Black Hat USA 2026 · PolySwarm is co-hosting the poker night · Claim a Seat →

How It Works

Incentivized Threat Detection

One submission. 35+ engines analyze in parallel. One consensus score you can trust. PolySwarm's engines are financially rewarded for accuracy and penalized for wrong verdicts, so every result is backed by real accountability.

How It Works

Submit

Users submit artifacts to PolySwarm's network via web UI, API, or CLI.

35+ Detection Engines

Commercial AV, specialized threat detectors, sandboxes, and research-grade analysis, all competing to protect you.

35+
Detection Engines
30%
Malware First Seen in PolySwarm
<1s
Average Response
CrowdStrike
SentinelOne
Dr.Web
IKARUS
ClamAV
Qihoo 360
Alibaba
Filseclab
Lionic
NanoAV
Proton
Quttera
RedDrip APT Scanner
SecondWrite
SecureAge
SecureBrain
Phishtank
urlscan.io
VenusEye
XVirus
SlashNext
Cyberstanc
K7
ApiVoid
CRDF
Criminal IP
Electron
INLYSE MalwareAI
Jiangmin
Seclookup
PolySwarm

Frequently asked questions

PolySwarm is a crowdsourced threat intelligence platform. You submit files, URLs, or other artifacts and 35+ independent detection engines analyze them in parallel. You get a single consensus score (PolyScore) along with full engine-level results.

You can submit via the PolySwarm web UI, API, or CLI. All three use the same detection engine network and return PolyScore and engine-level results.

PolyScore is our performance-weighted consensus score. It combines multiple engine verdicts into one number you can use for triage, automation, and reporting. Each engine's contribution is weighted by its historical accuracy.

You receive verdicts and PolyScore within seconds of engines completing their analysis.

Get started in minutes

Upload a file or URL and see real-time threat scores from our consensus engine. No commitment required.