Threat Intelligence Search
Search millions of analyzed artifacts by hash, IOC, or metadata. Instant lookups across everything scanned and sandboxed on PolySwarm.
Built for Speed
Instant Lookups
Sub-second response times. Search by hash, IOC, or metadata and get results immediately. No waiting, no queuing.
API-First
Clean, fast REST API designed for integration. Plug search into your SIEM, SOAR, or custom tooling with minimal effort.
1000+ Searchable Fields
Every scan and sandbox result generates rich metadata. Search across file properties, network IOCs, PE headers, malware configs, tags, families, and more.
Search Methods
Three ways to find threat intelligence in PolySwarm
Hash Search
Lookup by file hash
Search by MD5, SHA1, or SHA256 to instantly retrieve scan results, PolyScore, malware family name, and full artifact metadata for any previously analyzed file.
- MD5, SHA1, SHA256 lookup
- PolyScore and engine verdicts
- PolyUnite malware family name
- Full artifact metadata
IOC Search
IP, domain, and TTP lookup
Search by IP address, domain, or TTP to find matching hashes. Discover which samples communicated with a given C2 server or matched specific indicators. Requires sandbox data.
- IP address and domain lookup
- TTP-based search
- Find related sample hashes
- Sandbox-enriched IOC data
Metadata Search
Advanced search across 1000+ fields
Our most powerful search. Query across 1000+ metadata fields from scan and sandbox results. Search by PE headers, exiftool data, malware configs, tags, families, ransomware transactions, and more.
- PE headers and file structure
- Exiftool file properties
- Malware config fields (C2, botnet)
- Tags, families, and sandbox scores
Search Use Cases
Threat Validation
Quickly check if a file hash has been seen before and get its threat status. Instant answers without rescanning.
Incident Investigation
Search for related artifacts during incident response. Find all samples associated with a malware family or C2 infrastructure.
Threat Research
Use metadata queries to discover new variants and related threats. Search by PE characteristics, config fields, or sandbox indicators.
Automated Enrichment
Integrate hash and IOC searches into your SIEM or SOAR workflows. Automatically enrich alerts with threat intelligence from PolySwarm.
Start Searching Today
Instant threat intelligence lookups across millions of scanned and sandboxed artifacts.

