Panther
Enables interactive security operations and detection tuning within the Panther security platform.
概要
Panther provides an MCP server that bridges your IDE and the Panther security platform, allowing you to write and fine-tune detections, interactively query security logs using natural language, and triage alerts directly from your development environment. It supports a wide array of tools for managing alerts, querying data lakes, creating and managing rules and schemas, and gathering metrics, streamlining security workflows and enhancing incident response capabilities.
主な機能
- 7 GitHub stars
- Write and tune detection rules from your IDE
- Execute SQL queries against Panther's data lake
- Triage, comment on, and resolve alerts efficiently
- Query security logs interactively with natural language
- Manage Panther rules, schemas, and global helpers
ユースケース
- Automating alert management tasks, such as assigning and resolving alerts.
- Investigating security incidents by querying logs with natural language.
- Developing and testing Panther detection rules directly from an IDE.