Panther is a security information and event management (SIEM) platform that enables data-driven security teams to parse, normalize, and analyze large volumes of cloud logs in real-time, facilitating the creation of actionable alerts. It addresses the challenge of alert fatigue by employing detection-as-code and multi-event correlation to streamline threat detection and response at scale.
Funding
$141.5M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.


Founders
Product
Problem
Modern organizations struggle to efficiently manage and analyze the massive influx of security logs generated by cloud infrastructure, leading to delayed threat detection and increased alert fatigue for security teams. Legacy Security Information and Event Management (SIEM) systems often lack the scalability, real-time analysis capabilities, and flexible detection mechanisms required to effectively address these challenges.
Solution
Panther is a cloud-native security monitoring platform that empowers data-driven security teams to transform cloud noise into actionable security signals. By providing petabyte-scale log ingestion, real-time analysis, and a cloud-native security data lake, Panther enables organizations to detect threats faster, respond smarter, and maintain comprehensive security visibility. The platform's Detection-as-Code approach allows security engineers to customize and manage detections using Python, integrate with CI/CD pipelines, and reduce false positives through multi-event correlation. Panther offers a unified search interface, AI-powered investigation tools, and seamless integration with existing security workflows, enabling proactive security operations at scale.
Target Audience
Panther is designed for data-driven security teams, security engineers, and security operations center (SOC) analysts who need a scalable, flexible, and efficient platform for security monitoring and threat detection in cloud and hybrid environments.
Features
- Petabyte-scale ingestion and normalization of diverse log sources, including CloudTrail, VPC Flow Logs, and application logs
- Real-time alerting based on streaming data analysis and customizable Detection-as-Code rules written in Python
- Cloud-native security data lake with affordable search and retention for compliance and threat hunting
- Multi-event correlation to chain security events and reduce alert fatigue
- Automated alert triage and response through integrations with Splunk, Slack, Jira, and other security tools
- Unified data lake search for comprehensive visibility across all log types
- AI-powered investigation tools to accelerate incident response with clear steps and contextual information
- Pre-built and custom detections for various use cases, including data exfiltration, insider threats, and privilege escalation
- Integration with popular cloud platforms, identity providers, and automation tools
- Enterprise-ready deployment options with single-tenant environments, data isolation, and compliance certifications (SOC 2, PCI, ISO-27001, HIPAA)