Note: Listing is specific to Panther's Cloud Connected deployment model, which requires the customer to own AWS and Snowflake infrastructure and associated costs. For custom pricing, SaaS deployment options, EULA, private contract, or private offers please contact sales@panther.com.
The shift to the cloud has resulted in an explosion of data that security teams need to collect, analyze, and retain to detect threats. However, traditional security monitoring tools were never built with cloud-scale in mind and cannot meet the demands of today's modern workloads. Panther is an AWS cloud-native threat detection platform that transforms terabytes of raw logs per day into a structured security data lake to power real-time detection, swift incident response, and thorough investigations.
With detection-as-code in Python and out-of-the-box integrations for critical log sources including S3, CloudTrail, VPC Flow Logs and more - Panther solves the challenges of security operations at scale.
Highlights
Detect threats immediately by analyzing logs as soon as they are ingested, giving you the fastest possible time to detection.
Answer security questions quickly with the ability to immediately query months of data in minutes and efficiently search for IoCs across all logs.
Reduce SIEM costs dramatically while gaining lightning-fast query speeds, with an efficient, highly scalable data lake architecture.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This contract gives you Panther Cloud Connected with a set monthly data ingestion allowance of 1TB and 1 year of data retention. You commit for a 1-year term. Your base price covers ingestion up to the monthly limit. If your ingestion exceeds that allowance, overage charges apply. The specific overage terms are defined in the EULA rather than shown as a separate priced tier here. Pricing centers on how much log data you ingest each month, so your cost tracks with the volume you send into the platform.
Top-of-mind questions for buyers
What counts toward my 1TB monthly ingestion allowance?
The allowance measures the volume of log data you send into the platform each month. Panther ingests sources like cloud infrastructure logs, identity provider logs, endpoint logs, and SaaS application logs. It normalizes each source into a structured schema at ingest. All ingested log volume counts toward the 1TB monthly figure.
What happens if my ingestion goes over the 1TB monthly allowance?
Your base contract covers ingestion up to 1TB each month. If you send more than that in a given month, overage charges apply. The specific overage rates and terms are defined in the EULA rather than listed as a separate priced item here. Review the EULA for exact overage details.
Where is my ingested data stored, and does that affect the ingestion charge?
Panther runs on your own cloud data warehouse, so your security data stays in infrastructure you already own rather than Panther-managed storage. The ingestion allowance meters data volume sent into the platform. Storage in your own account is separate from the contract's ingestion pricing.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Panther support has been continuously praised by customers. See the SLA's page attached for further insight. support@panther.io
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Analyzes logs immediately upon ingestion to detect threats with minimal time to detection latency.
Detection-as-Code Framework
Supports detection rules written in Python programming language for flexible and customizable threat detection logic.
Cloud-Native Data Lake Architecture
Transforms terabytes of raw logs daily into a structured security data lake optimized for scalability and query performance.
Multi-Source Log Integration
Provides out-of-the-box integrations for critical cloud log sources including S3, CloudTrail, and VPC Flow Logs.
Historical Data Query Capability
Enables querying of months of historical log data within minutes and supports efficient searching for Indicators of Compromise across all logs.
Security Information and Event Management
Real-time monitoring and visibility for threat detection including ransomware, insider threats, and cloud attacks with security analytics for rapid investigation and prioritization of critical threats.
Incident Response Automation and Orchestration
Automation and orchestration of incident response workflows with consistent, optimized, and measurable process execution.
Enterprise-Grade AI and Automation
Embedded artificial intelligence and automation capabilities designed to increase analyst productivity and accelerate incident lifecycle management.
Multi-Source Data Correlation
Correlation of data across users, networks, and cloud-native services to identify threats including cloud misconfigurations, policy changes, and suspicious user activity with alert deduplication.
Hybrid and Cloud Environment Integration
Centralized visibility across hybrid cloud and on-premises environments with deep integrations to AWS security services including Security Hub, CloudTrail, GuardDuty, Network Firewall, WAF, Detective, CloudWatch, and VPC Flow Logs.
Threat Detection Engine
Library of 900+ out-of-the-box detections with user and attacker behavior analytics backed by community threat intelligence
Data Ingestion and Integration
Ingests CloudTrail, GuardDuty, EC2 network traffic, raw logs via SQS from multiple AWS accounts, on-premises networks, remote endpoints, and SaaS solutions
Investigation and Response Capabilities
Visual investigation timeline with detailed log timelines, automated response workflows, and instant actions such as asset quarantining
Deception Technology
Honeypots, honey credentials, and honey files for layered defense mechanisms
Compliance and Monitoring
File Integrity Monitoring (FIM) with support for PCI, HIPAA, and GDPR compliance requirements, plus detection of new AWS regions, services, and EC2 instance types
Panther’s SIEM + AI Makes Triage and Threat Hunting Fast and Seamless
Reviewed on Jun 04, 2026
Review provided by G2
What do you like best about the product?
