LATEST RELEASE

v1.118

Jan 16, 2026

Panther AI is now generally available with new open beta features including natural language PantherFlow query generation, AI-assisted detection building, and human-in-the-loop tool approval.

New and Noteworthy
Enhancements
Schema Changes
  • TargetProcessId added to Crowdstrike.FDREvent schema as the primary field for target process IDs.

  • The following fields have been deprecated across all CrowdStrike schemas:

    • TreeId_decimal

    • ContextThreadId_decimal

    • ContextProcessId_decimal

    • ContextTimeStamp_decimal

  • Azure.Audit durationMs field type changed from bigint to float.

  • Azure.MonitorActivity has had additional parsing added to the time field to handle instances of timestamps being sent with nanoseconds.

  • Sublime.MDM message_id field changed from bigint to string. The body and subject fields are no longer required.

Panther Developer Workflows
  • Since the last Panther release, the panther-analysis repository has published versions 3.95.0–3.98.0, which include a number of new rules, such as:

    • Cloud ransomware detections for AWS, GCP, and Azure

    • React2Shell zero day detections for AWS, GCP, and Cloudflare

    • OpenAI detections

    • Azure.MonitorActivity rules based on MSFT and Elastic detections

  • The Panther MCP server has released version 2.2.0, which focuses on infrastructure improvements, better defaults for metrics tools, and documentation for production deployments.

Bug Fixes
  • Added Bedrock permissions for self-hosted customers.

  • Fixed EventBridge sources documentation link and added an info message referencing log source documentation.

  • Fixed EventBridge source update functionality.

  • Fixed MongoDB puller pagination for users with a high number of projects.

  • Fixed EventHub sources update flow.

  • Fixed Enrichment schema updates for Databricks customers.

  • Fixed UI link for syncing custom enrichment data from Google Cloud Storage (GCS) to point to Panther documentation.

LATEST RELEASE

v1.118

Jan 16, 2026

Panther AI is now generally available with new open beta features including natural language PantherFlow query generation, AI-assisted detection building, and human-in-the-loop tool approval.

New and Noteworthy
Enhancements
Schema Changes
  • TargetProcessId added to Crowdstrike.FDREvent schema as the primary field for target process IDs.

  • The following fields have been deprecated across all CrowdStrike schemas:

    • TreeId_decimal

    • ContextThreadId_decimal

    • ContextProcessId_decimal

    • ContextTimeStamp_decimal

  • Azure.Audit durationMs field type changed from bigint to float.

  • Azure.MonitorActivity has had additional parsing added to the time field to handle instances of timestamps being sent with nanoseconds.

  • Sublime.MDM message_id field changed from bigint to string. The body and subject fields are no longer required.

Panther Developer Workflows
  • Since the last Panther release, the panther-analysis repository has published versions 3.95.0–3.98.0, which include a number of new rules, such as:

    • Cloud ransomware detections for AWS, GCP, and Azure

    • React2Shell zero day detections for AWS, GCP, and Cloudflare

    • OpenAI detections

    • Azure.MonitorActivity rules based on MSFT and Elastic detections

  • The Panther MCP server has released version 2.2.0, which focuses on infrastructure improvements, better defaults for metrics tools, and documentation for production deployments.

Bug Fixes
  • Added Bedrock permissions for self-hosted customers.

  • Fixed EventBridge sources documentation link and added an info message referencing log source documentation.

  • Fixed EventBridge source update functionality.

  • Fixed MongoDB puller pagination for users with a high number of projects.

  • Fixed EventHub sources update flow.

  • Fixed Enrichment schema updates for Databricks customers.

  • Fixed UI link for syncing custom enrichment data from Google Cloud Storage (GCS) to point to Panther documentation.

Ready for less noise
and more control?

See Panther in action. Book a demo today.

Get product updates, webinars, and news

By submitting this form, you acknowledge and agree that Panther will process your personal information in accordance with the Privacy Policy.

Product
Resources
Support
Company