Great for Writing Detections
What do you like best about the product?
Writing detections in Python is super nice.
Being able to throw an indicator such as an IP address or username into Panther and having it search everywhere is convenient.
Being able to throw an indicator such as an IP address or username into Panther and having it search everywhere is convenient.
What do you dislike about the product?
When we make customizations to detection rules, it often causes merge conflicts when syncing from the upstream panther-analysis repo.
Custom SQL queries are often slow (on the order of 10 minutes).
Custom SQL queries are often slow (on the order of 10 minutes).
What problems is the product solving and how is that benefiting you?
Having our security relevant logs in one place where we can customize alerting and easily search during manual investigations.
There are no comments to display