Black Hat USA 2026 · PolySwarm is co-hosting the poker night · Claim a Seat →

TIP Integration

Malware Intel for Your Threat Platform

Enrich observables with PolySwarm malware verdicts or ingest our STIX/TAXII malware intelligence feed directly into your TIP. Native integrations with Anomali, ThreatConnect, ThreatQuotient, Cyware, and Silobreaker.

Two Ways to Integrate PolySwarm

Enrich observables on demand or ingest a continuous malware intelligence feed. Most teams use both.

Enrich

Look up hashes, URLs, or observables to get PolyScore verdicts, malware family names, engine detections, sandbox data, and MITRE ATT&CK mappings. Run enrichments manually or automate them in playbooks.

Ingest

Pull PolySwarm's STIX/TAXII malware intelligence feed directly into your TIP. Ingest threat indicators, YARA hunt results, and malware context for operational use across your security stack.

How TIP Integration Works

1

Connect

Install the PolySwarm app from your TIP marketplace or configure the STIX/TAXII feed

2

Enrich or Ingest

Enrich observables on demand or continuously ingest PolySwarm's malware intelligence feed

3

Get Context

PolyScore, malware family, engine detections, sandbox data, and associated indicators returned

4

Operationalise

Use enriched intel to prioritize alerts, validate IOCs, and distribute to SIEM, SOAR, and EDR

How Teams Use PolySwarm + TIP

Real use cases from PolySwarm TIP integrations.

Hash Enrichment

Look up any hash to get PolyScore, malware family, engine detections, and file details. Enrich manually from the observable page or automate via playbooks.

Malware Intelligence Feed

Ingest PolySwarm's STIX/TAXII feed to pull malware indicators directly into your TIP. Operationalise threat data across your security stack without manual effort.

Investigation Enrichment

During investigations, enrich observables to reveal associated hashes, URLs, IPs, and domains. See C2 outreaches, sandbox behavior, and MITRE ATT&CK mappings.

Hunt Ingestion

Run YARA rules against PolySwarm's dataset using Live Hunt or Historical Hunt. Pull matching results directly into your TIP for triage and analysis.

5+
TIP Partners
35+
Detection Engines
STIX/TAXII
Intelligence Feed

Ready to Integrate PolySwarm

Enrich observables and ingest malware intelligence in your TIP. Native integrations or STIX/TAXII feed.