Skip to content
Notifications
Clear all

Panther alternatives that are not Wiz or CrowdStrike?

3 Posts
3 Users
0 Reactions
19 Views
(@ci_cd_junkie)
Honorable Member
Joined: 7 months ago
Posts: 476
Topic starter   [#28256]

Alright folks, I've been knee-deep in evaluating Panther for the last three weeks, trying to build a proof-of-concept pipeline to ingest, normalize, and alert on cloud audit logs. The data handling is pretty slick, I'll give it that, but the operational overhead of managing the data lake has my platform engineering team giving me the side-eye 😅. We're a mid-sized shop, and while we love the open-source core, we're now looking at the full hosted price tag and... yikes.

So the usual suspects pop up: Wiz for cloud security, CrowdStrike for EDR/XDR. But we're not looking to replace our entire stack; we need a *detection and response* layer that can consume disparate logs (CloudTrail, GCP Audit Logs, some Okta events) and run Python detections. The "build your own" with something like Tines or a custom Elastic setup is on the table, but I'd rather not reinvent the wheel if a good alternative exists.

I'm specifically looking for alternatives that match Panther's core strengths:
* **Detection-as-Code** is non-negotiable. We have a CI/CD pipeline for our security rules, and we treat them like application code (linting, unit tests, PR reviews).
* **Strong support for custom data sources** without a massive per-ingestion fee.
* **The ability to write detections in a familiar language** (Python, Go, etc.), not a proprietary query language alone.
* **Decent response automation** (think auto-contain a user, disable a key, not just alert).

What we've glanced at but would love real-world pipeline stories on:
* **Datadog Security** (We already use their APM, but is the security side robust enough for custom detections?)
* **LimaCharlie** (Infrastructure-as-Code approach looks promising from a devops perspective)
* **Anyscale** or **Google Chronicle** (More on the data lake/query side, but can we build a true DaC workflow on top?)
* **Vanta** (More compliance-focused, I know, but their detection engine seems to be evolving)
* **A simple Snowflake/Apache Iceberg setup with a scheduled dbt + Python layer** (This is the "roll your own" extreme, but maybe it's simpler than we think?)

Has anyone actually implemented a CI/CD flow for detections with any of these? My dream is a GitHub Actions workflow that looks something like this:

```yaml
name: Deploy Detection Rules
on:
push:
paths:
- 'detections/**'
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Lint Python Detections
run: |
python -m pylint detections/
- name: Run Unit Tests
run: |
python -m pytest tests/ --cov=detections
deploy:
needs: test
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Deploy to Security Platform
run: |
# Some CLI tool to sync rules
sec-platform-cli apply -f detections/
```

I'm curious about the real pipeline storiesβ€”what's the testing story like? How do you handle false positive regression? Would you choose a different path if you started today?


pipeline all the things


   
Quote
(@hannahb)
Reputable Member
Joined: 3 months ago
Posts: 261
 

Oh, that Detection-as-Code requirement is so key, I get it. I'm in a similar boat trying to formalize our own alerting. Have you looked into LimaCharlie? From what I've been reading, it seems to hit a lot of those notes - you write detections in YAML or Python and push them via their CLI, which fits into CI/CD. It's cloud-native and they handle the data layer, so maybe less of that operational overhead you mentioned?

I'm curious though, for your custom data sources, are they mostly structured JSON or do you have to deal with weird, non-standard log formats too? That's the part that always trips me up.



   
ReplyQuote
(@cloud_ops_learner_99)
Honorable Member
Joined: 4 months ago
Posts: 495
 

Yeah, the data lake overhead was the exact deal-breaker for us too. We ended up testing a tool called Sumo Logic's Cloud SIEM (formerly Sumo Logic CSE). It does the Detection-as-Code thing with their API and Terraform provider, which might fit your CI/CD pipeline? You can manage all the rules and ingest config as code.

But I'm also nervous about the custom log part. For CloudTrail it's great, but have you tried feeding in those weird Okta System Log events? I had to write a bunch of parsers.



   
ReplyQuote