Learn how to craft high-value alerts in Panther that trigger robust remediation workflows in the industry’s leading no-code security automation platform, Tines.
2. Today’s Speakers
Jack Naglieri
Founder, CEO
Thomas Kinsella
Co-Founder, COO
8+ years in Detection and Response
Ex-Airbnb and Yahoo
Co-creator of StreamAlert
8+ years in Security Operations
Ex-DocuSign and eBay
3. Security teams must leverage automation
to keep up with continuously growing
attack surfaces and data volumes
The Problem
4. Teams can utilize Panther for security
analytics and Tines for automated security
response at cloud-scale
A Path Forward
5. ● Keep your team focused
● Avoid team burnout
● Modular, repeatable, tailored
● Scalable! Built for the cloud
Benefits of this Approach
6. Automating Detection and Response
Collect
Parse, normalize,
and store for
analytics
Detect
Apply real-time
Python detections
on logs
Alert
Fire off alerts to
Tines for automated
response and triage
Respond
Ping users for more
information, hit
external APIs, take
automated action
Investigate
Only triage and
investigate high-
confident alerts
18. ● Pass Alert Context
● Parameterized
requests
● Shared API
credentials
● Templates for 150+
tools, but trivial to
edit to make your
own calls
Scenario 1 - Configuring Stories
22. Scenario 1 - Recap
● Flexible Detections
● Data Lake for Analytics
● Get context on initial signal with VirusTotal
● Ping employees to validate activity
● Automate remediation and containment
● Create repeatable Stories and workflows
33. Scenario 2 - Recap
● Flag initial activity
● Send to Tines for automating lookups
● Use a repeatable ‘Send to Story’ to analyze IP
● Feedback into Panther via S3
● Post-process with Python
● Store in SQL for a history of records
35. Automate all of the things!
● High-scale data processing and analytics
● Detections as Code
● Automated Response
● Plug into commonly used security APIs
● Kick-start your investigations
● Tailored to fit your needs
● Flexible deployments
Better Together
36. Get Started
Join Panther & Tines Community
We can't wait to see what you build!
slack.runpanther.io
github.com/panther-labs/panther
sales@runpanther.io
tines.io/slack
tines.io/community-edition
sales@tines.io