PolySwarm Enrichment
Overview
Enrich file hash observables with PolySwarm detection data, malware profiles, and MITRE ATT&CK mappings.
Enriches SHA-256, SHA-1, and MD5 file hash observables with PolySwarm multi-engine detection results across default and private communities. Creates STIX indicators with detection scores, malware family profiles with threat actor and CVE associations, MITRE ATT&CK technique mappings, network IOCs (domains, IPs, URLs), and geolocation data. Malware intelligence is sourced from polykg knowledge graph.