AI SOC, Detection & Security Operations Blog | Panther

NEW

Panther joins Databricks to build the future of the security lakehouse. Read more →

close

Platform

Solutions

Resources

Company

InsightsfromthefrontlinesofSecOps

Ideas, lessons, and tactics from the team behind Panther.

\ \ Threat Research\ \ A Patient Trojan Dropper: polymarket-stake-math Steals Wallet Keys, Browser Sessions, and Telegram from Crypto Developers\ \ Read more\ \ Ariel\ \ Ropek](/content/blog/a-patient-trojan-dropper-polymarket-stake-math-steals-wallet-keys-browser-sessions-and-telegram-from-crypto-developers/index.html)

See all resources

All

Threat Research

Detection & Response

Customer Stories

Thought Leadership

Cloud Security

Product

Company Culture

Data Engineering

Compliance

Press Release

\ \ 10 Best AI SOC Platforms: Features & Use Cases\ \ Michelle\ \ Dufty](/content/blog/best-ai-soc-platforms/index.html) \ \ Product\ \ Google Threat Intelligence Now Available in Panther Detections\ \ Kostas\ \ Papageorgiou](/content/blog/google-threat-intelligence-now-available-in-panther-detections/index.html) \ \ Best SIEM Tools (2026): Detection, Deployment Options & Real Trade-offs\ \ Michelle\ \ Dufty](/content/blog/best-siem-tools/index.html) \ \ AI governance implementation: A practical guide for security teams\ \ Michelle\ \ Dufty](/content/blog/ai-governance-implementation-guide/index.html) \ \ AI governance challenges: what security teams need to solve first\ \ Michelle\ \ Dufty](/content/blog/ai-governance-challenges/index.html) \ \ AI governance responsibilities: Who owns what in an AI-powered security operations center?\ \ Michelle\ \ Dufty](/content/blog/ai-governance-responsibilities/index.html) \ \ AI governance monitoring: How to track AI actions, approvals, and risk\ \ Michelle\ \ Dufty](/content/blog/ai-governance-monitoring/index.html) \ \ AI Incident Response: Where Agents Help and Where Analysts Still Lead\ \ Michelle\ \ Dufty](/content/blog/ai-incident-response/index.html) \ \ How To Measure AI SOC ROI: The Metrics That Actually Matter to Leadership\ \ Michelle\ \ Dufty](/content/blog/measure-ai-soc-roi/index.html) \ \ AI for Log Analysis: What It Speeds Up and What to Validate\ \ Michelle\ \ Dufty](/content/blog/ai-for-log-analysis/index.html) \ \ What Is an Audit Trail? Why AI SOC Tools Need One\ \ Michelle\ \ Dufty](/content/blog/what-is-an-audit-trail/index.html) \ \ What Is AI Threat Detection? Where It Helps Most and Where It Still Needs Human Review\ \ Michelle\ \ Dufty](/content/blog/ai-threat-detection/index.html) \ \ AI Security Operations Center (SOC) Evaluation: 28 Questions to Ask Before You Trust a Vendor\ \ Michelle\ \ Dufty](/content/blog/ai-soc-vendor-evaluation-questions/index.html) \ \ Predictive Threat Intelligence: What It Actually Means for Security Operations\ \ Michelle\ \ Dufty](/content/blog/predictive-threat-intelligence/index.html) \ \ What Is Shadow AI? Why Security Teams Need to See It Early\ \ Michelle\ \ Dufty](/content/blog/what-is-shadow-ai/index.html) \ \ Agentic AI vs. Generative AI: What the Difference Means for SOC Teams\ \ Michelle\ \ Dufty](/content/blog/agentic-ai-vs-generative-ai-soc-teams/index.html) \ \ Threat Research\ \ Lend Me Your Claude: The Cost of Borrowed AI Compute\ \ Zaynah\ \ Smith-DaSilva](/content/blog/lend-me-your-claude-the-cost-of-borrowed-ai-compute/index.html) \ \ Threat Research\ \ Through the Looking Glass: Simulating an Adversary in Okta\ \ Zaynah\ \ Smith-DaSilva](/content/blog/through-the-looking-glass-simulating-an-adversary-in-okta/index.html) \ \ Product\ \ Cloud Infrastructure Monitoring: Best Practices for Modern SOC Teams\ \ Katie\ \ Campisi](/content/blog/cloud-infrastructure-monitoring-best-practices-for-modern-soc-teams/index.html) \ \ Threat Research\ \ Mini Shai-Hulud Supply-Chain Compromise of @redhat-cloud-services npm Packages via GitHub Actions OIDC Abuse\ \ Alessandra\ \ Rizzo](/content/blog/mini-shai-hulud-supply-chain-compromise-of-redhat-cloud-services-npm-packages-via-github-actions-oidc-abuse/index.html) \ \ AI Detection Engineering: How AI Helps Write, Test, and Tune Detection Rules\ \ Michelle\ \ Dufty](/content/blog/ai-detection-engineering/index.html) \ \ Prompt Injection Security: How to Test for It and Reduce the Risk\ \ Michelle\ \ Dufty](/content/blog/prompt-injection-security/index.html) \ \ Agentic Security Orchestration: Where Agents Fit and Where Humans Still Matter\ \ Michelle\ \ Dufty](/content/blog/agentic-security-orchestration/index.html) \ \ 7 Best AI Tools for Security Alert Triage\ \ Michelle\ \ Dufty](/content/blog/ai-tools-security-alert-triage/index.html) \ \ 8 Best Tools for Automating EDR Alert Triage\ \ Michelle\ \ Dufty](/content/blog/tools-for-automating-edr-alert-triage/index.html) \ \ Threat Research\ \ FragMiner: A Triple Threat Hiding in npm, Kernel Exploit, Supply Chain Worm, and Cryptomining from a Single Package\ \ Michael\ \ Baker](/content/blog/fragminer-a-triple-threat-hiding-in-npm-kernel-exploit-supply-chain-worm-and-cryptomining-from-a-single-package/index.html) \ \ Product\ \ Identity Threat Detection: Best Practices for Modern SOC Teams\ \ Katie\ \ Campisi](/content/blog/identity-threat-detection-best-practices-for-modern-soc-teams/index.html) \ \ Threat Research\ \ Crate Expectations: NastyC2 Ships Rust Post-Exploitation Framework Through NPM\ \ Alessandra\ \ Rizzo](/content/blog/crate-expectations-nastyc2-ships-rust-post-exploitation-framework-through-npm/index.html) \ \ Threat Research\ \ Mapping The Contagious Trader Delivery Network\ \ Alessandra\ \ Rizzo](/content/blog/mapping-the-contagious-trader-delivery-network/index.html) \ \ AI Case Triage: How to Prioritize Security Cases Without Burning Out Your Team\ \ Michelle\ \ Dufty](/content/blog/ai-case-triage/index.html) \ \ Alert Triage Automation: How to Reduce Manual Review Without Missing Real Threats\ \ Michelle\ \ Dufty](/content/blog/alert-triage-automation/index.html) \ \ AI-Enabled Incident Triage: How Teams Investigate Faster With Better Context\ \ Michelle\ \ Dufty](/content/blog/ai-enabled-incident-triage/index.html) \ \ What Is a SIEM Agent? How Agentic SIEM Changes Triage and Investigation\ \ Michelle\ \ Dufty](/content/blog/what-is-a-siem-agent/index.html) \ \ AI Agents for Incident Triage and Prioritization: What Actually Works\ \ Michelle\ \ Dufty](/content/blog/ai-agents-incident-triage-prioritization/index.html) \ \ How to Secure an MCP Server: Practical Controls for Security Teams\ \ Michelle\ \ Dufty](/content/blog/how-to-secure-an-mcp-server/index.html) \ \ AI Threat Investigation: Where AI Helps and Where Analysts Still Lead\ \ Michelle\ \ Dufty](/content/blog/ai-threat-investigation/index.html) \ \ AI False Positives in the SOC: Why They Happen and How to Reduce Them\ \ Michelle\ \ Dufty](/content/blog/ai-false-positives-soc/index.html) \ \ Agentic AI Security Risks: What Changes When AI Can Take Action\ \ Michelle\ \ Dufty](/content/blog/agentic-ai-security-risks/index.html) \ \ What Is AI SecOps? Use Cases, Benefits, and What Good Looks Like\ \ Michelle\ \ Dufty](/content/blog/what-is-ai-secops/index.html) \ \ Adversarial AI: Attacks, Risks, and Defenses for Security Teams\ \ Michelle\ \ Dufty](/content/blog/adversarial-ai/index.html) \ \ Machine Learning in Cybersecurity: Applications and Benefits\ \ Michelle\ \ Dufty](/content/blog/machine-learning-in-cybersecurity/index.html) \ \ What Is AI TRiSM? Framework, Use Cases, and Security Implications\ \ Michelle\ \ Dufty](/content/blog/what-is-ai-trism/index.html) \ \ AI Security Risks: The Practical Threats Security Teams Should Prioritize\ \ Michelle\ \ Dufty](/content/blog/ai-security-risks-prioritization/index.html) \ \ Human in the Loop: Why AI Security Operations Center (SOC) Tools Still Need Analyst Approval\ \ Michelle\ \ Dufty](/content/blog/human-in-the-loop/index.html) \ \ Product\ \ Tuning Detections Without a Backlog\ \ Katie\ \ Campisi](/content/blog/tuning-detections-without-a-backlog/index.html) \ \ Product\ \ Autonomous Threat Hunting\ \ Katie\ \ Campisi](/content/blog/autonomous-threat-hunting/index.html) \ \ Threat Research\ \ 4 Years, 51 Packages, 3 organizations: How npm Became a Gambling Ring's Config Server\ \ Panther Threat Research Team](/content/blog/4-years-51-packages-3-organizations-how-npm-became-a-gambling-ring-s-config-server/index.html) \ \ Threat Research\ \ Frankly Malicious: Inside a 38-Package NPM Supply Chain Campaign Targeting Tech Giants\ \ Zaynah\ \ Smith-DaSilva](/content/blog/frankly-malicious-inside-a-38-package-npm-supply-chain-campaign-targeting-tech-giants/index.html) \ \ What is SecDevOps? A Security-First Development Guide\ \ Michelle\ \ Dufty](/content/blog/what-is-secdevops/index.html) \ \ What Is Threat Detection and Response (TDR)?\ \ Michelle\ \ Dufty](/content/blog/threat-detection/index.html) \ \ What Is Threat Hunting? Process, Tools, and Techniques\ \ Michelle\ \ Dufty](/content/blog/what-is-threat-hunting-process-tools-and-techniques/index.html) \ \ What Is Lateral Movement? Prevention, Detection, & Examples\ \ Michelle\ \ Dufty](/content/blog/lateral-movement-meaning/index.html) \ \ AI SOC Agents: What They Can Do Today and What They'll Do Next\ \ Michelle\ \ Dufty](/content/blog/ai-soc-agents-capabilities-today-and-next/index.html) \ \ Where AI Actually Fits in Your SOC Workflow (and Where It Creates More Problems)\ \ Michelle\ \ Dufty](/content/blog/ai-soc-workflow-benefits-risks/index.html) \ \ Will AI Replace SOC Analysts? The Honest Answer Is More Complicated\ \ Michelle\ \ Dufty](/content/blog/will-ai-replace-soc-analysts/index.html) \ \ AI SOC Analysts: What They Actually Do (and Where They Still Need Humans)\ \ Michelle\ \ Dufty](/content/blog/ai-soc-analysts-capabilities/index.html) \ \ What Are Query Languages? Definition, Examples, & Uses\ \ Michelle\ \ Dufty](/content/blog/what-are-query-languages/index.html) \ \ What Is Centralized Logging? Benefits, Architecture, and Best Practices\ \ Michelle\ \ Dufty](/content/blog/what-is-centralized-logging/index.html) \ \ What Is an Incident Response Retainer? Benefits, Costs, and When You Need One\ \ Michelle\ \ Dufty](/content/blog/incident-response-retainer/index.html) \ \ What Is QBot Malware? Detection and Removal Guide\ \ Michelle\ \ Dufty](/content/blog/qbot-malware-detection/index.html) \ \ What Is Credential Stuffing? How It Works and How to Prevent It\ \ Michelle\ \ Dufty](/content/blog/what-is-credential-stuffing/index.html) \ \ Product\ \ Investigating Alerts Without Switching Tools\ \ Katie\ \ Campisi](/content/blog/investigating-alerts-without-switching-tools/index.html) \ \ Threat Research\ \ Inside DPRK’s npm malware factory: 108 packages, 261 versions, and a 31-day campaign wave\ \ Michael\ \ Baker](/content/blog/inside-dprk%E2%80%99s-npm-malware-factory-108-packages-261-versions-and-a-31-day-campaign-wave/index.html) \ \ What Is SIEM as a Service? Benefits and Pricing\ \ Michelle\ \ Dufty](/content/blog/siem-as-a-service/index.html) \ \ What Is Security Analytics? Benefits, Tools, & Use Cases\ \ Michelle\ \ Dufty](/content/blog/what-is-security-analytics/index.html) \ \ What Is Managed SIEM? Benefits, Costs, and How to Choose\ \ Michelle\ \ Dufty](/content/blog/what-is-managed-siem/index.html) \ \ Top SIEM Use Cases: Security Monitoring, Compliance, and More\ \ Michelle\ \ Dufty](/content/blog/siem-use-cases/index.html) \ \ What Is a Data Warehouse vs Data Lake vs Data Lakehouse? Key Differences\ \ Michelle\ \ Dufty](/content/blog/data-warehouse-vs-data-lake-vs-data-lakehouse/index.html) \ \ Data Lake Architecture: Components, Design, and Best Practices\ \ Michelle\ \ Dufty](/content/blog/data-lake-architecture-components/index.html) \ \ Top 5 Data Lake Solutions: Features, Pricing and Comparison\ \ Michelle\ \ Dufty](/content/blog/data-lake-solutions/index.html) \ \ What is Log Aggregation and How Does It Work? A Complete Guide\ \ Michelle\ \ Dufty](/content/blog/what-is-log-aggregation/index.html) \ \ What Are Security Logs? Types, Examples, and Analysis\ \ Michelle\ \ Dufty](/content/blog/what-are-security-logs/index.html) \ \ SIEM vs EDR: Critical Differences & Similarities\ \ Michelle\ \ Dufty](/content/blog/siem-vs-edr/index.html) \ \ How to Create an Incident Response Plan: Steps and Template\ \ Michelle\ \ Dufty](/content/blog/incident-response-plan/index.html) \ \ What Is Detection Engineering? A Practitioner's Guide\ \ Michelle\ \ Dufty](/content/blog/what-is-detection-engineering/index.html) \ \ What is Infrastructure as Code (IaC) Security? How it Works & Best Practices\ \ Michelle\ \ Dufty](/content/blog/iac-security/index.html) \ \ What Is a Host-Based Intrusion Detection System (HIDS)?\ \ Michelle\ \ Dufty](/content/blog/host-based-intrusion-detection-system-hids/index.html) \ \ What Is the Cyber Kill Chain? Strategies and How to Use It Effectively\ \ Michelle\ \ Dufty](/content/blog/cyber-kill-chain/index.html) \ \ What Is Cyber Threat Hunting? A Practitioner's Guide to Proactive Threat Detection\ \ Michelle\ \ Dufty](/content/blog/cyber-threat-hunting/index.html) \ \ Shai-Hulud npm Supply Chain Attack: What You Need to Know\ \ Michelle\ \ Dufty](/content/blog/shai-hulud-npm-supply-chain-attack/index.html) \ \ How to Detect Compromised Credentials: Signs and Response Steps\ \ Michelle\ \ Dufty](/content/blog/detect-compromised-credentials/index.html) \ \ What Is Threat and Vulnerability Management? A 2026 Guide\ \ Michelle\ \ Dufty](/content/blog/threat-and-vulnerability-management-guide/index.html) \ \ Automating Security Operations With AI: Where to Start When Everything Feels Manual\ \ Michelle\ \ Dufty](/content/blog/automating-security-operations-with-ai/index.html) \ \ AI Agents in Security Operations: What's Real, What's Hype, and What's Next\ \ Michelle\ \ Dufty](/content/blog/ai-agents-security-operations-real-vs-hype/index.html) \ \ Who's Leading AI-Powered