Now available on Splunk and Databricks Marketplaces Learn more >>>
Partner Integrations

Your Agents Already Move at Machine Speed. Get Ground Truth to Match It.

Bring Kyberis enrichment and investigation into Splunk and Databricks, where your detection and security data already lives. Both call the same Kyberis Threat Investigator API (/v2) you use from agents and REST clients, so verdicts, scores, and evidence are identical no matter where the question is asked.

Two Ways In

Native Integrations. Not Another Console.

Kyberis Threat Intelligence for Databricks

Official Databricks Partner · Databricks Marketplace

Notebooks and jobs surface indicators from your data fast — and without external context, they surface them blind. No actor attribution, no confidence scoring, no chain of evidence.

The kyberis_databricks package batch-enriches indicator tables from notebooks and jobs, or powers interactive lookups in the Databricks App. Credentials load from Databricks secret scopes, so access and auditing run through the governance you already have.

Go to Databricks Marketplace

Integration guide · Installation

Kyberis Threat Intelligence for Splunk

Official Splunk Partner · Splunkbase

Splunk shows you the indicator — not whether it matters. Analysts pivot to a separate console to ask "is this actually bad?", then paste a verdict back with its evidence left behind.

The | kyberis search command and an Enterprise Security adaptive response action enrich indicators in place, mapped into the CIM Threat Intelligence data model. It runs on search heads only, and raw SPL never leaves your environment.

Go to Splunkbase

Integration guide · Installation

Not on Databricks or Splunk?

The API and MCP server work anywhere. Start free, or talk to us about Enterprise.