Black Hat USA 2026 · PolySwarm is co-hosting the poker night · Claim a Seat →

PolySwarm Search

Threat Intelligence Search

Search millions of analyzed artifacts by hash, IOC, or metadata. Instant lookups across everything scanned and sandboxed on PolySwarm.

Built for Speed

Instant Lookups

Sub-second response times. Search by hash, IOC, or metadata and get results immediately. No waiting, no queuing.

API-First

Clean, fast REST API designed for integration. Plug search into your SIEM, SOAR, or custom tooling with minimal effort.

1000+ Searchable Fields

Every scan and sandbox result generates rich metadata. Search across file properties, network IOCs, PE headers, malware configs, tags, families, and more.

Search Methods

Three ways to find threat intelligence in PolySwarm

Hash Search

Lookup by file hash

Search by MD5, SHA1, or SHA256 to instantly retrieve scan results, PolyScore, malware family name, and full artifact metadata for any previously analyzed file.

  • MD5, SHA1, SHA256 lookup
  • PolyScore and engine verdicts
  • PolyUnite malware family name
  • Full artifact metadata

IOC Search

IP, domain, and TTP lookup

Search by IP address, domain, or TTP to find matching hashes. Discover which samples communicated with a given C2 server or matched specific indicators. Requires sandbox data.

  • IP address and domain lookup
  • TTP-based search
  • Find related sample hashes
  • Sandbox-enriched IOC data

Metadata Search

Advanced search across 1000+ fields

Our most powerful search. Query across 1000+ metadata fields from scan and sandbox results. Search by PE headers, exiftool data, malware configs, tags, families, ransomware transactions, and more.

  • PE headers and file structure
  • Exiftool file properties
  • Malware config fields (C2, botnet)
  • Tags, families, and sandbox scores

Search Use Cases

Threat Validation

Quickly check if a file hash has been seen before and get its threat status. Instant answers without rescanning.

Incident Investigation

Search for related artifacts during incident response. Find all samples associated with a malware family or C2 infrastructure.

Threat Research

Use metadata queries to discover new variants and related threats. Search by PE characteristics, config fields, or sandbox indicators.

Automated Enrichment

Integrate hash and IOC searches into your SIEM or SOAR workflows. Automatically enrich alerts with threat intelligence from PolySwarm.

Millions
Analyzed Artifacts
1000+
Searchable Fields
<1s
Response Time

Start Searching Today

Instant threat intelligence lookups across millions of scanned and sandboxed artifacts.