SOC Automation? A Practitioner's Market Map\ \ Michelle\ \ Dufty](/content/blog/ai-soc-automation-market-map/index.html) \ \ Agentic AI Security Platforms: What to Expect and How to Evaluate Them\ \ Michelle\ \ Dufty](/content/blog/agentic-ai-security-platforms-guide/index.html) \ \ Is AI SOC Automation Worth It? An Honest Look at the Costs, Gains, and Gotchas\ \ Michelle\ \ Dufty](/content/blog/ai-soc-automation-costs-gains-gotchas/index.html) \ \ How to Build an AI-Enabled SOC: Lessons From Teams That Did It Without Ripping and Replacing\ \ Michelle\ \ Dufty](/content/blog/how-to-build-ai-soc/index.html) \ \ Everything as Code: Bringing Software Engineering Discipline to Security Operations\ \ Michelle\ \ Dufty](/content/blog/everything-as-code/index.html) \ \ Threat Research\ \ Sober Up! npm Typosquat Delivers Winos4.0 Implant via Multi-Stage PowerShell Dropper\ \ Alessandra\ \ Rizzo](/content/blog/sober-up-npm-typosquat-delivers-winos4.0-implant-via-multi-stage-powershell-dropper/index.html) \ \ Threat Research\ \ Mapping the Infrastructure Behind the kube-health-tools Supply Chain Malware\ \ Alessandra\ \ Rizzo](/content/blog/mapping-the-infrastructure-behind-the-kube-health-tools-supply-chain-malware/index.html) \ \ Threat Research\ \ Enrichment Baselines: A Statistical Framework for Threat Detection\ \ Zaynah \ \ Smith-DaSilva](/content/blog/enrichment-baselines-a-statistical-framework-for-threat-detection/index.html) \ \ Threat Research\ \ False Claims: An npm Supply Chain Campaign Impersonates Known US Insurance Provider\ \ Alessandra\ \ Rizzo](/content/blog/false-claims-an-npm-supply-chain-campaign-impersonates-insurance-provider/index.html) \ \ Threat Research\ \ Tracking an OtterCookie Infostealer Campaign Across npm\ \ Alessandra\ \ Rizzo](/content/blog/tracking-an-ottercookie-infostealer-campaign-across-npm/index.html) \ \ Threat Research\ \ Polymarket Trader Funds at Risk: DPRK npm Package Steals Wallet Keys and Installs SSH Backdoor\ \ Michael\ \ Baker](/content/blog/polymarket-trader-funds-at-risk-dprk-npm-package-steals-wallet-keys/index.html) \ \ Threat Research\ \ jsonspack: Multi-Tenant Node.js RAT — DPRK Supply Chain Campaign\ \ Michael \ \ Baker](/content/blog/jsonspack-multi-tenant-node.js-rat-%E2%80%94-dprk-supply-chain-campaign/index.html) \ \ Threat Research\ \ Tunnel Vision: Supply Chain Attack Targets Kubernetes via npm and PyPI\ \ Alessandra\ \ Rizzo](/content/blog/tunnel-vision-supply-chain-attack-targets-kubernetes-via-npm-and-pypi/index.html) \ \ Threat Research\ \ Introducing Unique Value Thresholds\ \ Ariel\ \ Ropek](/content/blog/introducing-unique-value-thresholds/index.html) \ \ Product\ \ AI-Powered Alert Triage\ \ Katie\ \ Campisi](/content/blog/ai-powered-alert-triage/index.html) \ \ Thought Leadership\ \ Defining the AI SOC Platform\ \ Jack\ \ Naglieri](/content/blog/defining-the-ai-soc-platform/index.html) \ \ Agentic AI Architecture: Components and Design Patterns for Security Teams\ \ Michelle\ \ Dufty](/content/blog/agentic-ai-architecture-security-teams/index.html) \ \ Building an AI-Powered SOC: Architecture, Trade-offs, and What to Prioritize\ \ Michelle\ \ Dufty](/content/blog/ai-powered-soc/index.html) \ \ How to Integrate AI Into Your SOC Without Disrupting Existing Workflows\ \ Michelle\ \ Dufty](/content/blog/ai-security-operations/index.html) \ \ Agentic AI in Cybersecurity: What It Actually Does (and Doesn't Do)\ \ Michelle\ \ Dufty](/content/blog/agentic-ai-cybersecurity/index.html) \ \ MCP Tools for Security Teams: Using the MCP Ecosystem to Orchestrate AI SOC Agents\ \ Michelle\ \ Dufty](/content/blog/mcp-tools/index.html) \ \ What Is LLM Security? Risks, Vulnerabilities, and Best Practices\ \ Michelle\ \ Dufty](/content/blog/llm-security/index.html) \ \ Product\ \ The Complete AI SOC: What We Built and Why\ \ Jack\ \ Naglieri](/content/blog/the-complete-ai-soc-what-we-built-and-why/index.html) \ \ Threat Research\ \ Detecting and Hunting for Cloud Ransomware Part 3: Azure Storage\ \ Alessandra\ \ Rizzo](/content/blog/detecting-and-hunting-for-cloud-ransomware-part-3-azure-storage/index.html) \ \ Managed Detection and Response (MDR): How It Works, Key Components, and When You Need It\ \ Michelle\ \ Dufty](/content/blog/managed-detection-response/index.html) \ \ Intrusion Detection Systems: How They Work, Types, and Where Cloud-Native Detection Fits\ \ Michelle\ \ Dufty](/content/blog/intrusion-detection-systems/index.html) \ \ Threat Research\ \ Phantom Menace: The Ghost Loader Infostealer Campaign\ \ Alessandra\ \ Rizzo](/content/blog/phantom-menace-the-ghost-loader-infostealer-campaign/index.html) \ \ Threat Research\ \ Catching Salesforce Integration Breaches with Panther\ \ Zaynah\ \ Smith-DaSilva](/content/blog/catching-salesforce-integration-breaches-with-panther/index.html) \ \ Top Splunk Alternatives (2026): Features, Pricing, and Comparison\ \ Michelle\ \ Dufty](/content/blog/splunk-alternatives/index.html) \ \ Top AIOps Use Cases for Security Operations\ \ Michelle\ \ Dufty](/content/blog/aiops-use-cases/index.html) \ \ What Is AI SIEM? Features, Benefits, and Use Cases\ \ Michelle\ \ Dufty](/content/blog/ai-siem/index.html) \ \ SIEM vs. SOAR: Key Differences\ \ Michelle\ \ Dufty](/content/blog/siem-vs-soar/index.html) \ \ Threat Research\ \ Part Two: LLM Threats and Defensive Strategies\ \ Zaynah\ \ Smith-DaSilva](/content/blog/part-two-llm-threats-and-defensive-strategies/index.html) \ \ What is Alert Fatigue? And How to Reduce it in Your SOC\ \ Michelle\ \ Dufty](/content/blog/what-is-alert-fatigue/index.html) \ \ What Is Security Automation? Benefits, Tools, and Best Practices\ \ Michelle\ \ Dufty](/content/blog/security-automation/index.html) \ \ What Is AI Threat Intelligence? How AI Enhances Threat Detection\ \ Michelle\ \ Dufty](/content/blog/ai-threat-intelligence/index.html) \ \ Threat Research\ \ Part One: LLM Threats and Defensive Strategies\ \ Zaynah\ \ Smith-DaSilva](/content/blog/llm-threats-and-defensive-strategies-part-one/index.html) \ \ Detection & Response\ \ How to Build SOC Teams in 2026: A Step-by-Step Guide\ \ Dufty](/content/blog/how-to-build-soc-teams/index.html) \ \ Product\ \ Panther v1.118 Focuses on Removing Friction from Security Operations\ \ Katie\ \ Campisi](/content/blog/panther-v1.118-focuses-on-removing-friction-from-security-operations/index.html) \ \ Threat Research\ \ No Fool's Errand: The Koalemos RAT Campaign\ \ Alessandra\ \ Rizzo](/content/blog/no-fool-s-errand-the-koalemos-rat-campaign/index.html) \ \ Threat Research\ \ Building a Supply Chain Scanner for Fun and Profit\ \ Ariel\ \ Ropek](/content/blog/building-a-supply-chain-scanner-for-fun-and-profit/index.html) \ \ Threat Research\ \ Detecting and Hunting for Cloud Ransomware Part 2: GCP GCS\ \ Alessandra\ \ Rizzo](/content/blog/detecting-and-hunting-for-cloud-ransomware-part-2-gcp-gcs/index.html) \ \ Threat Research\ \ Introducing a Safer, Smarter Way to Launch Detections\ \ Panther Threat Research Team](/content/blog/introducing-a-safer-smarter-way-to-launch-detections/index.html) \ \ Panther + Expel: Bringing AI-Powered SIEM and MDR Together\ \ Katie\ \ Campisi](/content/blog/panther-expel-bringing-ai-powered-siem-and-mdr-together/index.html) \ \ Product\ \ AI in the SOC – Only as Good as the Data You Give It!