PolySwarm Scan & Sandbox
自動配備
検証済み
Enrichment & Analysis
Malware Analysis And Sandbox
概要
Enrich file artifacts with PolySwarm multi-engine scanning and CAPE/Triage sandbox analysis.
Submits Artifact observables to PolySwarm for multi-engine scanning and sandbox analysis (CAPE, Triage, or both). Creates STIX Notes with scan verdicts, sandbox behavioral reports, LLM threat summaries, and network IOCs. Optionally enriches with malware family profiles (threat actors, CVEs, ATT&CK patterns) via polykg. Attaches JSON, PDF, and LLM reports as files to the observable.
基本情報
コネクター
Internal enrichment
7.260527.0
0