Black Hat USA 2026 · PolySwarm is co-hosting the poker night · Claim a Seat →

SOAR Integration

Automate Threat Response

Enrich alerts and submit files directly from your SOAR playbooks. Hash lookups, file scanning, and sandboxing via API or native integration.

Two Ways to Automate

Enrich

Look up hashes, IOCs, or metadata to get instant threat context. PolyScore, malware family, and full artifact details returned in under a second.

Submit

Upload suspicious files directly for scanning or sandboxing. Get deeper analysis when enrichment alone is not enough.

How SOAR Integration Works

1

Alert Fires

Your SOAR receives an alert with a file hash, URL, or suspicious file

2

Enrich or Submit

Search PolySwarm for existing intel, or submit the file for scan and sandbox

3

PolyScore

Get a threat probability, malware family, and full context

4

Respond

Quarantine, allow, or escalate based on your playbook thresholds

SOAR Use Cases

Email Attachment Triage

Suspicious attachment flagged? Submit the file to PolySwarm for scanning and sandboxing. Auto-quarantine if PolyScore exceeds your threshold.

EDR Alert Enrichment

Enrich EDR alerts with a hash lookup. Analysts see PolyScore and malware family immediately instead of hunting for context.

URL Investigation

User reports a suspicious link? Automatically scan it against PolySwarm and return a PolyScore verdict to the reporting workflow

Automated Sandboxing

For files that need deeper analysis, submit directly to PolySwarm sandboxing from your playbook. Get behavioral results without manual intervention.

XSOAR
Palo Alto Integration
Tines
SOAR Integration
<1s
Enrichment Response

Ready to Automate

Enrich alerts and submit files from your SOAR playbooks. Native integrations or REST API.