\ \ Katie\ \ Campisi](/content/blog/ai-in-the-soc-%E2%80%93-only-as-good-as-the-data-you-give-it/index.html) \ \ Threat Research\ \ Detecting and Hunting for Cloud Ransomware Part 1: AWS S3\ \ Alessandra \ \ Rizzo](/content/blog/detecting-and-hunting-for-cloud-ransomware-part-1-aws-s3/index.html) \ \ Threat Research\ \ Elf on a (npm) Shelf\ \ Panther Threat Research Team](/content/blog/elf-on-a-(npm/index.html)-shelf) \ \ Compliance\ \ How to Automate Continuous SOC 2 Monitoring in Cloud Environments\ \ Katie\ \ Campisi](/content/blog/automate-soc2-cloud-monitoring/index.html) \ \ Threat Research\ \ A Data-Driven Analysis of the Sha1-Hulud 2.0 Campaign\ \ Panther Threat Research Team](/content/blog/a-data-driven-analysis-of-the-sha1-hulud-2-0-campaign/index.html) \ \ Threat Research\ \ Detecting and Hunting for GitHub Actions Compromise\ \ Alessandra \ \ Rizzo](/content/blog/detecting-and-hunting-for-github-actions-compromise/index.html) \ \ Threat Research\ \ My Top 4 Takeaways from MITRE ATT&CKcon 6.0\ \ Ariel\ \ Ropek](/content/blog/my-top-4-takeaways-from-mitre-att-ckcon-6-0/index.html) \ \ Company Culture\ \ Doubling Down on Data: Why We're Acquiring Datable\ \ William\ \ Lowe](/content/blog/doubling-down-on-data-why-we-re-acquiring-datable/index.html) \ \ Thought Leadership\ \ Beyond SIEM: Francis Odum Highlights the Shift to Data-Driven Security\ \ Katie\ \ Campisi](/content/blog/beyond-siem-francis-odum-highlights-the-shift-to-data-driven-security/index.html) \ \ Press Release\ \ Panther Achieves the AWS Generative AI Competency\ \ Panther](/content/blog/panther-achieves-the-aws-generative-ai-competency/index.html) \ \ Product\ \ Smarter AI Workflows, Broader Coverage: What’s New in Panther v1.115\ \ Katie\ \ Campisi](/content/blog/smarter-ai-workflows-broader-coverage-what-s-new-in-panther-v1-115/index.html) \ \ Product\ \ Panther x Databricks Private Preview: AI SOC Platform on Your Security Lakehouse\ \ William\ \ Lowe](/content/blog/panther-x-databricks-private-preview-ai-soc-platform-on-your-security-lakehouse/index.html) \ \ Splunk to Panther: A Migration That Transforms Your Security Operations\ \ Mike\ \ Olsen](/content/blog/splunk-to-panther-a-migration-that-transforms-your-security-operations/index.html) \ \ Threat Research\ \ NX Threat Analysis\ \ Ariel\ \ Ropek](/content/blog/nx-threat-analysis/index.html) \ \ Thought Leadership\ \ Join the SIEM Revolution: AI-Ready Security That Scales\ \ William\ \ Lowe](/content/blog/join-the-siem-revolution-ai-ready-security-that-scales/index.html) \ \ Product\ \ New Panther Features Solving Real-World Problems in v1.114\ \ Katie\ \ Campisi](/content/blog/new-panther-features-solving-real-world-problems-in-v1-114/index.html) \ \ Detection & Response\ \ 10x Your Detection Engineering Workflows with MCP\ \ Jack\ \ Naglieri](/content/blog/10-your-detection-engineering-workflows-with-mcp/index.html) \ \ Company Culture\ \ Betting on Panther, Twice\ \ Michael\ \ Baker](/content/blog/betting-on-panther-twice/index.html) \ \ Detection & Response\ \ How Model Context Protocol Helps Security Teams Scale SecOps\ \ Jack\ \ Naglieri](/content/blog/how-model-context-protocol-helps-security-teams-scale-secops/index.html) \ \ Customer Stories\ \ Infoblox Tunes Detections 70% Faster with Panther AI\ \ Katie\ \ Campisi](/content/blog/infoblox-tunes-detections-70-faster-with-panther-ai/index.html) \ \ Product\ \ Panther AI: Transforming Alert Triage and Resolution\ \ Jack\ \ Naglieri](/content/blog/panther-ai-transforming-alert-triage-and-resolution/index.html) \ \ Customer Stories\ \ Cresta Accelerates SecOps with Panther AI, Powered by AWS & Claude\ \ Katie\ \ Campisi](/content/blog/cresta-accelerates-secops-with-panther-ai-powered-by-aws-claude/index.html) \ \ Product\ \ Panther Launches AI-Powered Security Operations\ \ Jack\ \ Naglieri](/content/blog/panther-launches-ai-powered-security-operations/index.html) \ \ Cloud Security\ \ Panther + Snowflake: Security Monitoring with Streaming Analysis for Your Enterprise Data\ \ Jack\ \ Naglieri](/content/blog/panther-snowflake-security-monitoring-with-streaming-analysis-for-your-enterprise-data/index.html) \ \ Cloud Security\ \ Centralize and Correlate Critical Security Data with Panther and Zscaler\ \ Remy\ \ Kullberg](/content/blog/centralize-and-correlate-critical-security-data-with-panther-and-zscaler/index.html) \ \ Cloud Security\ \ Panther + Wiz: Empowering SecOps Teams with Unified Context\ \ Jack\ \ Naglieri](/content/blog/panther-wiz-empowering-secops-teams-with-unified-context/index.html) \ \ Detection & Response\ \ Sigma Rules: Your Guide to Threat Detection’s Open Standard\ \ Panther Labs](/content/blog/your-guide-to-the-sigma-rules-open-standard-for-threat-detection/index.html) \ \ Data Engineering\ \ Introducing PantherFlow: Accelerate Investigations in Your Security Data Lake\ \ Bryan\ \ Peace](/content/blog/introducing-pantherflow/index.html) \ \ Detection & Response\ \ Investigating Amazon EKS Privilege Escalation with PantherFlow\ \ Panther Labs](/content/blog/investigating-amazon-eks-privilege-escalation-with-pantherflow/index.html) \ \ Cloud Security\ \ Panther Debuts as Wiz Defend Launch Partner\ \ Bryan\ \ Peace](/content/blog/panther-debuts-as-wiz-defend-launch-partner/index.html) \ \ Data Engineering\ \ How to Write Queries in PantherFlow, a Piped Search Language\ \ Doug\ \ Miller](/content/blog/how-to-write-queries-in-pantherflow-a-piped-search-language/index.html) \ \ Data Engineering\ \ Why PantherFlow: How Our Piped Query Language Simplifies Search\ \ Doug\ \ Miller](/content/blog/why-pantherflow-how-our-piped-query-language-simplifies-search/index.html) \ \ Thought Leadership\ \ How to Know You're Ready for a Dedicated Detections Team\ \ Remy\ \ Kullberg](/content/blog/how-to-know-youre-ready-for-a-dedicated-detections-team/index.html) \ \ Data Engineering\ \ Python for Cybersecurity: Key Use Cases and Tools\ \ Remy\ \ Kullberg](/content/blog/python-for-cybersecurity-key-use-cases-and-tools/index.html) \ \ Data Engineering\ \ Introducing pypanther: The Future of Code-Driven Detection and Response\ \ Jack\ \ Naglieri](/content/blog/introducing-pypanther-the-future-of-code-driven-detection-and-response/index.html) \ \ Company Culture\ \ Turn Up the Volume, Turn Down the Noise with Code-Driven Correlations at Black Hat 2024\ \ Panther Labs](/content/blog/turn-up-the-volume-turn-down-the-noise-with-code-driven-correlations-at-black-hat-2024/index.html) \ \ Detection & Response\ \ Securing Zoom: How to Detect and Mitigate Threats in Remote Collaboration Tools\ \ Remy\ \ Kullberg](/content/blog/securing-zoom-how-to-detect-and-mitigate-threats-in-remote-collaboration-tools/index.html) \ \ Data Engineering\ \ 5 Reasons Your Pipeline Is Broken‚ And How to Fix It\ \ Bryan\ \ Peace](/content/blog/5-reasons-your-pipeline-is-broken-and-how-to-fix-it/index.html) \ \ Detection & Response\ \ Enhanced Identity Attack Detection with Push Security\ \ Bryan\ \ Peace](/content/blog/enhanced-identity-attack-detection-with-push-security/index.html) \ \ Data Engineering\ \ How to Turn Security Pipelines Into Gold Mines\ \ Bryan\ \ Peace](/content/blog/how-to-turn-security-pipelines-into-gold-mines/index.html) \ \ Detection & Response\ \ Regarding the Recent Campaign Targeting Snowflake Customers\ \ Panther Labs](/content/blog/regarding-the-recent-campaign-targeting-snowflake-customers/index.html) \ \ Data Engineering\ \ Make Your SecOps Pipe Dreams a Reality\ \ Bryan\ \ Peace](/content/blog/make-your-secops-pipe-dreams-a-reality/index.html) \ \ Cloud Security\ \ Why You Should Be Ingesting AWS VPC Flow Logs\ \ Remy\ \ Kullberg](/content/blog/why-you-should-be-ingesting-aws-vpc-flow-logs/index.html) \ \ Detection & Response\ \ Drowning in False Positives? Your Detections Probably Suck\ \ Katie\ \ Campisi](/content/blog/drowning-in-false-positives-your-detections-probably-suck/index.html) \ \ Detection & Response\ \ Introducing Panther’s Newest Alert Destination: Torq\ \ Panther Labs](/content/blog/introducing-panthers-newest-alert-destination-torq/index.html) \ \ Thought Leadership\ \ Restoring Clarity in a Broken System\ \ Matt\ \ Jezorek](/content/blog/restoring-clarity-broken-system/index.html) \ \ Data Engineering\ \ Panther Users Can Now Seamlessly Leverage Powerful Observo.ai Data Pipeline Features\ \ Panther Labs](/content/blog/panther-users-can-now-seamlessly-leverage-powerful-observo-ai-data-pipeline-features/index.html) \ \ Company Culture\ \ Stop Creating Dumb Alerts: See Our New AI and Correlation Rules at RSA\ \ Panther Labs](/content/blog/stop-creating-dumb-alerts-see-our-new-ai-and-correlation-rules-at-rsa/index.html) \ \ Company Culture\ \ Meet Matt Jezorek: One of Panther’s Earliest Champions\ \ William\ \ Lowe](/content/blog/meet-matt-jezorek-panther-s-new-vp-of-product-and-security/index.html) \ \ Cloud Security\ \ Why You Should Be Ingesting AWS GuardDuty Logs\ \ Remy\ \ Kullberg](/content/blog/why-you-should-be-ingesting-aws-guardduty-logs/index.html) \ \ Cloud Security\ \ Panther Now Integrates with Amazon Security Lake: Embracing the Open Cybersecurity Schema Framework (OCSF)\ \ Panther Labs](/content/blog/panther-now-integrates-with-aws-security-lake-embracing-the-open-cybersecurity-schema-framework-ocsf/index.html) \ \ Customer Stories\ \ Learn it Firsthand: How Zapier Uses Detection-as-Code to Increase Their Alert Fidelity\ \ Panther Labs](/content/blog/learn-it-firsthand-how-zapier-uses-detection-as-code-to-increase-their-alert-fidelity/index.html) \ \ Cloud Security\ \ Why You Should Be Ingesting AWS CloudTrail Logs\ \ Remy\ \ Kullberg](/content/blog/why-you-should-be-ingesting-aws-cloudtrail-logs/index.html) \ \ Threat Research\ \ What You Need to Know About the Latest GitLab Vulnerability (Including Detection)\ \ Ariel\ \ Ropek](/content/blog/what-you-need-to-know-about-the-latest-gitlab-vulnerability-including-detection/index.html) \ \ Detection & Response\ \ Identifying and Mitigating False Positive Alerts\ \ Remy\ \ Kullberg](/content/blog/identifying-and-mitigating-false-positive-alerts/index.html) \ \ Thought Leadership\ \ Is Your SIEM a Hotel California?\ \ Ken\ \ Westin](/content/blog/is-your-siem-a-hotel-california/index.html) \ \ Detection & Response\ \ Unraveling SIEM Correlation Techniques\ \ Jack\ \ Naglieri](/content/blog/unraveling-siem-correlation-techniques/index.html) \ \ Detection & Response\ \ CVE-2024-3094 - Linux Supply Chain Compromise Affecting XZ Utils Data Compression Library\ \ Ken\ \ Westin](/content/blog/cve-2024-3094-linux-supply-chain-compromise-affecting-xz-utils-data-compression-library/index.html) \ \ Threat Research\ \ Critical Steps To Detect and Prevent Cryptojacking In Your Cloud Infrastructure\ \ Ariel\ \ Ropek](/content/blog/critical-steps-to-detect-and-prevent-cryptojacking-in-your-cloud-infrastructure/index.html) \ \ Compliance\ \ How North Korean Cybercrime Aids the Russian Military and Circumvents Sanctions\ \ Ken\ \ Westin](/content/blog/how-north-korean-cybercrime-aids-the-russian-military-and-circumvents-sanctions/index.html) \ \ Detection & Response\ \ Mitigating the Midnight Blizzard Threat\ \ Ken\ \ Westin](/content/blog/mitigating-the-midnight-blizzard-threat/index.html) \ \ Threat Research\ \ The Scattered Spider Attack: Safeguarding Your Okta Infrastructure\ \ Ariel\ \ Ropek](/content/blog/the-scattered-spider-attack-safeguarding-your-okta-infrastructure/index.html) \ \ Thought Leadership\ \ Mastering Alert Fatigue: Best Practices for Centralized Management\ \ Remy\ \ Kullberg](/content/blog/mastering-alert-fatigue-best-practices-for-centralized-management/index.html) \ \ Cloud Security\ \ Securing the Cloud with Panther: Providing Multi Cloud Support Across AWS, GCP, and Azure\ \ Carrie\ \ Pascale](/content/blog/securing-the-cloud-with-panther-providing-multi-cloud-support-across-aws-gcp-and-azure/index.html) \ \ Company Culture\ \ From Vision to Reality: Panther‚s New Identity\ \ Panther Labs](/content/blog/from-vision-to-reality-panthers-new-identity/index.html) \ \ Detection & Response\ \ Harnessing the Power of Data Lake Search and DaC for Crypto Mining Malware Detection and Investigation\ \ Panther Labs](/content/blog/harnessing-the-power-of-data-lake-search-and-dac-for-crypto-mining-malware-detection-and-investigation/index.html) \ \ Thought Leadership\ \ Why Proactive Threat Monitoring is Crucial: Unveiling the Invisible Risks\ \ Panther Labs](/content/blog/why-proactive-threat-monitoring-is-crucial-unveiling-the-invisible-risks/index.html) \ \ Company Culture\ \ Built In Recognizes Panther as Top Workplace in Industry!