Panther Labs
Cloud-native SIEM that runs on Snowflake or Databricks, keeping security data in infrastructure customers already own, with 200+ MITRE ATT&CK-mapped detections built in.
Visit Website ↗ + Add to CompareOverview
Panther Labs builds a cloud-native SIEM and detection platform built around the idea that security data should live in the data warehouse an organization already runs, not a proprietary store the SIEM vendor controls. Panther runs natively on top of Snowflake or Databricks, letting customers keep security logs in infrastructure they already own, query it with SQL, and apply detection rules written as Python, an architectural bet against the traditional SIEM model where log ingestion, storage, and licensing costs scale together and often become the single biggest line item in a security operations budget.
Founded in 2018 in San Francisco by Jack Naglieri, Panther has raised roughly $140 million across four rounds, including a $120 million Series B at a $1.4 billion valuation led by ICONIQ Growth and Snowflake Ventures, and a $68 million Series C in January 2023 at an undisclosed valuation. The platform ships with more than 200 built-in detection rules and policies mapped to the MITRE ATT&CK and CIS frameworks, along with dashboards that track detection coverage against those frameworks directly.
Documented customer case studies, such as energy staffing and vendor-management company Workrise, describe choosing Panther specifically to avoid the operational overhead and storage costs of a traditional SIEM while still building custom detections and KPIs quickly, a credible, independently reported example of the cost and complexity tradeoff Panther is built around, even as the company competes in a crowded field against both legacy SIEM incumbents and newer cloud-native security data platforms.
Innovation Matrix Assessment
The platform has continuously expanded its detection library to 200+ rules mapped to MITRE ATT&CK and CIS, plus native Snowflake and Databricks integrations, reflecting sustained product investment since 2018.
A unicorn-valued company with a documented, named production customer (Workrise) describing real operational use, though headcount and total customer count are not independently confirmed.
Roughly $140M raised across four rounds is a strong absolute figure, but the January 2023 Series C did not disclose a valuation, unlike the $1.4B Series B, which leaves the company's more recent growth trajectory less independently verifiable.
Running natively on a customer's own Snowflake or Databricks instance instead of a proprietary data store is a genuine architectural break from both legacy SIEM and most cloud-native SIEM competitors, directly targeting SIEM cost and data-ownership complaints.
The Workrise case study is an independently published, named customer account of real deployment benefits, and the 200+ MITRE ATT&CK-mapped detections are concretely documented; broader efficacy data (detection accuracy, time-to-detect) is not independently benchmarked.
SIEM data volume and licensing cost is one of the most common complaints security operations teams raise, and building detection directly on infrastructure they already pay for addresses that problem in a way that is highly relevant to modern SOC budgets.
Why CISOs Should Care
Lets security teams run detection and investigation directly on security data already sitting in their Snowflake or Databricks environment, avoiding the cost and lock-in of moving that data into a separate proprietary SIEM store.
What Makes It Different
Built natively on customer-owned data warehouses (Snowflake, Databricks) rather than a proprietary backend, with detections written in Python and mapped explicitly to MITRE ATT&CK and CIS coverage dashboards.
The Matrix Verdict
67/100 — INCREMENTAL INNOVATOR
A well-funded, architecturally differentiated cloud-native SIEM with a real customer case study behind it; strong overall, tempered by an undisclosed-valuation Series C that makes recent growth harder to independently verify.
Editorial Note: Claims vs. Verified Findings
Founding details and funding rounds through the Series B ($1.4B valuation) are independently reported by SC Media, Built In SF, and Crunchbase. The Series C amount is independently reported but its valuation was not disclosed publicly. The Workrise case study is independently published by Panther but reflects a real named customer rather than an anonymous claim; broader efficacy statistics are not independently audited.
Sources
Alternatives to Panther Labs
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
ReliaQuest
ReliaQuest operates GreyMatter, a security operations platform that unifies detection, investigation, and response across a customer's existing security…
Microsoft Sentinel
Microsoft's cloud-native SIEM, deeply integrated with Azure and Microsoft 365 telemetry, now layering agentic AI (Security Copilot/Sentinel agents)…