Databricks Buys Panther

Databricks acquires Panther, merging its AI SOC platform with Databricks' security lakehouse to enhance threat detection and data retention.

6 min read
Databricks logo next to Panther logo
Visual TL;DR
Legacy SIEM LimitsDriver
struggle with data volume, high storage costs, limited data retention
From the article 2 mentionsLegacy SIEMs, designed over a decade ago, are ill-equipped to handle the speed and complexity of today's cyber threats.
Databricks Acquires PantherCore
merging AI SOC platform with Databricks' security lakehouse for enhanced detection
From the article 6 mentionsDatabricks has officially completed its acquisition of Panther, an AI-powered Security Operations Center (SOC) platform.
Scalable Data RetentionEffect
overcomes legacy SIEM limitations with cost-effective, long-term data storage
From the article 2 mentionsThe announcement highlights the growing need for scalable, AI-driven solutions in cybersecurity, a field increasingly defined by data volume and speed of response.
Security Lakehouse ApproachContext
combines Panther's SOC workflows with Databricks' Lakewatch foundation
From the article 9 mentionsThis approach unifies security, IT, and business data in a single, open, and governed location.
AI-Native TriageEffect
leverages AI for faster, more accurate threat detection and investigation
From the article 3 mentionsThis constraint creates data silos and forces analysts into manual, time-consuming alert triage, contributing to burnout.
Openness, Customer ControlContext
anchored in open standards and giving customers control over their data
Enhanced Threat DetectionEffect
improves ability to identify and respond to security threats quickly
From the articleKey features include Detections-as-Code, which brings software engineering rigor to threat detection by allowing engineers to author, test, and deploy detections through standard CI/CD pipelines.
Bolstered Security OfferingsOutcome
Databricks significantly strengthens its cybersecurity capabilities within its architecture
From the articleThis move signals a significant push by Databricks to bolster its security offerings within its data lakehouse architecture.

Databricks has officially completed its acquisition of Panther, an AI-powered Security Operations Center (SOC) platform. This move signals a significant push by Databricks to bolster its security offerings within its data lakehouse architecture. The integration aims to combine Panther's mature SOC workflows and detection engine with Databricks' Lakewatch, an open security lakehouse foundation. The announcement highlights the growing need for scalable, AI-driven solutions in cybersecurity, a field increasingly defined by data volume and speed of response. You can read more about the announcement on the Databricks blog.

The Limits of Legacy SIEM

Traditional Security Information and Event Management (SIEM) systems often force security teams into difficult compromises. These systems struggle with the sheer volume of data generated by modern IT environments, leading to high storage costs and limited data retention. This constraint creates data silos and forces analysts into manual, time-consuming alert triage, contributing to burnout. The rapid evolution of AI-driven threats and sophisticated, multi-stage attacks necessitates an architecture capable of processing petabytes of telemetry with continuous context and automated intelligence. Legacy SIEMs, designed over a decade ago, are ill-equipped to handle the speed and complexity of today's cyber threats.

The Security Lakehouse Approach

Databricks posits that the security lakehouse offers a new paradigm. This approach unifies security, IT, and business data in a single, open, and governed location. This unification allows SOC teams to perform detection, investigation, and response directly on the data. With the integration of Panther, Databricks aims to accelerate this vision. Lakewatch, the core of Databricks' security lakehouse, provides high-fidelity, open-data storage. It enables organizations to retain petabytes of security telemetry for extended periods without prohibitive costs or forced data sampling. This deep historical context is vital for AI agents to detect complex, multi-stage attacks.

Panther's Contribution to the Lakehouse

Panther brings critical capabilities to the Databricks security lakehouse. Its strengths lie in its software-driven detection logic and native AI workflows embedded directly into the data layer. Key features include Detections-as-Code, which brings software engineering rigor to threat detection by allowing engineers to author, test, and deploy detections through standard CI/CD pipelines. This replaces the often cumbersome and ungoverned nature of traditional SIEM rule management. Panther also offers over 100 pre-built integrations across major cloud providers, identity systems, and endpoints, ensuring rapid deployment and immediate value.

AI-Native Triage and Investigation

A central promise of this acquisition is the acceleration of signal-to-context triage. By embedding Panther's AI agents directly into Lakewatch, the platform can perform automated, agentic triage in real time. These agents enrich alerts with crucial context from across the security lakehouse, including cloud logs, identity signals, and business data. This process transforms raw telemetry into actionable incident summaries, significantly reducing the signal-to-noise ratio that plagues SOC teams. Unlike bolt-on AI features, Databricks emphasizes that these are native agentic workflows, capable of continuous learning, rule optimization, and automating response actions at machine speed.

Anchored in Openness and Customer Control

Both Databricks and Panther emphasize a commitment to open standards and customer data ownership. This contrasts with legacy SIEM providers whose business models often rely on proprietary data formats and high ingestion fees. Security telemetry stored in the Databricks security lakehouse remains accessible and governed in open formats like OCSF, Spark, Unity Catalog, Delta, and Parquet. This avoids vendor lock-in and allows for analysis with a variety of best-of-breed tools. This open approach ensures that security teams retain complete control over their data, enabling greater flexibility and interoperability across their entire enterprise technology stack.

Competitive Context

The acquisition places Databricks in direct competition with established players in the SIEM and security analytics market, as well as other data platform providers expanding into security. Companies like Snowflake are also building out security capabilities on their platforms. Palantir Technologies, with its own focus on data integration and security analytics, represents another significant competitor. StartupHub.ai data indicates Databricks holds a strong position with a score of 82/100, while Palantir Technologies scores 85/100. The overall market for security data platforms is rapidly evolving, driven by the increasing sophistication of cyber threats and the adoption of AI for defense. Databricks' move to integrate Panther positions it to capture a larger share of this growing market.

© 2026 StartupHub.ai. All rights reserved. Do not enter, scrape, copy, reproduce, or republish this article in whole or in part. Use as input to AI training, fine-tuning, retrieval-augmented generation, or any machine-learning system is prohibited without written license. Substantially-similar derivative works will be pursued to the fullest extent of applicable copyright, database, and computer-misuse laws. See our terms.