \ Detection & Response\ \ Introducing Panther’s Newest Alert Destination: Torq\ \ Panther Labs](/content/blog/introducing-panthers-newest-alert-destination-torq/index.html) \ \ Thought Leadership\ \ Restoring Clarity in a Broken System\ \ Matt\ \ Jezorek](/content/blog/restoring-clarity-broken-system/index.html) \ \ Data Engineering\ \ Panther Users Can Now Seamlessly Leverage Powerful Observo.ai Data Pipeline Features\ \ Panther Labs](/content/blog/panther-users-can-now-seamlessly-leverage-powerful-observo-ai-data-pipeline-features/index.html) \ \ Company Culture\ \ Stop Creating Dumb Alerts: See Our New AI and Correlation Rules at RSA\ \ Panther Labs](/content/blog/stop-creating-dumb-alerts-see-our-new-ai-and-correlation-rules-at-rsa/index.html) \ \ Company Culture\ \ Meet Matt Jezorek: One of Panther’s Earliest Champions\ \ William\ \ Lowe](/content/blog/meet-matt-jezorek-panther-s-new-vp-of-product-and-security/index.html) \ \ Cloud Security\ \ Why You Should Be Ingesting AWS GuardDuty Logs\ \ Remy\ \ Kullberg](/content/blog/why-you-should-be-ingesting-aws-guardduty-logs/index.html) \ \ Cloud Security\ \ Panther Now Integrates with Amazon Security Lake: Embracing the Open Cybersecurity Schema Framework (OCSF)\ \ Panther Labs](/content/blog/panther-now-integrates-with-aws-security-lake-embracing-the-open-cybersecurity-schema-framework-ocsf/index.html) \ \ Customer Stories\ \ Learn it Firsthand: How Zapier Uses Detection-as-Code to Increase Their Alert Fidelity\ \ Panther Labs](/content/blog/learn-it-firsthand-how-zapier-uses-detection-as-code-to-increase-their-alert-fidelity/index.html) \ \ Cloud Security\ \ Why You Should Be Ingesting AWS CloudTrail Logs\ \ Remy\ \ Kullberg](/content/blog/why-you-should-be-ingesting-aws-cloudtrail-logs/index.html) \ \ Threat Research\ \ What You Need to Know About the Latest GitLab Vulnerability (Including Detection)\ \ Ariel\ \ Ropek](/content/blog/what-you-need-to-know-about-the-latest-gitlab-vulnerability-including-detection/index.html) \ \ Detection & Response\ \ Identifying and Mitigating False Positive Alerts\ \ Remy\ \ Kullberg](/content/blog/identifying-and-mitigating-false-positive-alerts/index.html) \ \ Thought Leadership\ \ Is Your SIEM a Hotel California?\ \ Ken\ \ Westin](/content/blog/is-your-siem-a-hotel-california/index.html) \ \ Detection & Response\ \ Unraveling SIEM Correlation Techniques\ \ Jack\ \ Naglieri](/content/blog/unraveling-siem-correlation-techniques/index.html) \ \ Detection & Response\ \ CVE-2024-3094 - Linux Supply Chain Compromise Affecting XZ Utils Data Compression Library\ \ Ken\ \ Westin](/content/blog/cve-2024-3094-linux-supply-chain-compromise-affecting-xz-utils-data-compression-library/index.html) \ \ Threat Research\ \ Critical Steps To Detect and Prevent Cryptojacking In Your Cloud Infrastructure\ \ Ariel\ \ Ropek](/content/blog/critical-steps-to-detect-and-prevent-cryptojacking-in-your-cloud-infrastructure/index.html) \ \ Compliance\ \ How North Korean Cybercrime Aids the Russian Military and Circumvents Sanctions\ \ Ken\ \ Westin](/content/blog/how-north-korean-cybercrime-aids-the-russian-military-and-circumvents-sanctions/index.html) \ \ Detection & Response\ \ Mitigating the Midnight Blizzard Threat\ \ Ken\ \ Westin](/content/blog/mitigating-the-midnight-blizzard-threat/index.html) \ \ Threat Research\ \ The Scattered Spider Attack: Safeguarding Your Okta Infrastructure\ \ Ariel\ \ Ropek](/content/blog/the-scattered-spider-attack-safeguarding-your-okta-infrastructure/index.html) \ \ Thought Leadership\ \ Mastering Alert Fatigue: Best Practices for Centralized Management\ \ Remy\ \ Kullberg](/content/blog/mastering-alert-fatigue-best-practices-for-centralized-management/index.html) \ \ Cloud Security\ \ Securing the Cloud with Panther: Providing Multi Cloud Support Across AWS, GCP, and Azure\ \ Carrie\ \ Pascale](/content/blog/securing-the-cloud-with-panther-providing-multi-cloud-support-across-aws-gcp-and-azure/index.html) \ \ Company Culture\ \ From Vision to Reality: Panther‚s New Identity\ \ Panther Labs](/content/blog/from-vision-to-reality-panthers-new-identity/index.html) \ \ Detection & Response\ \ Harnessing the Power of Data Lake Search and DaC for Crypto Mining Malware Detection and Investigation\ \ Panther Labs](/content/blog/harnessing-the-power-of-data-lake-search-and-dac-for-crypto-mining-malware-detection-and-investigation/index.html) \ \ Thought Leadership\ \ Why Proactive Threat Monitoring is Crucial: Unveiling the Invisible Risks\ \ Panther Labs](/content/blog/why-proactive-threat-monitoring-is-crucial-unveiling-the-invisible-risks/index.html) \ \ Company Culture\ \ Built In Recognizes Panther as Top Workplace in Industry!\ \ Pamela\ \ Golden](/content/blog/built-in-recognizes-panther-as-top-workplace-in-industry/index.html) \ \ Data Engineering\ \ Introducing the Panther Sigma Rule Converter\ \ Panther Labs](/content/blog/introducing-the-panther-sigma-rule-converter/index.html) \ \ Thought Leadership\ \ How to Evaluate a Security Detection Platform\ \ Panther Labs](/content/blog/how-to-evaluate-a-security-detection-platform/index.html) \ \ Detection & Response\ \ How to Create a Code-Based Detection\ \ Remy\ \ Kullberg](/content/blog/how-to-create-a-code-based-detection/index.html) \ \ Detection & Response\ \ How Detection-as-Code Revolutionizes Security Posture\ \ Remy\ \ Kullberg](/content/blog/how-detection-as-code-revolutionizes-security-posture/index.html) \ \ Product\ \ Panther Announces Splunk Alert Destination Integration\ \ Ken\ \ Westin](/content/blog/panther-announces-splunk-alert-destination-integration/index.html) \ \ Product\ \ Introducing Panther‚s Security Data Lake Search\ \ Panther Labs](/content/blog/introducing-panthers-security-data-lake-search/index.html) \ \ Thought Leadership\ \ Shifting from Reactive to Proactive Cybersecurity Postures\ \ Panther Labs](/content/blog/shifting-from-reactive-to-proactive-cybersecurity-postures/index.html) \ \ Compliance\ \ Silver Surfers: Guarding Seniors in the Digital Wave of Cybersecurity\ \ Ashley\ \ Yvonne](/content/blog/silver-surfers-guarding-seniors-in-the-digital-wave-of-cybersecurity/index.html) \ \ Company Culture\ \ SOCtober Spook Fest: Watch All 3 Stories\ \ Panther Labs](/content/blog/soctober-spook-fest-watch-all-3-stories/index.html) \ \ Product\ \ Collaborate with Confidence: Monitor Notion Audit Logs with Panther\ \ Panther Labs](/content/blog/collaborate-with-confidence-monitor-notion-audit-logs-with-panther/index.html) \ \ Product\ \ User Experience, the Unseen Hero in Security Products\ \ Panther Labs](/content/blog/user-experience-the-unseen-hero-in-security-products/index.html) \ \ Cloud Security\ \ The Great Cloud-Native Fib: Unmasking a Core SIEM Deception\ \ Panther Labs](/content/blog/the-great-cloud-native-fib-unmasking-a-core-siem-deception/index.html) \ \ Cloud Security\ \ Shifting SIEM Left: Securing the Software Supply Chain with GitHub Monitoring\ \ Ken\ \ Westin](/content/blog/shifting-siem-left-securing-the-software-supply-chain-with-github-monitoring/index.html) \ \ Detection & Response\ \ A Quick and Easy Guide to Detection and Query Tuning\ \ Andrea\ \ Youwakim](/content/blog/a-quick-and-easy-guide-to-detection-and-query-tuning/index.html) \ \ Data Engineering\ \ Panther Users Can Now Manage S3 Log Sources with Terraform\ \ Dan\ \ Biwer](/content/blog/manage-s3-log-sources-with-terraform/index.html) \ \ Product\ \ Monitoring