\ \ Pamela\ \ Golden](/content/blog/built-in-recognizes-panther-as-top-workplace-in-industry/index.html) \ \ Data Engineering\ \ Introducing the Panther Sigma Rule Converter\ \ Panther Labs](/content/blog/introducing-the-panther-sigma-rule-converter/index.html) \ \ Thought Leadership\ \ How to Evaluate a Security Detection Platform\ \ Panther Labs](/content/blog/how-to-evaluate-a-security-detection-platform/index.html) \ \ Detection & Response\ \ How to Create a Code-Based Detection\ \ Remy\ \ Kullberg](/content/blog/how-to-create-a-code-based-detection/index.html) \ \ Detection & Response\ \ How Detection-as-Code Revolutionizes Security Posture\ \ Remy\ \ Kullberg](/content/blog/how-detection-as-code-revolutionizes-security-posture/index.html) \ \ Product\ \ Panther Announces Splunk Alert Destination Integration\ \ Ken\ \ Westin](/content/blog/panther-announces-splunk-alert-destination-integration/index.html) \ \ Product\ \ Introducing Panther‚s Security Data Lake Search\ \ Panther Labs](/content/blog/introducing-panthers-security-data-lake-search/index.html) \ \ Thought Leadership\ \ Shifting from Reactive to Proactive Cybersecurity Postures\ \ Panther Labs](/content/blog/shifting-from-reactive-to-proactive-cybersecurity-postures/index.html) \ \ Compliance\ \ Silver Surfers: Guarding Seniors in the Digital Wave of Cybersecurity\ \ Ashley\ \ Yvonne](/content/blog/silver-surfers-guarding-seniors-in-the-digital-wave-of-cybersecurity/index.html) \ \ Company Culture\ \ SOCtober Spook Fest: Watch All 3 Stories\ \ Panther Labs](/content/blog/soctober-spook-fest-watch-all-3-stories/index.html) \ \ Product\ \ Collaborate with Confidence: Monitor Notion Audit Logs with Panther\ \ Panther Labs](/content/blog/collaborate-with-confidence-monitor-notion-audit-logs-with-panther/index.html) \ \ Product\ \ User Experience, the Unseen Hero in Security Products\ \ Panther Labs](/content/blog/user-experience-the-unseen-hero-in-security-products/index.html) \ \ Cloud Security\ \ The Great Cloud-Native Fib: Unmasking a Core SIEM Deception\ \ Panther Labs](/content/blog/the-great-cloud-native-fib-unmasking-a-core-siem-deception/index.html) \ \ Cloud Security\ \ Shifting SIEM Left: Securing the Software Supply Chain with GitHub Monitoring\ \ Ken\ \ Westin](/content/blog/shifting-siem-left-securing-the-software-supply-chain-with-github-monitoring/index.html) \ \ Detection & Response\ \ A Quick and Easy Guide to Detection and Query Tuning\ \ Andrea\ \ Youwakim](/content/blog/a-quick-and-easy-guide-to-detection-and-query-tuning/index.html) \ \ Data Engineering\ \ Panther Users Can Now Manage S3 Log Sources with Terraform\ \ Dan\ \ Biwer](/content/blog/manage-s3-log-sources-with-terraform/index.html) \ \ Product\ \ Monitoring Tailscale Network & Audit Logs with Panther\ \ Grant\ \ Joy](/content/blog/tailscale-log-integration/index.html) \ \ Customer Stories\ \ How FloQast Transforms Security Ops with Detection-as-Code\ \ Panther Labs](/content/blog/how-floqast-transforms-security-ops-with-detection-as-code/index.html) \ \ Detection & Response\ \ Accelerating Investigation with Panther\ \ Ted\ \ Kietzman](/content/blog/accelerating-investigation-with-panther/index.html) \ \ Cloud Security\ \ How Panther Ensures Resilience During Cloud Outages\ \ Mark\ \ Stumpf](/content/blog/how-panther-ensures-resilience-during-cloud-outages/index.html) \ \ Detection & Response\ \ Nation-State Actors Targeting Software Supply Chain via GitHub\ \ Ken\ \ Westin](/content/blog/nation-state-actors-targeting-software-supply-chain-via-github/index.html) \ \ Compliance\ \ Hey Microsoft, Security Logs Want to be Free!\ \ Ken\ \ Westin](/content/blog/hey-microsoft-security-logs-want-to-be-free/index.html) \ \ Data Engineering\ \ Using AWS Secrets Manager with Panther Detections\ \ Carrie\ \ Pascale](/content/blog/using-aws-secrets-manager-with-panther-detections/index.html) \ \ Detection & Response\ \ The Power of Detection-as-Code, For Everyone\ \ Valerie\ \ Pitsch](/content/blog/the-power-of-detection-as-code-for-everyone/index.html) \ \ Customer Stories\ \ How Workrise Implemented Panther To Achieve Full Visibility\ \ Panther Labs](/content/blog/how-workrise-implemented-panther-to-achieve-full-visibility/index.html) \ \ Company Culture\ \ Panther Recognized as Fortune Best Places to Work in the Bay Area\ \ Pamela\ \ Golden](/content/blog/fostering-panther-pride-our-journey-to-being-recognized-as-one-of-fortunes-best-workplaces/index.html) \ \ Product\ \ Realize SIEM Value from Day One\ \ Ted\ \ Kietzman](/content/blog/realize-siem-value-from-day-one/index.html) \ \ Compliance\ \ How Panther Helps With SOC 2\ \ Austin\ \ Hirsch](/content/blog/how-panther-helps-with-soc-2/index.html) \ \ Detection & Response\ \ Building a Detection & Response Team in a Cloud First Environment\ \ Zeeshan\ \ Khadim](/content/blog/building-a-detection-response-team-in-a-cloud-first-environment/index.html) \ \ Cloud Security\ \ The Darksaber of Modern SIEM Tools in a Galaxy Far, Far Away\ \ Panther Labs](/content/blog/the-darksaber-of-modern-siem-tools-in-a-galaxy-far-far-away/index.html) \ \ Data Engineering\ \ Best practices for running faster SQL queries\ \ Lisa\ \ Meed](/content/blog/best-practices-for-faster-sql-queries/index.html) \ \ Detection & Response\ \ Discovering Exfiltrated Credentials\ \ Ed\ \ Anderson](/content/blog/discovering-exfiltrated-credentials/index.html) \ \ Detection & Response\ \ Analyzing Lateral Movement in Google Cloud Platform\ \ Brandon\ \ Min](/content/blog/analyzing-lateral-movement-in-google-cloud-platform/index.html) \ \ Detection & Response\ \ Maximizing Endpoint Security with SentinelOne and Panther\ \ Brandon\ \ Min](/content/blog/maximizing-endpoint-security-with-sentinelone-and-panther/index.html) \ \ Detection & Response\ \ Method to the Madness: Developing a Detection Engineering Methodology\ \ Ken\ \ Westin](/content/blog/method-to-the-madness-developing-a-detection-engineering-methodology/index.html) \ \ Detection & Response\ \ Faster Triaging with Slack Bot Boomerangs\ \ Ted\ \ Kietzman](/content/blog/faster-triaging-with-slack-bot-boomerangs/index.html) \ \ Detection & Response\ \ Writing Your First Python Detection in 30 Minutes with Okta and Panther\ \ Ken\ \ Westin](/content/blog/writing-your-first-python-detection-in-30-minutes-with-okta-and-panther/index.html) \ \ Detection & Response\ \ Top 5 AWS Services to Protect with CloudTrail\ \ Brandon\ \ Min](/content/blog/top-5-aws-services-to-protect-with-cloudtrail/index.html) \ \ Detection & Response\ \ Zero False Positives from your SIEM\ \ Jack\ \ Naglieri](/content/blog/zero-false-positives-from-your-siem/index.html) \ \ Detection & Response\ \ Threat Hunting in AWS\ \ Calvin\ \ Kim](/content/blog/threat-hunting-in-aws/index.html) \ \ Detection & Response\ \ Accelerate Response with the Panther Slack Bot\ \ Ted\ \ Kietzman](/content/blog/accelerate-response-with-the-panther-slackbot/index.html) \ \ Cloud Security\ \ Optimize CloudTrail Ingestion with Modern SIEM\ \ Brandon\ \ Min](/content/blog/optimize-cloudtrail-ingestion-with-modern-siem/index.html) \ \ Thought Leadership\ \ 5 Things You Need to Know About the State of SIEM in 2022\ \ Panther Labs](/content/blog/5-things-you-need-to-know-about-the-state-of-siem-in-2022/index.html) \ \ Thought Leadership\ \ State of SIEM 2022: 5 Key Takeaways\ \ Panther Labs](/content/blog/state-of-siem-2022-5-key-takeaways/index.html) \ \ Cloud Security\ \ Get Started: AWS and Panther\ \ Brandon\ \ Min](/content/blog/get-started-aws-and-panther/index.html) \ \ Cloud Security\ \ Protect Azure Services with Microsoft Graph API\ \ Brandon\ \ Min](/content/blog/protect-azure-services-with-microsoft-graph-api/index.html) \ \ Customer Stories\ \ How Booz Allen Hamilton uses Detection-as-Code to Transform Security in the Federal Government\ \ Mike\ \ Saxton](/content/blog/how-booz-allen-hamilton-uses-detection-as-code/index.html) \ \ Thought Leadership\ \ Going Phishless: How Panther Deployed WebAuthN with Okta & YubiKeys\ \ Panther Labs](/content/blog/going-phishless-how-panther-deployed-webauthn/index.html) \ \ Company Culture\ \ 13 Questions with Founder and CEO Jack Naglieri in the Panther Community\ \ Matt\ \ Korovesis](/content/blog/13-questions-with-founder-and-ceo-jack-naglieri/index.html) \ \ Detection & Response\ \ Adopting Real-Time Threat Detection Workflows\ \ Brandon\ \ Min](/content/blog/adopting-real-time-threat-detection/index.html) \ \ Thought Leadership\ \ Five Lessons From Detection & Response Leaders\ \ Jack\ \ Naglieri](/content/blog/five-lessons-from-detection-response-leaders/index.html) \ \ Detection & Response\ \ The Benefits of Using Python to Write SIEM Detections\ \ Brandon\ \ Min](/content/blog/using-python-to-write-siem-detections/index.html) \ \ Company Culture\ \ Join Panther’s Founder and CEO Jack Naglieri for a Community AMA!