Black Hat USA 2026 · PolySwarm is co-hosting the poker night · Claim a Seat →

Use Case: Triage

Triage Suspicious Files in Seconds

A user reports a suspicious email. A help desk ticket comes in about a suspicious link. You need a verdict fast. PolySwarm scans attachments and URLs across 35+ engines and returns a PolyScore so you can act, not wait.

The Triage Problem

SOC and help desk teams deal with suspicious files and links every day. Speed matters.

Users Report, You Scramble

Someone forwards a suspicious attachment. You download it, spin up a sandbox VM, wait for analysis, check multiple tools. That takes time you do not have if it is ransomware.

One Tool, One Opinion

Your AV says it is clean. But is it? New malware variants slip past single engines regularly. You need more than one opinion when the stakes are high.

URLs Are Just as Dangerous

Phishing links look legitimate until someone clicks. Checking URLs manually across reputation databases is slow and inconsistent.

35+ Engines. One Verdict.

Submit a file or URL and get back a PolyScore, a confidence-weighted verdict from the engines that assert on your artifact. Malware family identification included.

Scan in Seconds

Drop a file, paste a URL, or submit via API. Results come back fast enough to keep up with your help desk queue.

Multi-Engine Verdict

A single engine might miss it. PolySwarm sends artifacts to 35+ engines and those with relevant expertise assert. PolyScore weights their results by accuracy, giving you signal not noise.

Need Deeper Analysis?

When scanning is not enough, submit to PolySwarm's sandboxes for full behavioral analysis. See network calls, dropped payloads, and MITRE ATT&CK mappings.

Real-World Scenario: The Suspicious Invoice

1

9:02 AM - User Reports Suspicious Email

An employee in accounting forwards an email to the security team. Subject: 'Urgent: Final Invoice.' The attachment is 'invoice_march.exe', not a normal invoice format.

2

9:03 AM - Submitted to PolySwarm

The analyst uploads the file to PolySwarm. No need to fire up a VM or isolate the file manually. It goes straight to 35+ detection engines.

3

9:04 AM - Verdict Returned

PolyScore: 0.97 (malicious). Identified as an Emotet dropper by the majority of engines. Malware family name confirmed. Sandbox analysis shows C2 communication and a secondary payload drop.

4

9:06 AM - Threat Contained

The team blocks the sender domain at the email gateway, adds IOCs to the blocklist, and confirms the user did not open the attachment. Total time from report to resolution: 4 minutes.

Why Teams Use PolySwarm for Triage

Minutes, Not Hours

What used to take 20+ minutes with manual tools takes under 60 seconds with PolySwarm. Scan, verdict, act.

35+ Engines Available

Every submission is sent to 35+ detection engines. Each engine asserts only when it has an opinion on that file type, giving you relevant verdicts not guesswork.

No VMs to Maintain

No local sandbox infrastructure to manage. PolySwarm handles the scanning and sandboxing infrastructure for you.

API or GUI

Submit manually through the web interface or automate triage via API. Integrate into your SOAR playbooks for hands-off triage.

<60s
Time to Verdict
35+
Engines Available
API
Automate via REST API

Triage Faster With PolySwarm

See how PolySwarm can cut your triage time from minutes to seconds.