Panther’s SIEM iteration into the AI security space has been a real shift in our security team’s capabilities. With AI Auto Triage, the triage process is quick, and the Panther AI integration enables automated threat hunting. Having threat intel pushed into the MCPs has also been helpful.
The price-to-capability balance feels fair, and it’s the only SIEM I’ve seen so far that has pushed this heavily into SIEM + AI integration. The standard plug-and-play integrations are limited to a typical security tech stack; however, it isn’t difficult to ship logs to S3 and normalize them directly in Panther.
Using a Snowflake datalake, queries are efficient and it’s one of the more seamless ways I’ve used to query log sources at scale. We also have monthly visits with the Panther team to help integrate and upgrade our instances, uncover new release items, and help us engineer the platform for success.
Lastly, the UI/UX is easy to navigate. Most SIEMs are difficult to work with, with buttons doing various things across different areas. This is a SIEM through and through: if you know what you want to find or what detection you want to build, you can do it easily since the backend query structure is SQL and the detections are all detection as code.
What do you dislike about the product?
The hardest part of working with Panther is making sure you manage your detections as code in a solid, maintainable way. It’s easy for your implementation to drift and become out of date compared with the upstream managed Panther repo. Before you start implementing rules and creating your own detections, it’s really important to think through the upstream conflicts that can come up when you customize things. If you account for that upfront while designing your detection-as-code infrastructure, you shouldn’t run into major problems.
What problems is the product solving and how is that benefiting you?
Panther is really moving forward with its AI capabilities. The Panther AI Auto Triage feature has helped us go from triaging hundreds of alerts to focusing only on the important ones. While other companies are adding built-on features to enable AI auto-triage in combination with your SIEM, Panther has this functionality built in, and it works great.
On top of that, they’re taking it a step further by working toward AI that can create new detections directly within the platform. It can also help identify areas with high false positives so we can reduce the noise our analysts deal with, including by suggesting updates to detections that cut down on unnecessary alerts.
Narendran Nair
AI triage has streamlined real-time alert monitoring and has improved on-call incident response
Reviewed on Jun 01, 2026
Review from a verified AWS customer
What is our primary use case?
My main use case for Panther is real-time monitoring of alerts, where we triage incidents that occur for our on-call duties. Panther is one of the major sources from which we receive alerts in real-time.
I use Panther for real-time monitoring by integrating it with Teams and other applications that we use frequently. Whenever an alert comes up, based on the logs and integrations we have set up with Panther, we receive alerts that we triage for further investigation to determine whether they are false positives or not. Panther's AI feature specifically helps us a lot by simplifying our work, providing context on the findings and alerts it processes, and aiding us in understanding whether an activity could be benign or malicious.
We receive Panther alerts since we have integrated many network components with it. Currently, we are utilizing the AI Triage feature, which offers significant clarity on issues and whether they might be false positives or not, allowing us to focus more on suspicious findings. Sometimes what I observe is that an alert could be a false positive, yet it could also be a true positive. However, AI Triage significantly aids us, and we still need to verify if we are genuinely affected or not.
What is most valuable?
The best features Panther offers are AI Triage, the ability to comment on our activities, and seamless integration with other communication sources such as PagerDuty, Microsoft Teams, and potentially Slack, showcasing the flexibility we have in using this tool.
The most valuable feature for my team is definitely AI Triage, which helps save a lot of time by eliminating the need for manual research regarding patterns that may be repeated, making our work easier and more efficient.
Panther has positively impacted my organization as it serves as one of the main sources for triaging real-time incidents. Panther definitely plays a key role in the work that we do.
Specific outcomes that show how Panther has helped our organization include saving a lot of time, especially since the AI Triage feature reduces the necessity to reach out to others for clarity, which it occasionally accomplishes on its own. To be honest, it does lack some aspects. For example, if it could access our organizational knowledge, including the Jira database, it might better analyze incidents and determine whether they are false positives or not by using more contextual data.
What needs improvement?
Panther could be improved by adding a feature that allows it to access organizational data, which would help produce better-tuned outputs with fewer false positives and alerts, making our jobs easier. Additionally, a feature in the alert section that enables users to create rules, perhaps using AI, to whitelist or blacklist certain patterns would also be useful.