\ \ Matt\ \ Korovesis](/content/blog/join-panthers-founder-and-ceo-jack-naglieri-for-a-community-ama/index.html) \ \ Detection & Response\ \ Rapid Detection and Response with Panther & Tines\ \ Mark\ \ Stone](/content/blog/rapid-detection-and-response-with-panther-tines/index.html) \ \ Detection & Response\ \ Modernize detection engineering with Detection-as-Code\ \ Kyle\ \ Bailey](/content/blog/modernize-detection-engineering-with-detection-as-code/index.html) \ \ Cloud Security\ \ Protect Business Critical Applications with GitHub Audit Logs & Modern SIEM\ \ Brandon\ \ Min](/content/blog/protect-business-critical-applications-with-github-audit-logs-modern-siem/index.html) \ \ Detection & Response\ \ Think Like a Detection Engineer, Pt. 2: Rule Writing\ \ Jack\ \ Naglieri](/content/blog/think-like-a-detection-engineer-pt-2-rule-writing/index.html) \ \ Detection & Response\ \ Think Like a Detection Engineer, Pt. 1: Logging\ \ Jack\ \ Naglieri](/content/blog/think-like-a-detection-engineer-pt-1-logging/index.html) \ \ Company Culture\ \ Connect with Panther Users and Security Experts in the Panther Community\ \ Matt\ \ Korovesis](/content/blog/introducing-the-panther-community/index.html) \ \ Cloud Security\ \ Monitoring 1Password Logs\ \ Weyland\ \ Chiang](/content/blog/monitoring-1password-logs/index.html) \ \ Cloud Security\ \ How Panther Protects Data in the Cloud\ \ Brandon\ \ Min](/content/blog/how-panther-protects-cloud-data/index.html) \ \ Product\ \ Avoiding Alert Storms with Data Replay in Panther\ \ Brandon\ \ Min](/content/blog/data-replay-in-panther/index.html) \ \ Company Culture\ \ Reflecting on what makes Panther a “Great Place to Work”\ \ Pamela\ \ Golden](/content/blog/reflecting-on-what-makes-panther-a-great-place-to-work/index.html) \ \ Detection & Response\ \ Reduce false positives with GreyNoise threat intelligence in Panther\ \ Panther Labs](/content/blog/greynoise-threat-intelligence-in-panther/index.html) \ \ Detection & Response\ \ Okta and LAPSUS$: Investigation Resources and How Panther Can Help\ \ Panther Labs](/content/blog/investigating-the-2022-lapsus-okta-security-incident/index.html) \ \ Product\ \ Improve detection fidelity and alert triage with Lookup Tables in Panther\ \ Panther Labs](/content/blog/improve-detection-fidelity-and-alert-triage-with-lookup-tables-in-panther/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Bill Lawrence\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-bill-lawrence-2/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Slava Bronfman\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-slava-bronfman/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Carlos Morales\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-carlos-morales/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Ashu Savani\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-ashu-savani/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Albert Heinle\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-albert-heinle/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Aliaksandr Latushka\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-aliaksandr-latushka/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Isla Sibanda\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-isla-sibanda/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Matt Hartley\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-matt-hartley/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Hugo Sanchez\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-hugo-sanchez/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From David Vincent\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-david-vincent-2/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Giora Engel\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-giora-engel/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Eslam Reda\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-eslam-reda/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Kimberly Sutherland\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-kimberly-sutherland/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Bruce Young\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-bruce-young/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Morgan Hill\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-morgan-hill/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Yaniv Masjedi\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-yaniv-masjedi/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Haseeb Awan\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-haseeb-awan/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Eric McGee\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-eric-mcgee/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Steve Tcherchian\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-steve-tcherchian/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Purandar Das\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-purandar-das/index.html) \ \ Detection & Response\ \ Panther’s guide to Log4j exploitation prevention and detection\ \ Panther Labs](/content/blog/panthers-guide-to-log4j-exploitation-prevention-and-detection/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Roger Smith\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-roger-smith/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Ian L. Paterson\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-ian-l-paterson/index.html) \ \ Company Culture\ \ Building the Future of Security: Panther Series B Funding\ \ Jack\ \ Naglieri](/content/blog/building-the-future-of-security-panther-series-b-funding/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Jerry Sanchez\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-jerry-sanchez/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Chris Connor\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-chris-connor/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Charlie