Databricks Completes Panther Acquisition to Advance Security Lakehouse with AI SOC

Databricks Completes Panther Acquisition to Advance Security Lakehouse with AI SOC Image Credit: DragosCondrea/Bigstockphoto.com
Databricks completed its acquisition of Panther to accelerate its security lakehouse strategy by combining AI-native SOC workflows with large-scale security data management.
» @databricks @runpanther »

Databricks announced that the company officially completed the acquisition of Panther, an AI SOC platform built for modern security operations. Cybersecurity has fundamentally transformed into a data management and AI problem. The ability to collect, retain, and analyze data at scale and in real time is now the limiting factor in how fast a SOC can detect and respond. Attackers are leveraging automation and AI to move faster, hide within massive volumes of complex data, and launch increasingly sophisticated, multi-stage attacks across cloud, identity, and SaaS environments. To defend modern enterprises, security teams require an architecture capable of processing petabytes of telemetry with continuous context and automated intelligence.

Legacy SIEMs were built more than a decade ago around limited data ingestion, strict sampling trade-offs, rigid compute architectures, and manual alert triage. Constrained by high compute costs and inflexible processing power, this legacy approach simply cannot scale to defend against AI-driven threats and rapid zero-day attacks. The industry needs a new paradigm. Databricks established that paradigm with the security lakehouse: an open, governed lakehouse that unifies security, IT, and business data in one place so SOC teams can run detection, investigation, and response directly on top of that data.

Earlier this year, Databricks introduced Lakewatch as our agentic SIEM built on the security lakehouse. Today, the addition of Panther dramatically accelerates the security lakehouse vision by bringing mature, proven operational SOC workflows and 100+ out-of-the-box integrations directly on top of Lakewatch’s open data foundation.

Panther bridges the gap between raw lakehouse data and real-time security execution. Engineered specifically for modern, cloud-native teams, Panther pairs software engineering practices and deep detection logic with native AI workflows embedded directly into the data layer. Instead of basic alert summarization, security teams can deploy intelligent agents that actively investigate incidents, draft detection rules, and execute response actions at machine speed.

Key Capabilities Panther Brings to the Security Lakehouse:

Detections-as-Code: Replace manually managed SIEM rules and ungoverned, UI-centric workflows with detection engineering. Security engineers author, test, version-control, and deploy detections-as-code through standard CI/CD pipelines, bringing software-engineering rigor to threat detection.

100+ Out-of-the-Box Integrations: Deeply parsed connectors across major cloud providers (AWS, Microsoft Azure, Google Cloud), identity systems (Okta, Entra ID), SaaS apps, and endpoints ensure immediate time to value.

AI-Native Triage & Investigation: Automated, agentic triage workflows enrich alerts in real time, turning raw telemetry signals into actionable context before an analyst even opens a ticket.

While other security tools treat AI as a bolted-on chatbot, Lakewatch delivers true, native agentic workflows: AI agents that continuously learn from analyst feedback, automate rule optimization, and elevate your team from alert handlers to strategic engineers.

Last modified on Tuesday, 04 August 2026 07:00

PREVIOUS POST

ImageLockDX Launches AI Authentication Method to Prevent Brute Force Attacks