Malware Intel for Your Threat Platform
Enrich observables with PolySwarm malware verdicts or ingest our STIX/TAXII malware intelligence feed directly into your TIP. Native integrations with Anomali, ThreatConnect, ThreatQuotient, Cyware, and Silobreaker.
Two Ways to Integrate PolySwarm
Enrich observables on demand or ingest a continuous malware intelligence feed. Most teams use both.
Enrich
Look up hashes, URLs, or observables to get PolyScore verdicts, malware family names, engine detections, sandbox data, and MITRE ATT&CK mappings. Run enrichments manually or automate them in playbooks.
Ingest
Pull PolySwarm's STIX/TAXII malware intelligence feed directly into your TIP. Ingest threat indicators, YARA hunt results, and malware context for operational use across your security stack.
How TIP Integration Works
Connect
Install the PolySwarm app from your TIP marketplace or configure the STIX/TAXII feed
Enrich or Ingest
Enrich observables on demand or continuously ingest PolySwarm's malware intelligence feed
Get Context
PolyScore, malware family, engine detections, sandbox data, and associated indicators returned
Operationalise
Use enriched intel to prioritize alerts, validate IOCs, and distribute to SIEM, SOAR, and EDR
How Teams Use PolySwarm + TIP
Real use cases from PolySwarm TIP integrations.
Hash Enrichment
Look up any hash to get PolyScore, malware family, engine detections, and file details. Enrich manually from the observable page or automate via playbooks.
Malware Intelligence Feed
Ingest PolySwarm's STIX/TAXII feed to pull malware indicators directly into your TIP. Operationalise threat data across your security stack without manual effort.
Investigation Enrichment
During investigations, enrich observables to reveal associated hashes, URLs, IPs, and domains. See C2 outreaches, sandbox behavior, and MITRE ATT&CK mappings.
Hunt Ingestion
Run YARA rules against PolySwarm's dataset using Live Hunt or Historical Hunt. Pull matching results directly into your TIP for triage and analysis.
Ready to Integrate PolySwarm
Enrich observables and ingest malware intelligence in your TIP. Native integrations or STIX/TAXII feed.

