Threat intelligence is only valuable if it reaches your detections. For many teams, that's still the hardest part. IoCs live in a TIP, a spreadsheet, or someone's browser tab, while detections rely on lookup tables that go stale, scheduled scripts, or custom code that's difficult to maintain. Our latest integration with Google Threat Intelligence brings IoCs into Panther before detections run, making that context available across every detection, search, and alert the moment an event is ingested. Read the full blog to see how it works: https://lnkd.in/d4Q9PF6c
Panther
Computer and Network Security
San Francisco, CA 16,324 followers
The Complete AI SOC Platform
About us
Panther is the AI SOC Platform that scales security expertise by embedding AI agents across your security operations with native access to your data lake, detection logic, and organizational knowledge. Unlike bolt-on tools, Panther's closed-loop architecture turns every alert into compounding intelligence that makes the system smarter over time.
- Website
-
https://panther.com/
External link for Panther
- Industry
- Computer and Network Security
- Company size
- 51-200 employees
- Headquarters
- San Francisco, CA
- Type
- Privately Held
- Founded
- 2018
- Specialties
- Cloud Security, Information Security, Startup, AWS, AWS Security, SIEM, Cloud-Native SIEM, big data, Security Data Lake, Security, Detections as Code, Splunk Alternative, Cloud SIEM, Log Analysis, Security Monitoring, Python, and threat detection
Products
Panther
Security Information & Event Management (SIEM) Software
Panther is the security monitoring platform for the cloud. Unlike ‘next-gen’ SIEMs that rely on historical detections and closed ecosystems, Panther enables flexible defense in production environments with streaming data analysis, programmable detections, and seamless cloud integration – empowering teams to optimize costs and control, accelerate incident response, and achieve cross-system visibility at scale.
Locations
-
Primary
Get directions
San Francisco, CA 94103, US
Employees at Panther
Updates
-
Panther Founder & CEO Jack Naglieri was featured in SC Media discussing one of the biggest challenges facing security teams today: how to scale threat hunting beyond the limits of human bandwidth. His latest commentary explores why continuous, AI-powered hunting could fundamentally change how organizations identify and investigate emerging threats. Read Jack's perspective in SC Media: https://lnkd.in/g-zA_W-q
-
Big news!! 💥
We’re excited to announce that we have agreed to acquire Panther, a next-generation AI SOC platform. Panther delivers what legacy SIEMs can't: AI SOC agents that triage and investigate every alert, and broad data source coverage across the full spectrum of security telemetry. Panther accelerates our vision for agentic security operations. Trusted by leading security teams — including Anthropic — Panther has proven it can defend the most demanding, AI-native environments. Panther marks our third security acquisition as we double down to help organizations defend against increasingly sophisticated AI-driven attackers. Together, we’ll deliver agentic detection and response workflows on an open security lakehouse. This is security built for the agentic era. https://lnkd.in/g52uSUG5
-
-
One of the biggest misconceptions in cloud security is that more telemetry automatically means better detection. CloudTrail already records almost everything that happens in your AWS environment, but the real challenge is determining what warrants attention. In our experience, some of the highest-value cloud detections are surprisingly simple: • Logging tampering • Activity in unused regions • IAM drift • Network exposure changes We put together a practical guide on the cloud signals SOC teams should prioritize, where identity context becomes critical, and how to avoid turning cloud monitoring into another noisy alert queue. 👉 https://lnkd.in/gSRtg8bJ
-
A malicious npm and PyPI package is targeting Kubernetes environments. It looks like a node health tool, and it installs like one too. Once installed, it drops a binary that opens a persistent reverse tunnel back to the attacker. From there, it’s not just the host that’s exposed. Developer machines and CI/CD systems often have: • kubeconfig access • cloud credentials • service account tokens That’s enough to move from one machine to full cluster access. Read the full post → https://lnkd.in/gBsKazFF #ThreatResearch #Panther #Kubernetes #npm
-
👀 Caught in the wild: Anthropic using Panther as part of their agent-driven investigation workflows.
This video from Anthropic perfectly represents the new shape of the SOC, where agents accelerate detection and response workflows. Agents perform best when they can see internal company knowledge, multiple datasets, and broad security/IT tooling. That brings organizational context alongside the event logs, giving us the business-level justification for the signals we create in the SOC. As the interface to security workflows becomes prompt-based, there's real potential to scale who can collaborate on security and the volume of signals we monitor. Anthropic's security team recently shared a demo of what this looks like in practice. They use their system, CLUE, to orchestrate investigation and remediation, which gathers context from Panther, VirusTotal, and internal sources to assess risk and take next steps. Those findings close the loop, improving their overall security posture and remediating issues that surface along the way. The future is agentic! Check it out: https://lnkd.in/gGD9a_-4
How Anthropic uses Claude in Cybersecurity
https://www.youtube.com/
-
A new npm package was published targeting developers running Polymarket trading bots. It presents as a simple logging utility. The payload runs on require(). Once executed, it: • reads .env files and project configs • looks for Polymarket SDK files like createClobClient.ts and clob.ts • exfiltrates API keys and wallet data • installs an SSH key for persistent access on Linux The targeting is specific to how these bots are built, not a broad scan for secrets. If those credentials are exposed, it’s direct access to the accounts the bot is trading on. Read the full blog → https://lnkd.in/e_edk5mx
-
Panther’s #ThreatResearch team tracked an OtterCookie campaign using npm packages that look legitimate on the surface, because they are. The top-level package is a clean wrapper, cloning a real library. The malicious logic sits one dependency deeper in the install chain. On install, a postinstall hook executes the payload and starts pulling data immediately: • credentials and environment files • wallet keys and config files • a full filesystem scan based on remote config On Linux, it goes further, adding an SSH key for persistent access. The package itself looks clean. The behavior lives underneath it. Full breakdown → https://lnkd.in/g3EPweh3
-
In this special episode of the Detection at Scale podcast, our CPO Julian Giuca turns the mic on Panther founder and CEO Jack Naglieri. The conversation covers the full journey of building Panther's AI SOC platform: the 2018 architectural bets on security data lakes and detection-as-code that turned out to be exactly the foundation AI agents needed, and what security teams have learned deploying these systems in production. Topics include: • Why detections written for human analysts fail AI agents • The three-part inflection (reasoning models, tool calling, and MCP) that made agentic SOC work real • What it means to close the loop rather than just close an alert • How teams should think about agent autonomy across different workflow risk levels • What going from 50% to 110% alert coverage actually looks like in practice One frame from the episode worth sitting with: the risk of not adopting AI in the SOC is now greater than the risk of an agent making a mistake. That changes the calculus for how quickly security teams should be moving. Listen now. Link in the comments.
-
⏰ 𝐋𝐢𝐯𝐞 𝐭𝐨𝐦𝐨𝐫𝐫𝐨𝐰: On 𝐌𝐚𝐲 12 𝐚𝐭 10𝐚𝐦 𝐏𝐓 / 1𝐩𝐦 𝐄𝐓, John Hammond and Jack Naglieri are walking through how agentic workflows are being used across triage, investigation, and detection. You’ll see what agents actually need to do the job well, and how investigation output feeds back into detection coverage. We hope you can join us! Save your spot → https://lnkd.in/ghTTx8tQ
-