Skip to main content
There are three ways to use Kyberis in Databricks. All of them need a Kyberis API key (Credential setup) and outbound HTTPS to the Kyberis API (Network requirements).

Compatibility

1. Databricks Marketplace

Kyberis Threat Intelligence for Databricks is listed on Databricks Marketplace.
  1. Open the listing and select Get instance access.
  2. Name the catalog when Databricks prompts you. The default is kyberis_kyberis_threat_intelligence_for_databricks; the rest of these steps use <catalog> for whatever you chose.
  3. The wheel arrives in a shared volume at /Volumes/<catalog>/kyberis/releases/.
Install it on the cluster or job that will run your enrichment:
The wheel is code only: the kyberis_databricks helper package and the vendored kyberis_core client, both dependency-free, so there is nothing else to install. The example notebooks are attached to the Marketplace listing itself, and the Databricks App source comes from the Git folder below. Then set up credentials per Credential setup.

2. Git folder and notebooks

  1. In your workspace, go to Workspace → Create → Git folder and use the URL https://github.com/kyberis-ai/kyberis-databricks.git.
  2. Set up credentials per Credential setup.
  3. Open notebooks/01_ioc_batch_enrichment.py, attach any DBR 13.3+ cluster, fill in the widgets, and run. The notebooks import src/ and vendor/ from the Git folder — nothing to install.

3. Databricks App

The repository root is the app source root, since app.yaml lives there.
Before the first deploy, add the two secret resources the app expects, under Compute → Apps → kyberis-threat-intelligence → Edit → Resources: Grant analysts Can use on the app, from the Permissions tab. The app’s service principal needs READ on the secret scope; Databricks configures that automatically when the secret resources are added. See Credential setup and Permissions.

Upgrading

Pull the Git folder, or re-run databricks sync followed by databricks apps deploy. The version is tracked in pyproject.toml and kyberis_databricks.__version__.

Build the wheel from source

If you would rather not consume the Marketplace share — an air-gapped workspace, or a build you want to audit first — build the same wheel from a clone of kyberis-ai/kyberis-databricks:
Upload it as a job or cluster library, or to a Unity Catalog volume of your own, then %pip install it by path.

Local development

Export KYBERIS_API_KEY_ID, KYBERIS_API_KEY_SECRET, and optionally KYBERIS_API_BASE_URL before running the app locally.