Polyswarm Logo

Polyswarm

0
Commercial
Visit Website

PolySwarm is a next-generation malware intelligence marketplace that provides early detection of threats, unique samples, higher accuracy, and unrivaled threat hunting capabilities. It aggregates threat detection engines from various contributors, including independent researchers and security teams, to cover protection gaps and better protect enterprises against new threats. The platform offers PolyScore threat scoring, which enables SOC automation, and allows users to try it out with a free sign-up. PolySwarm's robust network of threat detection engines delivers wide coverage against common threats, and its specialized engines detect emerging and rare threats that others may miss.

FEATURES

ALTERNATIVES

A community-driven project sharing detection logic, adversary tradecraft, and resources to make detection development more efficient, following MITRE ATT&CK structure.

A collection of public YARA signatures for various malware families.

A tool for creating custom detection rules from YAML input

A library of adversary emulation plans to evaluate defensive capabilities against real-world threats.

Powershell Threat Hunting Module for scanning remote endpoints and collecting comprehensive information.

Check if an IP address was used as a Tor relay on a given date.

A community-driven public malware repository providing access to malware samples, tools, and resources for the cybersecurity community.

Tool for visualizing correspondences between YARA ruleset and samples

PINNED