Sandbox
On the Sandbox page in the PolySwarm UI, we support Sandboxing Artifacts directly, and managing current submissions.
This page is for submitting Artifacts and tracking those submissions. The results themselves are shown on the Artifact's Results page, alongside the engine verdicts, see Where Results Appear.
To use Sandboxing functionality, you must have this paid feature enabled on your Plan, you can check your Usage page to see if you have this.
Submit to Sandbox
The Submit to Sandbox button offers the ability to submit new Artifacts or Artifacts already in PolySwarm to be detonated on the Sandboxes by a chosen Sandbox provider. Sandbox Analysis will take around 2-5 minutes before the results can be accessed.
This is a direct Sandbox submission, meaning the artifact will go directly to the sandbox and not for Scanning by the AV Engines, if you want to Scan a file then you need to upload the file via the Scanning upload. Alternatively, once the file has been Sandboxed you can use the
Analyze Nowbutton on its Results page to have the AV Engines scan it.
If you are using the Public Community, the default is that Sandboxed Artifacts will be detonated on the Sandbox with Internet Outreach. If you are using the Private Community, the default is that Sandboxed Artifacts will be detonated on the Sandbox without Internet Outreach.
The Submit to Sandbox button presents a popup with the following options:
- File, Select a local artifact to be uploaded to PolySwarm for Sandboxing
- Hash, Search for a artifact already in PolySwarm by hash value
-
URL, Paste in the URL that you wish to Sandbox
- Choose which Sandbox Provider and detonation VM image to use, currently PolySwarm offers
CapeandTriageproviders with different detonation images for each.
- Choose which Sandbox Provider and detonation VM image to use, currently PolySwarm offers
- QR Code, Select a local qr code image to be uploaded to PolySwarm for Sandboxing
Provide the artifact or hash, select the Sandbox provider, and select the detonation VM, then click the Submit button to schedule the Sandboxing detonation task. Once submitted, you will return to the My Sandbox page where you can monitor the status of the task.
Sandboxes have multiple returned statuses, these are listed below.
| Status | What is it for? |
|---|---|
Success |
Finished processing correctly |
Started |
Sandbox session has started. |
Collecting Data |
Sandbox session has been successful and data is being collected. |
Failed |
Sandbox session has failed, this can be due to many reasons. |
Pending |
Sandbox session is queued up and ready to start. |
Delayed |
Sandbox session has been delayed and will start soon. |
Failed with Quota Reimbursement |
Finished processing but failed, quota will be reimbursed. |
Timed out with Quota Reimbursement |
Delayed in the queue for too long, got timed out and then reimbursement. |
Supported File Types
The PolySwarm Sandboxes support many file types, these are listed below.
| Type | Extensions | Sandbox Provider |
|---|---|---|
| Executable | .dll |
Triage, Cape |
| Executable | .upx |
Cape |
| Executable | .exe |
Triage, Cape |
| Executable | .msi |
Triage |
| Document | .chm |
Triage, Cape |
| Document | .eml |
Triage, Cape |
| Document | .msg |
Triage, Cape |
| Document | .hta |
Triage, Cape |
| Document | .iqy |
Triage |
| Document | .doc |
Cape |
| Document | .docx |
Cape |
| Document | .xls |
Cape |
| Document | .xlsx |
Cape |
| Document | .ppt |
Cape |
| Document | .pptx |
Cape |
| Document | .pub |
Cape |
| Document | .pub2016 |
Cape |
| Document | .one |
Cape |
| Document | .mht |
Cape |
| Document | .hwp |
Cape |
| Document | .ich |
Cape |
| Document | .inp |
Cape |
| Document | .pdf |
Triage |
| Document | .rtf |
Triage |
| Document | .slk |
Triage |
| Document | .swf |
Triage |
| Document | .html |
Triage, Cape |
| Scripting | .bat |
Triage, Cape |
| Scripting | .ps1 |
Triage, Cape |
| Scripting | .js |
Triage, Cape |
| Scripting | .jse |
Triage, Cape |
| Scripting | .vbe |
Triage, Cape |
| Scripting | .pl |
Triage |
| Scripting | .py |
Cape |
| Scripting | .vbs |
Triage, Cape |
| Scripting | .wsf |
Triage, Cape |
| Android | .apk |
Triage |
| Android | .dex |
Triage |
| Other | .jar |
Triage |
| Other | .lnk |
Triage, Cape |
| Other | .url |
Triage |
| Other | .jnlp |
Triage |
| Other | .reg |
Cape |
| Other | .xslt |
Cape |
| Other | .xps |
Cape |
32MB is the default "max" file submission size, this is a per-account setting, so it is possible for some users/teams to have a higher limit, if you wish to increase this limit please contact [email protected]
My Sandboxing
The My Sandbox tab shows you Artifacts that only you have Sandboxed, and the status of these submissions.
