> ## Documentation Index
> Fetch the complete documentation index at: https://developer.kyberis.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Kyberis for Databricks

> Batch-enrich indicator tables from notebooks and jobs, and investigate indicators interactively in a Databricks App.

Kyberis brings threat intelligence enrichment and investigation into Databricks,
where data and security teams already analyze operational and detection data.
Batch-enrich IOC tables from notebooks and jobs, and investigate indicators
interactively in a Databricks App — all against the Kyberis Threat Investigator
API (`/v2`).

Requires a Kyberis subscription and API key.

## What you get

* **A helper package (`kyberis_databricks`)** — credential loading from
  Databricks secret scopes or app environment variables, short-lived bearer
  token handling, and batched enrichment helpers (`assess_iocs`,
  `resolve_entities`) that return DataFrame-ready rows with a fixed schema. Pure
  standard library.
* **A Databricks App** — a Streamlit workspace app for interactive IOC and entity
  investigation: single lookups, paste-a-list batch enrichment with CSV export,
  and intel search.
* **Example notebooks** — IOC batch enrichment into a Delta table, and
  environment-driven CVE prioritization.
* **A vendored API client** — the shared Kyberis API client, dependency-free by
  design so vendoring is safe.

Kyberis Threat Intelligence for Databricks is listed on
[Databricks Marketplace](https://marketplace.databricks.com/details/3205ecb2-64eb-4baf-8207-b97cd90a18d4/Kyberis_Kyberis-Threat-Intelligence-for-Databricks).
The source is also public at
[`kyberis-ai/kyberis-databricks`](https://github.com/kyberis-ai/kyberis-databricks),
so you can add it as a Databricks Git folder or build a wheel for jobs that do
not use Git folders.

## Guides

| Document | Covers |
| - | - |
| [Installation](/integrations/databricks/install) | App deploy, Git folders, jobs, compatibility |
| [Credential setup](/integrations/databricks/credentials) | Secret scopes, app secret resources, rotation |
| [Permissions](/integrations/databricks/permissions) | Who needs what, the app service principal, least privilege |
| [Network requirements](/integrations/databricks/network) | Egress to `api.kyberis.ai`, serverless and classic compute notes |
| [Data handling and privacy](/integrations/databricks/privacy) | What leaves Databricks, what is stored where, audit logging |

## Quickstart

### Jobs and clusters, via Databricks Marketplace

Open the
[Marketplace listing](https://marketplace.databricks.com/details/3205ecb2-64eb-4baf-8207-b97cd90a18d4/Kyberis_Kyberis-Threat-Intelligence-for-Databricks),
select **Get instance access**, and name the catalog. The wheel lands in a shared
volume:

```python theme={null}
%pip install /Volumes/<catalog>/kyberis/releases/kyberis_databricks-1.0.0-py3-none-any.whl
dbutils.library.restartPython()
```

### Notebooks and jobs, via a Git folder

1. Add the repository as a Databricks Git folder (**Workspace → Create → Git
   folder**).

2. Create a secret scope holding your API key — see
   [Credential setup](/integrations/databricks/credentials):

   ```bash theme={null}
   databricks secrets create-scope kyberis
   databricks secrets put-secret kyberis kyberis-api-key-id
   databricks secrets put-secret kyberis kyberis-api-key-secret
   ```

3. Open `notebooks/01_ioc_batch_enrichment.py` and run it. The notebooks import
   `src/` and `vendor/` from the Git folder directly — no wheel install needed.

### Databricks App

```bash theme={null}
databricks apps create kyberis-threat-intelligence
databricks sync . /Workspace/Users/<you>/kyberis-databricks
databricks apps deploy kyberis-threat-intelligence \
  --source-code-path /Workspace/Users/<you>/kyberis-databricks
```

The app reads its API key from two app secret resources mapped to
`KYBERIS_API_KEY_ID` and `KYBERIS_API_KEY_SECRET` in `app.yaml`. Full steps are
in [Installation](/integrations/databricks/install).

## Support

Email [support@kyberis.ai](mailto:support@kyberis.ai), or
[open an issue](https://github.com/kyberis-ai/kyberis-databricks/issues).
