Integrate With Your Security Stack
Connect PolySwarm malware intelligence to your SIEM, SOAR, or TIP. Native integrations for the most popular platforms, REST API for everything else.
Native Integrations
Bring-your-own-key integrations for the platforms your team already uses.
SIEM
Enrich security events with PolySwarm malware verdicts. Splunk out-of-box integration, REST API for any SIEM.
SIEM IntegrationSOAR
Enrich alerts or submit files directly from playbooks. Native integrations with XSOAR and Tines.
SOAR IntegrationTIP
Enrich observables and ingest malware intelligence feeds. Anomali, ThreatConnect, ThreatQuotient, Cyware, and Silobreaker.
TIP IntegrationCustom Integrations
Most of our customers integrate PolySwarm into their own tools and workflows. The API makes it straightforward.
REST API
Scan files, look up hashes, search IOCs, and retrieve verdicts with simple HTTP requests. Full documentation and examples available.
STIX/TAXII Feed
Ingest PolySwarm malware intelligence as a STIX/TAXII feed directly into any platform that supports it.
Enrichment
The most common integration pattern. Look up a hash or IOC, get back a PolyScore, malware family, engine detections, and metadata in under a second.
File Submission
Submit files or URLs for scanning and sandboxing via API. Get full multi-engine verdicts and behavioral analysis results.
Ready to Integrate
Native integrations or REST API. Our team can help you get set up.