The table of submissions displays the following information:
| Column | What is it for? |
|---|---|
| Sandboxed On | Date and Time that the Artifact was Sandboxed on. |
| Target | File name of file uploaded, or hash of the file is resandboxed. |
| Type | Type of item sandboxed, i.e. file, url. |
| SHA-256 | The sha256 of the Artifact that has been Sandboxed. |
| Sandbox Provider | Name of the sandbox provider used. |
| Mal Score | Independent Score provided by the Sandbox, between 0-10. |
| Status | The status of the Sandbox submission is color coded. The statuses can be: Success, Pending, Collecting Data, Started, Delayed, Failed Reimbursed, Timeout Reimbursed or Failed |
| Actions | Single Action button will open the Results page for that Artifact once the Status has changed to Success. |
Filtering
The Filter button at the top right of My Sandbox page provides the ability to Filter the results being seen. The following filter options are available:
- Status - Status of the Sandbox submission and can be:
Success,Pending,Collecting Data,Started,Delayed,Failed Reimbursed,Timeout ReimbursedorFailed - Sandbox Provider - Name of the Sandbox provider.
- SHA256 - Specific sha256 value of the Sandboxing submission.
- Date Range - Start and End Date for the Sandboxing submission.
At the bottom of the My Sandbox page you can navigate to the next page if further results exist.
Team Sandboxing
The Team Sandbox tab shows you Artifacts that you and your team members you have Sandboxed, and the status of these submissions.
The table of submissions displays the following information:
| Column | What is it for? |
|---|---|
| Sandboxed On | Date and Time that the Artifact was Sandboxed on. |
| Target | File name of file uploaded, or hash of the file is resandboxed. |
| Type | Type of item sandboxed, i.e. file, url. |
| SHA-256 | The sha256 of the Artifact that has been Sandboxed. |
| Sandbox Provider | Name of the sandbox provider used. |
| Mal Score | Independent Score provided by the Sandbox, between 0-10. |
| Status | The status of the Sandbox submission is color coded. The statuses can be: Success, Pending, Collecting Data, Started, Delayed, Failed Reimbursed, Timeout Reimbursed or Failed |
| Actions | Single Action button will open the Results page for that Artifact once the Status has changed to Success. |
Filtering
The Filter button at the top right of Team Sandbox page provides the ability to Filter the results being seen. The following filter options are available:
- Status - Status of the Sandbox submission and can be:
Success,Pending,Collecting Data,Started,Delayed,Failed Reimbursed,Timeout ReimbursedorFailed - Sandbox Provider - Name of the Sandbox provider.
- SHA256 - Specific sha256 value of the Sandboxing submission.
- Date Range - Start and End Date for the Sandboxing submission.
At the bottom of the Team Sandbox page you can navigate to the next page if further results exist.
Sandbox History
The Sandbox History tab allows you to search by sha256 hash to get a list of every time that artifact was Sandboxed, by any user.
Once you have searched for a Hash value, the table of submissions provides the following information:
| Column | What is it for? |
|---|---|
| Sandboxed On | Date and Time that the Artifact was Sandboxed on. |
| Target | File name of file uploaded, or hash of the file is resandboxed. |
| Type | Type of item sandboxed, i.e. file, url. |
| Sandbox Provider | Name of the sandbox provider used. |
| Status | The status of the Sandbox submission is color coded. The statuses can be: Success, Pending, Collecting Data, Started, Delayed, Failed Reimbursed, Timeout Reimbursed or Failed |
| Actions | Single Action button will open the Results page for that Artifact once the Status has changed to Success. |
Filtering
The Filter button at the top right of the Sandbox History page provides the ability to Filter the results being seen. The following filter options are available:
- Status - Status of the Sandbox submission and can be:
Success,Pending,Collecting Data,Started,Delayed,Failed Reimbursed,Timeout ReimbursedorFailed - Sandbox Provider - Name of the Sandbox provider.
- Date Range - Start and End Date for the Sandboxing submission.
At the bottom of the Sandbox History page you can navigate to the next page if further results exist.
Where Results Appear
Sandbox results are shown on the Artifact's Results page, alongside the engine verdicts and the static analysis metadata. There is no separate sandbox results page.
Each provider has its own section on that page:
- Triage Sandbox — score and verdict, malware family, analysis tags, behavioral signatures, network activity, dropped files, extracted config, downloads, and the detonation video.
- CAPE Sandbox — score and verdict, malware family, detections, behavioral signatures, network activity, dropped files, extracted config, downloads, and screenshots.
- HTTP Requests — HTTP traffic captured by Triage.
Behaviour seen across both detonations is also rolled up into the MITRE ATT&CK and Indicators of Compromise sections.
Both sandboxes score the same Artifact independently and can disagree. See Reading the Scores.




