PolySwarm Scan & Sandbox
Overview
Enrich file artifacts with PolySwarm multi-engine scanning and CAPE/Triage sandbox analysis.
Submits Artifact observables to PolySwarm for multi-engine scanning and sandbox analysis (CAPE, Triage, or both). Creates STIX Notes with scan verdicts, sandbox behavioral reports, LLM threat summaries, and network IOCs. Optionally enriches with malware family profiles (threat actors, CVEs, ATT&CK patterns) via polykg. Attaches JSON, PDF, and LLM reports as files to the observable.