Request a demo

Request a demo

v1.109

Latest release

calendar

Aug 29, 2024

New and Noteworthy
  • New correlation rule enhancements:

    • It’s now possible to test correlation rules.

    • Group correlation rules can now specify a minimum number of rules that must match in order for the correlation rule to pass, using MinMatchCount.

    • It’s important to note that both correlation rules and signals can greatly increase Snowflake compute costs. Please see the guidance on both correlation rules and signals on how to ensure you are using them effectively.

  • Safeguard against alert storms with the alert limiter functionality.

  • Use the CrowdStrike Event Streams log source to ingest logs pulled from CrowdStrike’s Event Streams API.

    • This feature is in open beta, and is available to all customers.

  • Use the new Sublime Security integration to ingest Audit, MessageEvent, and Message Data Model (MDM) logs into Panther.

    • Panther-managed detections for Sublime Security logs are coming soon!

  • Ingest Apache Avro files into Panther—this enables you to onboard Azure Monitor and Microsoft Defender logs.

    • This feature is in open beta, and is available to all customers.

  • Use the event.lookup() function to dynamically fetch Lookup Table and Enrichment Provider data in Python detections.

  • The left-hand navigation bar in the Panther Console has been reformatted. For example, the Build option has become Detections, and MITRE ATT&CK is now a tab on the Dashboard homepage. Additionally, Data Models, Helpers, and Packs are now tabs within Detections.

Now Generally Available
  • Use the Sigma rule converter (now with conversion support for GCP Audit logs and SentinelOne Deep Visibility logs) to translate vendor-agnostic detections into Panther detections.

  • Ingest Parquet files into Panther. 

Enhancements
Panther Developer Workflows
  • Panther-analysis version 3.62.0 was released this week, featuring CrowdStrike Event Stream detections

Bug Fixes
  • Fixed a bug in decompression logic when handling large zstd data.

In Closed Beta
  • Panther’s Wiz integration which allows you to ingest issues, vulnerabilities, and audit logs from Wiz, is in closed beta

    • For customers interested in access, please reach out to your account team

    • If you already have access, in the Wiz.Audit schema, the `actionParameters` field is now `type:json` (it was previously `type: object`).

Previous Releases

⭐️

Connect to Content

Add layers or components to make infinite auto-playing slideshows.

Detection-as-Code

⭐️

Connect to Content

Add layers or components to make infinite auto-playing slideshows.

Escape Cloud Noise. Detect Security Signal.

Request a Demo

Escape Cloud Noise. Detect Security Signal.

Request a Demo

Escape Cloud Noise. Detect Security Signal.

Request a Demo

Escape Cloud Noise. Detect Security Signal.

Request a Demo

Product

Solutions

Integrations

Pricing

Detection Coverage

Resources

Case Studies

Blog

Podcasts

Webinars

Solution Briefs

Events

Workshops

Support

Documentation

Knowledge Base

Release Notes

Status

Community

Company

About Us

Careers

Partners

News

Trust

Product

Solutions

Integrations

Pricing

Detection Coverage

Resources

Case Studies

Blog

Podcasts

Webinars

Solution Briefs

Events

Workshops

Support

Documentation

Knowledge Base

Release Notes

Status

Community

Company

About Us

Careers

Partners

News

Trust

© 2024 Panther Labs

|

Terms of Service

Privacy Policy

|

Sitemap

Product
Resources
Support
Company