The only thing that comes to mind right now as an improvement is having greater organizational knowledge integration and fine-tuning the alerts we receive, along with better triage capabilities.
For how long have I used the solution?
I have been using Panther for more than one year.
What do I think about the stability of the solution?
Based on my experience, Panther is definitely stable.
What do I think about the scalability of the solution?
Panther's scalability is good. We have not encountered any scalability issues, as it handles whatever alerts arise appropriately.
How are customer service and support?
Customer support for Panther is good, although we have not needed to utilize it much. I believe they have a solid support system in place.
Which solution did I use previously and why did I switch?
Panther is the first solution we have used, and we are now considering the Wiz option. I have not switched from any other solution previously.
What was our ROI?
I believe we have seen a return on investment from using Panther, especially given our large infrastructure and network, which generates many alerts. Panther helps us in triaging and fine-tuning these alerts, saving a significant amount of time. The AI Triage feature frequently allows us to bypass manual triaging, contributing to our ROI from Panther.
What's my experience with pricing, setup cost, and licensing?
I am not aware of the pricing, setup cost, and licensing details, as I handle the usage of Panther and not the setup process.
Which other solutions did I evaluate?
I am not sure if other options were evaluated before choosing Panther because I joined the team only within the last year. Thus, I cannot provide details on what others may have considered.
What other advice do I have?
On a scale of one to ten, I would rate Panther an eight out of ten.
I give it an eight out of ten because, although it is a good tool, we are currently exploring Wiz as an option, which sometimes provides more detailed insights compared to Panther. Ultimately, both tools are similar, but we are still in the discovery phase as we consider our options.
Panther is a reputed tool in terms of AI governance and security. We base our confidence on the trust it has garnered and its security certifications along with risk assessments, so we feel comfortable with the data it handles.
Regarding Panther's accuracy and reliability of output, I would rate it at 70 percent since, at times, it identifies findings as valid when they may actually be false positives, which we have experienced in a few cases.
My advice for those looking to use Panther is that if you are aiming to reduce time, resources, and enhance efficiency, Panther's AI Triage is an excellent option. If it had the capability to scale with additional organizational knowledge, it would be an even more effective tool for triaging alerts.
I believe Panther is a good tool. The AI Triage feature saves a considerable amount of time, and if it were to incorporate organizational knowledge, it could provide finer-tuned results. For instance, if it can relate incidents, such as identifying a port scan, to our Jira data, it could determine whether it was likely a false positive based on existing knowledge. If it could integrate diverse contextual data, it would enhance its effectiveness considerably. My overall rating for this product is eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Busra K.
Panther Makes Security Operations Simpler and Faster
Reviewed on May 29, 2026
Review provided by G2
What do you like best about the product?
What I like best about Panther is how quickly it helps us move from alert to action. It’s powerful and highly automated, with strong native integrations that made setup and onboarding easy across teams. Features like enrichment and AI-assisted analysis make SOC investigations much faster and simpler, and the support team is consistently responsive whenever we need help.
What do you dislike about the product?
At the moment, I don’t have any major dislikes. Our experience with Panther has been smooth so far, from onboarding to daily SOC operations.
What problems is the product solving and how is that benefiting you?
Panther is helping us solve the biggest SIEM challenge: turning large volumes of security data into fast, actionable investigation workflows. It centralizes signals from multiple tools through native integrations, enriches alerts with useful context, and uses AI-assisted analysis to reduce manual triage time.
The benefit for us is a faster and more efficient SOC process. Our team can investigate and respond more quickly, onboarding across teams is easier, and we spend less time on repetitive analysis and more time on real risk reduction.
Vikram Chakravarthy
AI-assisted workflows have improved cloud threat investigations and streamline SOC operations
Reviewed on May 26, 2026
Review from a verified AWS customer
What is our primary use case?
Day-to-day, we use Panther AI SOC in-house for centralized SOC monitoring for cloud threat detection. Panther assists security analysts by analyzing security telemetry from the cloud, gathering logs from endpoints, identity, and infrastructure sources such as firewalls, endpoints, and DLP. The AI-assisted detection helps in prioritizing and investigating suspicious activity.
One example of Panther's efficiency is when investigating unusual authentication behavior. It correlated telemetry data and provided better context around suspicious patterns, speeding up investigation with enriched context rather than manual log correlation.
Panther is integrated with the broader SOC workflow alongside cloud telemetry such as IAM logs and infrastructure events, enhancing the AI-assisted analysis.
Panther integrates multiple sources for AI-assisted SOC visibility and investigation support, providing contextual investigation and better signal correlation. Due to its centralized telemetry and AI-driven support, it is essential in cloud-heavy environments.
