September 10, 2026
Polyswarm App
Enriches hashes, URLs, and domains with crowd-sourced malware verdicts, attribution, and sandbox detonation results from the PolySwarm threat intelligence platform.Built by Erick InglebySplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4
Log in to rate this app
The PolySwarm App integrates crowd-sourced malware threat intelligence into Splunk by enriching indicators of compromise with verdicts derived from multiple detection engines. The app processes hashes, URLs, and domains found in Splunk events, annotating them with threat scores, verdict classifications, and detection counts sourced from the PolySwarm platform. It extracts and refangs indicators from raw text fields within the search head environment and submits artifacts to a cloud-based sandbox for behavioral analysis. Search results are augmented with metadata including malware family attribution, file type classification, and aggregated security vendor assessments. The app operates entirely on the search head tier and relies on a key-value store to cache verdict data, track sandbox task state, and maintain modular input checkpoints. Data enrichment occurs through five specialized search commands that query the PolySwarm API, returning threat intelligence without requiring data to leave the Splunk deployment. Events tagged with the polyswarm:artifact source type represent intelligence pulled from the PolySwarm feed and sandbox task results. The app includes dashboards for reviewing enrichment activity, monitoring sandbox detonations, and triaging indicators flagged by scheduled searches. Workflow actions provide analysts with one-click enrichment from search result tables and direct navigation to the PolySwarm portal for detailed artifact analysis.
Log in to report this app listing.