v1.121

Panther AI can now generate SQL queries from natural language in the Data Explorer, run scheduled prompts and auto-triage as a specific user or token, and help build your organization profile.

New and Noteworthy

Now Generally Available

Enhancements

  • The Netskope integration now supports 15 additional log types.

    • Existing Netskope integrations need to enable these new schemas.

  • Define indicator fields when importing custom enrichment data with a Scheduled Search.

  • User management page includes sorting, filtering by role and status, and search.

  • Color contrast updates to the Panther Console.

  • Updated Panther logo in the Panther Console.

  • You can rename existing GCP Pub/Sub log sources.

  • The API Tokens page displays both the GraphQL and REST endpoint URLs.

  • The Panther REST API includes the reference field on all detection endpoints.

Panther Developer Workflows

  • Since the last Panther release, the panther-analysis repository has published versions 3.102.0–3.104.0, which include:

    • GreyNoise enrichment helpers and threat detection rules.

    • Okta baseline and behavioral anomaly rules.

    • Unified Sigma EDR data models.

    • New rulesets for Upwind, SOCRadar, Databricks audit, and AWS WAF.

  • You can now manage Google Cloud Pub/Sub and GCS log sources through the Panther Terraform Provider. Requires Panther v1.121 and Terraform Provider v0.2.10.

Bug Fixes

  • You can now rename existing GCP Pub/Sub log sources.

  • Fixed tooltip content rendering light text on a light background.

  • The Panther AI side panel is no longer visible on tabs that do not use it.

  • Global helpers can no longer include /, \\\\, or .. in their IDs. Existing globals with these characters must update their IDs before they can be modified.

  • Fixed an issue where failed Jira comment syncs on alerts did not surface an error when the Jira comment was not found.

  • Resolved an issue where comments containing horizontal rules did not sync correctly to Jira.

  • Fixed Google Workspace profile pulling with Workload Identity Federation.

  • Fixed the MS Graph UI save button being disabled when the subscription plan value was empty.

  • The Data Explorer and Search pages load faster.

  • GCP Pub/Sub and GCS log sources reject credential-type changes unless new credentials are provided.

v1.121

Panther AI can now generate SQL queries from natural language in the Data Explorer, run scheduled prompts and auto-triage as a specific user or token, and help build your organization profile.

New and Noteworthy

Now Generally Available

Enhancements

  • The Netskope integration now supports 15 additional log types.

    • Existing Netskope integrations need to enable these new schemas.

  • Define indicator fields when importing custom enrichment data with a Scheduled Search.

  • User management page includes sorting, filtering by role and status, and search.

  • Color contrast updates to the Panther Console.

  • Updated Panther logo in the Panther Console.

  • You can rename existing GCP Pub/Sub log sources.

  • The API Tokens page displays both the GraphQL and REST endpoint URLs.

  • The Panther REST API includes the reference field on all detection endpoints.

Panther Developer Workflows

  • Since the last Panther release, the panther-analysis repository has published versions 3.102.0–3.104.0, which include:

    • GreyNoise enrichment helpers and threat detection rules.

    • Okta baseline and behavioral anomaly rules.

    • Unified Sigma EDR data models.

    • New rulesets for Upwind, SOCRadar, Databricks audit, and AWS WAF.

  • You can now manage Google Cloud Pub/Sub and GCS log sources through the Panther Terraform Provider. Requires Panther v1.121 and Terraform Provider v0.2.10.

Bug Fixes

  • You can now rename existing GCP Pub/Sub log sources.

  • Fixed tooltip content rendering light text on a light background.

  • The Panther AI side panel is no longer visible on tabs that do not use it.

  • Global helpers can no longer include /, \\\\, or .. in their IDs. Existing globals with these characters must update their IDs before they can be modified.

  • Fixed an issue where failed Jira comment syncs on alerts did not surface an error when the Jira comment was not found.

  • Resolved an issue where comments containing horizontal rules did not sync correctly to Jira.

  • Fixed Google Workspace profile pulling with Workload Identity Federation.

  • Fixed the MS Graph UI save button being disabled when the subscription plan value was empty.

  • The Data Explorer and Search pages load faster.

  • GCP Pub/Sub and GCS log sources reject credential-type changes unless new credentials are provided.

Bolt-on AI closes alerts. Panther closes the loop.

See how Panther compounds intelligence across the SOC.

Bolt-on AI closes alerts. Panther closes the loop.

See how Panther compounds intelligence across the SOC.

Bolt-on AI closes alerts. Panther closes the loop.

See how Panther compounds intelligence across the SOC.

Bolt-on AI closes alerts. Panther closes the loop.

See how Panther compounds intelligence across the SOC.