Skip to main content
Kyberis brings threat intelligence enrichment and investigation into Databricks, where data and security teams already analyze operational and detection data. Batch-enrich IOC tables from notebooks and jobs, and investigate indicators interactively in a Databricks App — all against the Kyberis Threat Investigator API (/v2). Requires a Kyberis subscription and API key.

What you get

  • A helper package (kyberis_databricks) — credential loading from Databricks secret scopes or app environment variables, short-lived bearer token handling, and batched enrichment helpers (assess_iocs, resolve_entities) that return DataFrame-ready rows with a fixed schema. Pure standard library.
  • A Databricks App — a Streamlit workspace app for interactive IOC and entity investigation: single lookups, paste-a-list batch enrichment with CSV export, and intel search.
  • Example notebooks — IOC batch enrichment into a Delta table, and environment-driven CVE prioritization.
  • A vendored API client — the shared Kyberis API client, dependency-free by design so vendoring is safe.
Kyberis Threat Intelligence for Databricks is listed on Databricks Marketplace. The source is also public at kyberis-ai/kyberis-databricks, so you can add it as a Databricks Git folder or build a wheel for jobs that do not use Git folders.

Guides

Quickstart

Jobs and clusters, via Databricks Marketplace

Open the Marketplace listing, select Get instance access, and name the catalog. The wheel lands in a shared volume:

Notebooks and jobs, via a Git folder

  1. Add the repository as a Databricks Git folder (Workspace → Create → Git folder).
  2. Create a secret scope holding your API key — see Credential setup:
  3. Open notebooks/01_ioc_batch_enrichment.py and run it. The notebooks import src/ and vendor/ from the Git folder directly — no wheel install needed.

Databricks App

The app reads its API key from two app secret resources mapped to KYBERIS_API_KEY_ID and KYBERIS_API_KEY_SECRET in app.yaml. Full steps are in Installation.

Support

Email [email protected], or open an issue.