Skip to main content
Polyswarm App app icon

Polyswarm App

Enriches hashes, URLs, and domains with crowd-sourced malware verdicts, attribution, and sandbox detonation results from the PolySwarm threat intelligence platform.Built by Erick Ingleby
splunk product badge

Default Version 1.0.0

September 10, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

The PolySwarm App integrates crowd-sourced malware threat intelligence into Splunk by enriching indicators of compromise with verdicts derived from multiple detection engines. The app processes hashes, URLs, and domains found in Splunk events, annotating them with threat scores, verdict classifications, and detection counts sourced from the PolySwarm platform. It extracts and refangs indicators from raw text fields within the search head environment and submits artifacts to a cloud-based sandbox for behavioral analysis. Search results are augmented with metadata including malware family attribution, file type classification, and aggregated security vendor assessments. The app operates entirely on the search head tier and relies on a key-value store to cache verdict data, track sandbox task state, and maintain modular input checkpoints. Data enrichment occurs through five specialized search commands that query the PolySwarm API, returning threat intelligence without requiring data to leave the Splunk deployment. Events tagged with the polyswarm:artifact source type represent intelligence pulled from the PolySwarm feed and sandbox task results. The app includes dashboards for reviewing enrichment activity, monitoring sandbox detonations, and triaging indicators flagged by scheduled searches. Workflow actions provide analysts with one-click enrichment from search result tables and direct navigation to the PolySwarm portal for detailed artifact analysis.