Databricks has announced its intention to acquire Panther, an AI SOC platform innovator, in a move set to bolster its security lakehouse strategy.
This acquisition is aimed at reshaping the landscape of security software, challenging traditional SIEM systems with an agentic approach to security monitoring. By joining forces, Databricks and Panther plan to enhance threat detection capabilities, streamline alert investigations, and combat AI-driven cyber-attacks more effectively.
The role of AI in modern security measures
AI-driven threats continue to outpace traditional, human-led defences, as adversaries employ AI to exploit vulnerabilities across cloud, SaaS, and artificial intelligence systems.
Many Security Information and Event Management (SIEM) systems struggle with high costs and inefficient, manual processes, leading organisations to overlook significant portions of their security data. Panther addresses these challenges by providing agentic SOC workflows that allow security teams to efficiently manage alerts and mitigate attacks, matching the scale and speed of AI threats.
Enhancing the security lakehouse vision
Partnering with Panther strengthens Databricks’ capacity to automate SOC workflows
Ali Ghodsi, Co-founder and CEO of Databricks, highlighted the limitations of traditional SIEM systems in AI scenarios. He explained that Databricks is committed to expanding its Lakewatch security initiative and its overarching security lakehouse vision. Partnering with Panther strengthens Databricks’ capacity to automate SOC workflows and offers comprehensive data analysis capabilities, thereby enhancing defences against sophisticated AI-driven attacks.
Jack Naglieri, Founder and CEO of Panther, expressed enthusiasm for collaborating with Databricks, recognising the transformation AI brings to security operations. Together, they aim to provide defenders with advanced tools to scale their detection, investigation, and response efforts.
Integrating security operations
Tim Nguyen, Head of Defense at Anthropic, noted the importance of having programmable and well-integrated security operations to build frontier AI. Panther's approach has been instrumental in adopting a software engineering methodology towards threat detection and response, enabling rapid adaptations to evolving security landscapes.
Earlier this year, Databricks introduced Lakewatch, a security lakehouse framework designed to protect against AI-driven threats. Lakewatch integrates security with IT and business data into a unified, regulated environment, facilitating comprehensive data ingestion, retention, and analysis, all while optimizing operational costs.
Accelerating cloud-native security with Panther
Panther brings a wealth of expertise, with its team comprising seasoned engineers
The acquisition of Panther empowers Databricks' security lakehouse vision by embedding AI agents directly into SOC workflows, allowing for automated alert management and context gathering. Panther provides extensive, high-quality data coverage through numerous pre-built integrations across diverse platforms, delivering immediate, hassle-free data ingestion.
Panther brings a wealth of expertise, with its team comprising seasoned engineers and former SOC analysts. Founded on the principles of detection as code and security data lakes, Panther's platform has evolved into a robust, cloud-native solution.
This acquisition continues Databricks' strategic investments in security, following the acquisitions of Antimatter and SiftD.ai. The announcement is part of Databricks' broader strategy outlined at the Data + AI Summit in San Francisco, subject to regulatory approvals typical for such deals.
Databricks, the Data and AI company, today announces intent to acquire Panther, a pioneer AI SOC platform. The acquisition will advance the company’s vision for the security lakehouse, a new category of security software that is disrupting legacy SIEM with an agentic approach.
Together, Databricks and Panther will help organisations detect more threats, investigate every alert, and fight AI-driven attacks with AI. Trusted by leading security teams — including Anthropic — Panther has proven it can defend the most demanding, AI-native environments. Panther is the third security acquisition announced by Databricks, strengthening its AI security product team and deepening its investment in security.
AI-native environments
AI-driven attacks are evolving faster than human-led defences can keep up. Attackers now use AI agents to find new vulnerabilities and attack paths across cloud, SaaS, and AI systems. Meanwhile, SIEMs are held back by high costs, limited data, and manual, labour-intensive workflows. As a result, most organisations analyse only a fraction of their security data—leaving them blind to many of the new agent-driven attacks in their environments.
Today's SOC workflows make this worse, because they're still largely manual: teams hand-manage data ingestion, hand-write detection rules, and investigate every alert by hand. With legacy tools, SOC teams simply can't keep pace with new threats. Panther closes the gap by replacing costly, closed SIEM stacks with agentic SOC workflows—so defenders can investigate every alert and disrupt attacks at the speed and scale of AI.
Security lakehouse vision
“Legacy SIEM was never designed for AI,” said Ali Ghodsi, Co founder and CEO of Databricks. “Databricks, which has the trust of 70% of the Fortune 500 in data and AI, is doubling down on Lakewatch and our security lakehouse vision. With Panther, we enhance and expand our ability to analyse all data and automate SOC workflows. Together, we can offer the best platform to help defend the world against agentic attacks.”
“We are thrilled to join Databricks and help accelerate the security lakehouse vision,” said Jack Naglieri, Founder and CEO of Panther. “The SOC is at an inflection point: AI is changing how attacks are launched and defenders can now finally keep pace with them. Together with Databricks, we can arm defenders with sophisticated agents that scale detection, investigation, and response.”
AI-driven attackers
"Building frontier AI requires security operations that are programmable and deeply integrated with the way modern engineering teams work,” said Tim Nguyen, Head of Defense at Anthropic. “Panther has helped us bring a software engineering approach to detection and response, giving our team the flexibility to adapt quickly as our environment evolves."
Earlier this year, Databricks introduced Lakewatch, its security lakehouse designed to help organisations defend against increasingly sophisticated AI-driven attackers. Lakewatch unifies security, IT, and business data into a single, governed lakehouse for agentic detection and response, enabling customers to ingest, retain, and analyse unprecedented volumes of unstructured data while reducing total cost of ownership.
Cloud native security operations
Adding Panther accelerates Databricks’ security lakehouse vision in several key ways:
- Agentic workflows designed for SOC: Lakewatch and Panther embed AI agents directly into core SOC workflows so they can automatically triage alerts, gather context, and propose next steps.
- Broad, high-fidelity data coverage: 100+ pre-built, deeply parsed integrations across critical cloud infrastructure, identity providers, endpoints, networks, and SaaS applications, delivering immediate, out-of-the-box ingestion without the complex mapping required by legacy SIEMs.
- Top security team: The Panther team of engineers and former SOC analysts brings deep experience in open source and cloud native security operations. Founded by the leader of the open source StreamAlert project originally created at Airbnb, Panther has grown into a cloud native SIEM and AI SOC platform built on detection as code and security data lakes.
The acquisition of Panther builds on Databricks’ recent security investments, including its acquisitions of Antimatter and SiftD.ai. Hear more this week at Data + AI Summit in San Francisco. The proposed acquisition is subject to customary closing conditions, including any required regulatory clearances.