Riley\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-charlie-riley/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Alex Cherones\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-alex-cherones/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Bill Lawrence\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-bill-lawrence/index.html) \ \ Thought Leadership\ \ State of SIEM in 2021: 6 Key Takeaways\ \ Jack\ \ Naglieri](/content/blog/state-of-siem-in-2021-6-key-takeaways/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Zach Fuller\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-zach-fuller/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Paul Mansur\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-paul-mansur/index.html) \ \ Detection & Response\ \ Find Patterns Quickly with Indicator Search Drill Down\ \ Panther Labs](/content/blog/find-patterns-quickly-with-indicator-search-drill-down/index.html) \ \ Thought Leadership\ \ Future of Cyber Attacks\ \ Panther Labs](/content/blog/future-of-cyber-attacks/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From Jonathan Roy\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-jonathan-roy/index.html) \ \ Thought Leadership\ \ The Future of Cyber Attacks — Insights From David Pignolet\ \ Panther Labs](/content/blog/the-future-of-cyber-attacks-insights-from-david-pignolet/index.html) \ \ Detection & Response\ \ Detect Everything, Real-Time Alerts As Needed\ \ Nick\ \ Kuligoski](/content/blog/detect-everything-real-time-alerts-as-needed/index.html) \ \ Cloud Security\ \ Why Panther Chose Snowflake\ \ Jack\ \ Naglieri](/content/blog/why-panther-chose-snowflake/index.html) \ \ Thought Leadership\ \ Buy or Build Your Security Solution?\ \ Panther Labs](/content/blog/buy-or-build-your-security-solution/index.html) \ \ Company Culture\ \ Snowflake Cybersecurity Partner of The Year\ \ Jack\ \ Naglieri](/content/blog/snowflake-cybersecurity-partner-of-the-year/index.html) \ \ Product\ \ Going Closed Source\ \ Jack\ \ Naglieri](/content/blog/going-closed-source-panther-community-edition-is-being-sunset-with-v1-16-as-our-last-open-source-release/index.html) \ \ Detection & Response\ \ Advanced Detections with Scheduled Queries\ \ William\ \ Lowe](/content/blog/scheduled-queries-for-advanced-threat-detection/index.html) \ \ Detection & Response\ \ Security Monitoring with CrowdStrike Falcon Events\ \ Jack\ \ Naglieri](/content/blog/security-monitoring-crowdstrike-falcon/index.html) \ \ Product\ \ Activate Security Automation with Alert Context\ \ Sugandha\ \ Lahoti](/content/blog/security-automation-alert-context/index.html) \ \ Detection & Response\ \ Detecting Sunburst Malware with Panther\ \ Jade\ \ Catalano](/content/blog/detecting-sunburst-malware-with-panther/index.html) \ \ Product\ \ Automated Detection and Response with Panther and Tines\ \ Jack\ \ Naglieri](/content/blog/security-automation-panther-tines/index.html) \ \ Detection & Response\ \ Threat Hunting at Scale\ \ Jack\ \ Naglieri](/content/blog/threat-hunting/index.html) \ \ Detection & Response\ \ Analyze Internal Security Data with Custom Log Parsers\ \ Sugandha\ \ Lahoti](/content/blog/custom-log-parsers/index.html) \ \ Product\ \ Triage Alerts Faster with Alert Summaries\ \ Sugandha\ \ Lahoti](/content/blog/faster-alert-triage/index.html) \ \ Product\ \ Continuous Security Monitoring for Slack, Cloudflare, and Fastly\ \ Sugandha\ \ Lahoti](/content/blog/security-monitoring-slack-cloudflare-fastly/index.html) \ \ Company Culture\ \ From StreamAlert to Panther\ \ Jack\ \ Naglieri](/content/blog/streamalert-to-panther/index.html) \ \ Company Culture\ \ Panther Labs Series A Funding\ \ Jack\ \ Naglieri](/content/blog/series-a-funding/index.html) \ \ Product\ \ Why Panther Chose to Open Up Its Security Data Lake\ \ Russell\ \ Leighton](/content/blog/panther-database-as-service-modern-serverless-architecture/index.html) \ \ Product\ \ Feature Spotlight: Snowflake-Powered Data Explorer\ \ Sugandha\ \ Lahoti](/content/blog/snowflake-powered-data-explorer/index.html) \ \ Detection & Response\ \ Osquery Log Analysis Guide\ \ Jack\ \ Naglieri](/content/blog/osquery-log-analysis/index.html) \ \ Product\ \ Panther v1.6 Spotlight: Log Analysis Dashboard, SIEM for G Suite and Box Logs, SSO, Dark Theme, and more!\ \ Sugandha\ \ Lahoti](/content/blog/1-6-spotlight-siem-g-suite-box-logs-single-sign-on-dark-theme/index.html) \ \ Product\ \ Visualize Your AWS Cloud Security Posture with Charts and Graphs\ \ Sugandha\ \ Lahoti](/content/blog/aws-cloud-security-charts-graphs/index.html) \ \ Product\ \ Panther and Snowflake Partner to Power Enterprise SIEM Workloads\ \ Kartikey\ \ Pandey](/content/blog/panther-siem-partners-snowflake-press-release/index.html) \ \ Product\ \ Panther’s CLI Tool\ \ Sugandha\ \ Lahoti](/content/blog/panthers-cli-tool/index.html) \ \ Product\ \ Search Performance Optimizations\ \ Sugandha\ \ Lahoti](/content/blog/feature-spotlight-automatic-log-compaction/index.html) \ \ Product\ \ New Log Parsers\ \ Sugandha\ \ Lahoti](/content/blog/panther-log-parsers-feature/index.html) \ \ Cloud Security\ \ Panther Cloud-Native SIEM: Moving Beyond Traditional SIEMs\ \ Kartikey\ \ Pandey](/content/blog/cloud-native-siem-with-panther/index.html) \ \ Cloud Security\ \ Panther v1.0: Cloud-Native SIEM for Modern Security Teams\ \ Jack\ \ Naglieri](/content/blog/panther-v1-open-source-siem/index.html) \ \ Company Culture\ \ RSA Conference 2020: A Recap of the Top Announcements\ \ Sugandha\ \ Lahoti](/content/blog/rsa-conference-2020-announcements/index.html) \ \ Cloud Security\ \ 6 AWS Services for Cloud Security Detection\ \ Sugandha\ \ Lahoti](/content/blog/aws-security-services/index.html) \ \ Cloud Security\ \ 6 Open Source Cloud Security Tools You Should Know\ \ Sugandha\ \ Lahoti](/content/blog/open-source-cloud-security-tools/index.html) \ \ Product\ \ Announcing Panther: A Cloud-Native, Continuous Security Monitoring Platform\ \ Jack\ \ Naglieri](/content/blog/run-panther/index.html) \ \ Company Culture\ \ Panther Labs Raises $4.5M to Push Cloud Security Forward\ \ Jack\ \ Naglieri](/content/blog/panther-seed/index.html)

Bolt-on AI closes alerts. Panther closes the loop.

See how Panther compounds intelligence across the SOC.

Detect, investigate, and respond to threats at cloud scale — powered by code and AI.

Platform

Data Pipeline

AI SOC Agent

Detection Engine

Alerting and Triage Automation

Analytics & Reporting

Integrations

Solutions

AI SOC Transformation

Detection Engineering

Threat Hunting

Compliance

Managed Detection and Response

Cloud Security Posture

Threat Intelligence

Support

Release Notes

Documentation

Knowledge Base

Status

Resources

Blog

Documentation

Customer Stories

Webinars

Podcasts

Support Hub

Company

About us

Trust

Careers

All rights reserved © 2026 Panther, Inc

Terms of Service

Privacy Policy

Sitemap

linkedin

x-twitter

youtube

mastodon