A useful aspect is better prioritization of suspicious behavior, as AI assists with higher confidence signals, reducing manual alert validation time.
From an operational standpoint, Panther has matured our investigations, as analysts focus more on risk validation and response rather than stitching logs.
What is most valuable?
Panther offers robust AI-assisted SOC visibility and investigation support, integrating multiple sources. Instead of generating alerts, Panther helps analysts with contextual investigation and better signal correlation. In today's cloud-heavy environments, centralized telemetry, coupled with AI-driven investigation support, becomes incredibly useful.
Operationally, Panther has improved investigation maturity. Analysts spend less time manually stitching logs and focus more on risk validation and response. From a SOC perspective, investigation quality has improved as the AI assistance makes context easier to understand.
What needs improvement?
An improvement area could be reporting flexibility and dashboard customization for enterprise-level reporting since larger organizations may want deeper workflow customization based on internal governance requirements. As we use multiple SIEMs, improvements in these aspects would be beneficial.
Another potential enhancement is having AI recommendations become more contextual over time, especially in reducing false positives and tuning prioritization for organization-specific environments. Training the AI will hone alerts and incidents' accuracy.
For how long have I used the solution?
I started evaluating and using Panther within our SOC since 2024, providing POCs to end clients. Panther is a cloud security tool focused on workflow, initially emphasizing visibility and centralized detection, and we have leveraged its AI-driven investigation capabilities for better alert context and faster triage.
What do I think about the stability of the solution?
Panther has been stable in our experience, offering reliable cloud-native monitoring and security analytic workflows without downtime or reliability issues.
What do I think about the scalability of the solution?
Panther's scalability has kept up with our growth, efficiently handling our cloud environment and increasing telemetry data as our monitoring requirements expand based on customer needs.
How are customer service and support?
I have reached out to Panther customer support via email and engaged directly with the TAM. They have assisted us well, especially during customer onboarding issues, providing a positive experience.
Which solution did I use previously and why did I switch?
Previously, we used Seceon aiSIEM, but the AI capability was not as mature compared to Panther, prompting us to switch after evaluating several SIEM platforms and products.
What was our ROI?
We have seen a return on investment measured primarily through SOC efficiency and productivity improvements. The return is operational, with teams observing a twenty to thirty-five percent improvement in investigation efficiency depending on the environment and product maturity.
What's my experience with pricing, setup cost, and licensing?
In terms of pricing, it generally depends on the ingestion scale, telemetry volume, integration, and specific enterprise requirements as we onboard multiple customers. Our evaluation of Panther was based on our SOC efficiency gains and investigation maturity, with decisions typically made by our leadership or the salesperson.
Which other solutions did I evaluate?
We evaluated other options before choosing Panther, including Seceon and multiple AI platforms with integration capabilities, based on our cloud visibility needs.
What other advice do I have?
My advice for others looking into using Panther is first to understand their requirements. If an organization has both cloud and on-prem environments, Panther becomes even more valuable, especially for those with extensive cloud data and analysts spending significant time investigating or correlating logs, as Panther's AI SOC workflow helps enhance operational efficiency.
Panther's output has been consistent in terms of accuracy and reliability, depending on relevant alerts and use cases. We trained their AI platform based on our logs, significantly reducing issues, allowing our team to focus on specific alert parts or incidents.
Practically speaking, Panther commonly integrates with AWS in our environment and can connect with Azure and other cloud-native services depending on the architecture, leveraging AWS-related telemetry visibilities.
Panther is integrated within our cloud-centric SOC environments, connecting to multiple telemetry sources throughout our enterprise.
We purchased Panther directly from sales, not through the AWS Marketplace, and our company acts as a reseller for Panther based on my prior experience.
I would rate this review an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Marketing and Advertising
Compact, Powerful SIEM with Fast-Evolving AI Analytics
Reviewed on May 11, 2026
Review provided by G2
What do you like best about the product?
Panther is a compact, powerful SIEM with AI Analytics that are currently evolving by the day. Each category is easy to browse and use, there are several integrations that can be requested, the price is very competitive with other tools on the market, and the custom rule builder is very well designed.
What do you dislike about the product?
The tool is still in its infancy, however as it continues to grow and reaches action parity with larger, more advanced SIEMs, it will be world class
What problems is the product solving and how is that benefiting you?
Adapting an AI ruleset builder + detection triage helper can really help small teams fill the skill gap found in a SOC. A well built AI helper inside of a SIEM like this, when additional OSINT and context is added, could get an entire operation up and running in a matter of weeks without bloating a team to cover skills.