Tailscale Network & Audit Logs with Panther\ \ Grant\ \ Joy](/content/blog/tailscale-log-integration/index.html) \ \ Customer Stories\ \ How FloQast Transforms Security Ops with Detection-as-Code\ \ Panther Labs](/content/blog/how-floqast-transforms-security-ops-with-detection-as-code/index.html) \ \ Detection & Response\ \ Accelerating Investigation with Panther\ \ Ted\ \ Kietzman](/content/blog/accelerating-investigation-with-panther/index.html) \ \ Cloud Security\ \ How Panther Ensures Resilience During Cloud Outages\ \ Mark\ \ Stumpf](/content/blog/how-panther-ensures-resilience-during-cloud-outages/index.html) \ \ Detection & Response\ \ Nation-State Actors Targeting Software Supply Chain via GitHub\ \ Ken\ \ Westin](/content/blog/nation-state-actors-targeting-software-supply-chain-via-github/index.html) \ \ Compliance\ \ Hey Microsoft, Security Logs Want to be Free!\ \ Ken\ \ Westin](/content/blog/hey-microsoft-security-logs-want-to-be-free/index.html) \ \ Data Engineering\ \ Using AWS Secrets Manager with Panther Detections\ \ Carrie\ \ Pascale](/content/blog/using-aws-secrets-manager-with-panther-detections/index.html) \ \ Detection & Response\ \ The Power of Detection-as-Code, For Everyone\ \ Valerie\ \ Pitsch](/content/blog/the-power-of-detection-as-code-for-everyone/index.html) \ \ Customer Stories\ \ How Workrise Implemented Panther To Achieve Full Visibility\ \ Panther Labs](/content/blog/how-workrise-implemented-panther-to-achieve-full-visibility/index.html) \ \ Company Culture\ \ Panther Recognized as Fortune Best Places to Work in the Bay Area\ \ Pamela\ \ Golden](/content/blog/fostering-panther-pride-our-journey-to-being-recognized-as-one-of-fortunes-best-workplaces/index.html) \ \ Product\ \ Realize SIEM Value from Day One\ \ Ted\ \ Kietzman](/content/blog/realize-siem-value-from-day-one/index.html) \ \ Compliance\ \ How Panther Helps With SOC 2\ \ Austin\ \ Hirsch](/content/blog/how-panther-helps-with-soc-2/index.html) \ \ Detection & Response\ \ Building a Detection & Response Team in a Cloud First Environment\ \ Zeeshan\ \ Khadim](/content/blog/building-a-detection-response-team-in-a-cloud-first-environment/index.html) \ \ Cloud Security\ \ The Darksaber of Modern SIEM Tools in a Galaxy Far, Far Away\ \ Panther Labs](/content/blog/the-darksaber-of-modern-siem-tools-in-a-galaxy-far-far-away/index.html) \ \ Data Engineering\ \ Best practices for running faster SQL queries\ \ Lisa\ \ Meed](/content/blog/best-practices-for-faster-sql-queries/index.html) \ \ Detection & Response\ \ Discovering Exfiltrated Credentials\ \ Ed\ \ Anderson](/content/blog/discovering-exfiltrated-credentials/index.html) \ \ Detection & Response\ \ Analyzing Lateral Movement in Google Cloud Platform\ \ Brandon\ \ Min](/content/blog/analyzing-lateral-movement-in-google-cloud-platform/index.html) \ \ Detection & Response\ \ Maximizing Endpoint Security with SentinelOne and Panther\ \ Brandon\ \ Min](/content/blog/maximizing-endpoint-security-with-sentinelone-and-panther/index.html) \ \ Detection & Response\ \ Method to the Madness: Developing a Detection Engineering Methodology\ \ Ken\ \ Westin](/content/blog/method-to-the-madness-developing-a-detection-engineering-methodology/index.html) \ \ Detection & Response\ \ Faster Triaging with Slack Bot Boomerangs\ \ Ted\ \ Kietzman](/content/blog/faster-triaging-with-slack-bot-boomerangs/index.html) \ \ Detection & Response\ \ Writing Your First Python Detection in 30 Minutes with Okta and Panther\ \ Ken\ \ Westin](/content/blog/writing-your-first-python-detection-in-30-minutes-with-okta-and-panther/index.html) \ \ Detection & Response\ \ Top 5 AWS Services to Protect with CloudTrail\ \ Brandon\ \ Min](/content/blog/top-5-aws-services-to-protect-with-cloudtrail/index.html) \ \ Detection & Response\ \ Zero False Positives from your SIEM\ \ Jack\ \ Naglieri](/content/blog/zero-false-positives-from-your-siem/index.html) \ \ Detection & Response\ \ Threat Hunting in AWS\ \ Calvin\ \ Kim](/content/blog/threat-hunting-in-aws/index.html) \ \ Detection & Response\ \ Accelerate Response with the Panther Slack Bot\ \ Ted\ \ Kietzman](/content/blog/accelerate-response-with-the-panther-slackbot/index.html) \ \ Cloud Security\ \ Optimize CloudTrail Ingestion with Modern SIEM\ \ Brandon\ \ Min](/content/blog/optimize-cloudtrail-ingestion-with-modern-siem/index.html) \ \ Thought Leadership\ \ 5 Things You Need to Know About the State of SIEM in 2022\ \ Panther Labs](/content/blog/5-things-you-need-to-know-about-the-state-of-siem-in-2022/index.html) \ \ Thought Leadership\ \ State of SIEM 2022: 5 Key Takeaways\ \ Panther Labs](/content/blog/state-of-siem-2022-5-key-takeaways/index.html) \ \ Cloud Security\ \ Get Started: AWS and Panther\ \ Brandon\ \ Min](/content/blog/get-started-aws-and-panther/index.html) \ \ Cloud Security\ \ Protect Azure Services with Microsoft Graph API\ \ Brandon\ \ Min](/content/blog/protect-azure-services-with-microsoft-graph-api/index.html) \ \ Customer Stories\ \ How Booz Allen Hamilton uses Detection-as-Code to Transform Security in the Federal Government\ \ Mike\ \ Saxton](/content/blog/how-booz-allen-hamilton-uses-detection-as-code/index.html) \ \ Thought Leadership\ \ Going Phishless: How Panther Deployed WebAuthN with Okta & YubiKeys\ \ Panther Labs](/content/blog/going-phishless-how-panther-deployed-webauthn/index.html) \ \ Company Culture\ \ 13 Questions with Founder and CEO Jack Naglieri in the Panther Community\ \ Matt\ \ Korovesis](/content/blog/13-questions-with-founder-and-ceo-jack-naglieri/index.html) \ \ Detection & Response\ \ Adopting Real-Time Threat Detection Workflows\ \ Brandon\ \ Min](/content/blog/adopting-real-time-threat-detection/index.html) \ \ Thought Leadership\ \ Five Lessons From Detection & Response Leaders\ \ Jack\ \ Naglieri](/content/blog/five-lessons-from-detection-response-leaders/index.html) \ \ Detection & Response\ \ The Benefits of Using Python to Write SIEM Detections\ \ Brandon\ \ Min](/content/blog/using-python-to-write-siem-detections/index.html) \ \ Company Culture\ \ Join Panther’s Founder and CEO Jack Naglieri for a Community AMA!\ \ Matt\ \ Korovesis](/content/blog/join-panthers-founder-and-ceo-jack-naglieri-for-a-community-ama/index.html) \ \ Detection & Response\ \ Rapid Detection and Response with Panther & Tines\ \ Mark\ \ Stone](/content/blog/rapid-detection-and-response-with-panther-tines/index.html) \ \ Detection & Response\ \ Modernize detection engineering with Detection-as-Code\ \ Kyle\ \ Bailey](/content/blog/modernize-detection-engineering-with-detection-as-code/index.html) \ \ Cloud Security\ \ Protect Business Critical Applications with GitHub Audit Logs & Modern SIEM\ \ Brandon\ \ Min](/content/blog/protect-business-critical-applications-with-github-audit-logs-modern-siem/index.html) \ \ Detection & Response\ \ Think Like a Detection Engineer, Pt. 2: Rule Writing\ \ Jack\ \ Naglieri](/content/blog/think-like-a-detection-engineer-pt-2-rule-writing/index.html) \ \ Detection & Response\ \ Think Like a Detection Engineer, Pt. 1: Logging\ \ Jack\ \ Naglieri](/content/blog/think-like-a-detection-engineer-pt-1-logging/index.html) \ \ Company Culture\ \ Connect with Panther Users and Security Experts in the Panther Community\ \ Matt\ \ Korovesis](/content/blog/introducing-the-panther-community/index.html) \ \ Cloud Security\ \ Monitoring 1Password Logs\ \ Weyland\ \ Chiang](/content/blog/monitoring-1password-logs/index.html) \ \ Cloud Security\ \ How Panther Protects Data in the Cloud\ \ Brandon\ \ Min](/content/blog/how-panther-protects-cloud-data/index.html) \ \ Product\ \ Avoiding Alert Storms with Data Replay in Panther\ \ Brandon\ \ Min](/content/blog/data-replay-in-panther/index.html) \ \ Company Culture\ \ Reflecting on what makes Panther a “Great Place to Work”\ \ Pamela\ \ Golden](/content/blog/reflecting-on-what-makes-panther-a-great-place-to-work/index.html) \ \ Detection & Response\ \ Reduce false positives with GreyNoise threat intelligence in Panther\ \ Panther Labs](/content/blog/greynoise-threat-intelligence-in-panther/index.html) \ \ Detection & Response\ \ Okta and LAPSUS$: Investigation Resources and How Panther Can Help\ \ Panther Labs](/content/blog/investigating-the-2022-lapsus-okta-security-incident/index.html) \ \ Product\ \ Improve detection fidelity and alert triage with Lookup Tables in Panther\ \ Panther Labs](/content/blog/improve-detection-fidelity-and-alert-triage-with-lookup-tables-in-panther/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Bill Lawrence\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-bill-lawrence-2/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Slava Bronfman\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-slava-bronfman/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Carlos Morales\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-carlos-morales/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Ashu Savani\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-ashu-savani/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Albert Heinle\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-albert-heinle/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Aliaksandr Latushka\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-aliaksandr-latushka/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Isla Sibanda\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-isla-sibanda/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Matt Hartley\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-matt-hartley/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Hugo Sanchez\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-hugo-sanchez/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From David Vincent\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-david-vincent-2/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Giora Engel\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-giora-engel/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Eslam Reda\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-eslam-reda/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Kimberly Sutherland\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-kimberly-sutherland/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Bruce Young\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-bruce-young/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Morgan Hill\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-morgan-hill/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Yaniv Masjedi\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-yaniv-masjedi/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Haseeb Awan\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-haseeb-awan/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Eric McGee\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-eric-mcgee/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Steve Tcherchian\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-steve-tcherchian/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Purandar Das\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-purandar-das/index.html) \ \ Detection & Response\ \ Panther’s guide to Log4j exploitation prevention and detection\ \ Panther Labs](/content/blog/panthers-guide-to-log4j-exploitation-prevention-and-detection/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Roger Smith\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-roger-smith/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Ian L. Paterson\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-ian-l-paterson/index.html) \ \ Company Culture\ \ Building the Future of Security: Panther Series B Funding\ \ Jack\ \ Naglieri](/content/blog/building-the-future-of-security-panther-series-b-funding/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Jerry Sanchez\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-jerry-sanchez/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Chris Connor\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-chris-connor/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Charlie Riley\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-charlie-riley/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Alex Cherones\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-alex-cherones/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Bill Lawrence\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-bill-lawrence/index.html) \ \ Thought Leadership\ \ State of SIEM in 2021: 6 Key Takeaways\ \ Jack\ \ Naglieri](/content/blog/state-of-siem-in-2021-6-key-takeaways/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Zach Fuller\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-zach-fuller/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Paul Mansur\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-paul-mansur/index.html) \ \ Detection & Response\ \ Find Patterns Quickly with Indicator Search Drill Down\ \ Panther Labs](/content/blog/find-patterns-quickly-with-indicator-search-drill-down/index.html) \ \ Thought Leadership\ \ Future of Cyber Attacks\ \ Panther Labs](/content/blog/future-of-cyber-attacks/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Jonathan Roy\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-jonathan-roy/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From David Pignolet\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-david-pignolet/index.html) \ \ Detection & Response\ \ Detect Everything, Real-Time Alerts As Needed\ \ Nick\ \ Kuligoski](/content/blog/detect-everything-real-time-alerts-as-needed/index.html) \ \ Cloud Security\ \ Why Panther Chose Snowflake\ \ Jack\ \ Naglieri](/content/blog/why-panther-chose-snowflake/index.html) \ \ Thought Leadership\ \ Buy or Build Your Security Solution?\ \ Panther Labs](/content/blog/buy-or-build-your-security-solution/index.html) \ \ Company Culture\ \ Snowflake Cybersecurity Partner of The Year\ \ Jack\ \ Naglieri](/content/blog/snowflake-cybersecurity-partner-of-the-year/index.html) \ \ Product\ \ Going Closed Source\ \ Jack\ \ Naglieri](/content/blog/going-closed-source-panther-community-edition-is-being-sunset-with-v1-16-as-our-last-open-source-release/index.html) \ \ Detection & Response\ \ Advanced Detections with Scheduled Queries\ \ William\ \ Lowe](/content/blog/scheduled-queries-for-advanced-threat-detection/index.html) \ \ Detection & Response\ \ Security Monitoring with CrowdStrike Falcon Events\ \ Jack\ \ Naglieri](/content/blog/security-monitoring-crowdstrike-falcon/index.html) \ \ Product\ \ Activate Security Automation with Alert Context\ \ Sugandha\ \ Lahoti](/content/blog/security-automation-alert-context/index.html) \ \ Detection & Response\ \ Detecting Sunburst Malware with Panther\ \ Jade\ \ Catalano](/content/blog/detecting-sunburst-malware-with-panther/index.html) \ \ Product\ \ Automated Detection and Response with Panther and Tines\ \ Jack\ \ Naglieri](/content/blog/security-automation-panther-tines/index.html) \ \ Detection & Response\ \ Threat Hunting at Scale\ \ Jack\ \ Naglieri](/content/blog/threat-hunting/index.html) \ \ Detection & Response\ \ Analyze Internal Security Data with Custom Log Parsers\ \ Sugandha\ \ Lahoti](/content/blog/custom-log-parsers/index.html) \ \ Product\ \ Triage Alerts Faster with Alert Summaries\ \ Sugandha\ \ Lahoti](/content/blog/faster-alert-triage/index.html) \ \ Product\ \ Continuous Security Monitoring for Slack, Cloudflare, and Fastly\ \ Sugandha\ \ Lahoti](/content/blog/security-monitoring-slack-cloudflare-fastly/index.html) \ \ Company Culture\ \ From StreamAlert to Panther\ \ Jack\ \ Naglieri](/content/blog/streamalert-to-panther/index.html) \ \ Company Culture\ \ Panther Labs Series A Funding\ \ Jack\ \ Naglieri](/content/blog/series-a-funding/index.html) \ \ Product\ \ Why Panther Chose to Open Up Its Security Data Lake\ \ Russell\ \ Leighton](/content/blog/panther-database-as-service-modern-serverless-architecture/index.html) \ \ Product\ \ Feature Spotlight: Snowflake-Powered Data Explorer\ \ Sugandha\ \ Lahoti](/content/blog/snowflake-powered-data-explorer/index.html) \ \ Detection & Response\ \ Osquery Log Analysis Guide\ \ Jack\ \ Naglieri](/content/blog/osquery-log-analysis/index.html) \ \ Product\ \ Panther v1.6 Spotlight: Log Analysis Dashboard, SIEM for G Suite and Box Logs, SSO, Dark Theme, and more!\ \ Sugandha\ \ Lahoti](/content/blog/1-6-spotlight-siem-g-suite-box-logs-single-sign-on-dark-theme/index.html) \ \ Product\ \ Visualize Your AWS Cloud Security Posture with Charts and Graphs\ \ Sugandha\ \ Lahoti](/content/blog/aws-cloud-security-charts-graphs/index.html) \ \ Product\ \ Panther and Snowflake Partner to Power Enterprise SIEM Workloads\ \ Kartikey\ \ Pandey](/content/blog/panther-siem-partners-snowflake-press-release/index.html) \ \ Product\ \ Panther’s CLI Tool\ \ Sugandha\ \ Lahoti](/content/blog/panthers-cli-tool/index.html) \ \ Product\ \ Search Performance Optimizations\ \ Sugandha\ \ Lahoti](/content/blog/feature-spotlight-automatic-log-compaction/index.html) \ \ Product\ \ New Log Parsers\ \ Sugandha\ \ Lahoti](/content/blog/panther-log-parsers-feature/index.html) \ \ Cloud Security\ \ Panther Cloud-Native SIEM: Moving Beyond Traditional SIEMs\ \ Kartikey\ \ Pandey](/content/blog/cloud-native-siem-with-panther/index.html) \ \ Cloud Security\ \ Panther v1.0: Cloud-Native SIEM for Modern Security Teams\ \ Jack\ \ Naglieri](/content/blog/panther-v1-open-source-siem/index.html) \ \ Company Culture\ \ RSA Conference 2020: A Recap of the Top Announcements\ \ Sugandha\ \ Lahoti](/content/blog/rsa-conference-2020-announcements/index.html) \ \ Cloud Security\ \ 6 AWS Services for Cloud Security Detection\ \ Sugandha\ \ Lahoti](/content/blog/aws-security-services/index.html) \ \ Cloud Security\ \ 6 Open Source Cloud Security Tools You Should Know\ \ Sugandha\ \ Lahoti](/content/blog/open-source-cloud-security-tools/index.html) \ \ Product\ \ Announcing Panther: A Cloud-Native, Continuous Security Monitoring Platform\ \ Jack\ \ Naglieri](/content/blog/run-panther/index.html) \ \ Company Culture\ \ Panther Labs Raises $4.5M to Push Cloud Security Forward\ \ Jack\ \ Naglieri](/content/blog/panther-seed/index.html)
Bolt-on AI closes alerts. Panther closes the loop.
See how Panther compounds intelligence across the SOC.
Detect, investigate, and respond to threats at cloud scale — powered by code and AI.
Platform
Alerting and Triage Automation
Solutions
Managed Detection and Response
Support
Resources
Company
All rights reserved © 2026 Panther, Inc