Search

Testing | Panther Docs

Testing works by defining a test log event for a certain detection, and indicating whether or not you'd expect an alert to be generated when the test event is processed by that detection.

Detections - Panther Docs

Panther's detection testing ensures that detections behave as expected and generate alerts once deployed correctly. Test inputs are utilized to determine whether or not an alert will generate in order to promote reliability as code evolves and protect against regressions. For more information, see Testing.

Can I create scheduled queries in Panther that run against baseline ...

ANSWER. We recommend creating a scheduled search and then creating a scheduled rule that will be triggered each time your scheduled query runs. This allows you to capture the baseline using Python in the scheduled query, and create alerts from the data that your scheduled query returns.

Why Your Security Pipeline is Broken–And How to Fix It - Panther

Approaches to reducing storage and processing costs by prioritizing data sources for immediate threat detections vs historical analysis. Data pipeline capabilities across routing, parsing, normalizing, filtering, etc. with practical examples on how to use them in your environment.

DaC-Driven CI/CD: Mastering GitHub Actions and Workflows - Panther

In this workflow, you’ll: Write and manage threat detection content using code, implementing DaC. Automate testing, linting, and deployment of detection content by creating a CI/CD pipeline. Use GitHub and GitHub Actions to manage your code and create the CI/CD pipeline.

Testing a rule with GreyNoise enrichment in Panther returns null values ...

To test the GreyNoise functionality on a rule, make sure to provide the p_enrichment section in the test data below the rule definition in the Panther Console. Afterwards, click Run Test to run the test and verify that it is working as expected.

How do I check the contents of a Panther-managed detection pack?

ANSWER. All Panther-provided detection packs are available for viewing here on GitHub. If you have questions about a specific pack, feel free to reach out to Panther support. Panther Knowledge Base.

Unified Search | Panther

Panther’s search expedites investigations and alert triage. The intuitive interface and robust querying simplifies data searches during investigations and threat hunting. Analysts of all skill levels can conduct complex investigations effortlessly with or without using SQL.

How do I create a detection in Panther based on the number of results ...

QUESTION. How do I create a detection in Panther based on the number of results returned from a data lake query? For example, we want to be alerted when a WAF Rule has generated a high volume of logs which would indicate a DDoS attack is underway. ANSWER. To do this you will have to create a scheduled query and a schedule rule based on that query.

Support | Panther

Detect Security Signal. Request a Demo. We’re committed to helping our customers make the most out of their Panther subscription. Check out our website to see our support options.