PolySwarm Scan & Sandbox
自動配備
Filigranの提供による
Detection & Response Enablement
概要
Enrich file artifacts with PolySwarm multi-engine scanning and CAPE/Triage sandbox analysis.
Submits Artifact observables to PolySwarm for multi-engine scanning and sandbox analysis (CAPE, Triage, or both). Creates STIX Notes with scan verdicts, sandbox behavioral reports, LLM threat summaries, and network IOCs. Optionally enriches with malware family profiles (threat actors, CVEs, ATT&CK patterns) via polykg. Attaches JSON, PDF, and LLM reports as files to the observable.