Bring Kyberis enrichment and investigation into Splunk and Databricks, where your detection and security data already lives. Both call the same Kyberis Threat Investigator API (/v2) you use from agents and REST clients, so verdicts, scores, and evidence are identical no matter where the question is asked.

Official Databricks Partner · Databricks Marketplace
Notebooks and jobs surface indicators from your data fast — and without external context, they surface them blind. No actor attribution, no confidence scoring, no chain of evidence.
The kyberis_databricks package batch-enriches indicator tables from notebooks and jobs, or powers interactive lookups in the Databricks App. Credentials load from Databricks secret scopes, so access and auditing run through the governance you already have.
Go to Databricks Marketplace
Official Splunk Partner · Splunkbase
Splunk shows you the indicator — not whether it matters. Analysts pivot to a separate console to ask "is this actually bad?", then paste a verdict back with its evidence left behind.
The | kyberis search command and an Enterprise Security adaptive response action enrich indicators in place, mapped into the CIM Threat Intelligence data model. It runs on search heads only, and raw SPL never leaves your environment.
Go to SplunkbaseThe API and MCP server work anywhere. Start free, or talk to us about Enterprise.