PolySwarmPolySwarmPolySwarmPolySwarm
Go to PolySwarm
Home
Home

Sandbox

On the Sandbox page in the PolySwarm UI, we support Sandboxing Artifacts directly, and managing current submissions.

This page is for submitting Artifacts and tracking those submissions. The results themselves are shown on the Artifact's Results page, alongside the engine verdicts, see Where Results Appear.

To use Sandboxing functionality, you must have this paid feature enabled on your Plan, you can check your Usage page to see if you have this.

Submit to Sandbox

The Submit to Sandbox button offers the ability to submit new Artifacts or Artifacts already in PolySwarm to be detonated on the Sandboxes by a chosen Sandbox provider. Sandbox Analysis will take around 2-5 minutes before the results can be accessed.

This is a direct Sandbox submission, meaning the artifact will go directly to the sandbox and not for Scanning by the AV Engines, if you want to Scan a file then you need to upload the file via the Scanning upload. Alternatively, once the file has been Sandboxed you can use the Analyze Now button on its Results page to have the AV Engines scan it.

If you are using the Public Community, the default is that Sandboxed Artifacts will be detonated on the Sandbox with Internet Outreach. If you are using the Private Community, the default is that Sandboxed Artifacts will be detonated on the Sandbox without Internet Outreach.

Sandbox Submission Pop Up

The Submit to Sandbox button presents a popup with the following options:

  • File, Select a local artifact to be uploaded to PolySwarm for Sandboxing
  • Hash, Search for a artifact already in PolySwarm by hash value
  • URL, Paste in the URL that you wish to Sandbox

    • Choose which Sandbox Provider and detonation VM image to use, currently PolySwarm offers Cape and Triage providers with different detonation images for each.
  • QR Code, Select a local qr code image to be uploaded to PolySwarm for Sandboxing

Provide the artifact or hash, select the Sandbox provider, and select the detonation VM, then click the Submit button to schedule the Sandboxing detonation task. Once submitted, you will return to the My Sandbox page where you can monitor the status of the task.

Sandboxes have multiple returned statuses, these are listed below.

Status What is it for?
Success Finished processing correctly
Started Sandbox session has started.
Collecting Data Sandbox session has been successful and data is being collected.
Failed Sandbox session has failed, this can be due to many reasons.
Pending Sandbox session is queued up and ready to start.
Delayed Sandbox session has been delayed and will start soon.
Failed with Quota Reimbursement Finished processing but failed, quota will be reimbursed.
Timed out with Quota Reimbursement Delayed in the queue for too long, got timed out and then reimbursement.

Supported File Types

The PolySwarm Sandboxes support many file types, these are listed below.

Type Extensions Sandbox Provider
Executable .dll Triage, Cape
Executable .upx Cape
Executable .exe Triage, Cape
Executable .msi Triage
Document .chm Triage, Cape
Document .eml Triage, Cape
Document .msg Triage, Cape
Document .hta Triage, Cape
Document .iqy Triage
Document .doc Cape
Document .docx Cape
Document .xls Cape
Document .xlsx Cape
Document .ppt Cape
Document .pptx Cape
Document .pub Cape
Document .pub2016 Cape
Document .one Cape
Document .mht Cape
Document .hwp Cape
Document .ich Cape
Document .inp Cape
Document .pdf Triage
Document .rtf Triage
Document .slk Triage
Document .swf Triage
Document .html Triage, Cape
Scripting .bat Triage, Cape
Scripting .ps1 Triage, Cape
Scripting .js Triage, Cape
Scripting .jse Triage, Cape
Scripting .vbe Triage, Cape
Scripting .pl Triage
Scripting .py Cape
Scripting .vbs Triage, Cape
Scripting .wsf Triage, Cape
Android .apk Triage
Android .dex Triage
Other .jar Triage
Other .lnk Triage, Cape
Other .url Triage
Other .jnlp Triage
Other .reg Cape
Other .xslt Cape
Other .xps Cape

32MB is the default "max" file submission size, this is a per-account setting, so it is possible for some users/teams to have a higher limit, if you wish to increase this limit please contact [email protected]

My Sandboxing

The My Sandbox tab shows you Artifacts that only you have Sandboxed, and the status of these submissions.

My Sandboxing

The table of submissions displays the following information:

Column What is it for?
Sandboxed On Date and Time that the Artifact was Sandboxed on.
Target File name of file uploaded, or hash of the file is resandboxed.
Type Type of item sandboxed, i.e. file, url.
SHA-256 The sha256 of the Artifact that has been Sandboxed.
Sandbox Provider Name of the sandbox provider used.
Mal Score Independent Score provided by the Sandbox, between 0-10.
Status The status of the Sandbox submission is color coded. The statuses can be: Success, Pending, Collecting Data, Started, Delayed, Failed Reimbursed, Timeout Reimbursed or Failed
Actions Single Action button will open the Results page for that Artifact once the Status has changed to Success.

Filtering

The Filter button at the top right of My Sandbox page provides the ability to Filter the results being seen. The following filter options are available:

My Sandbox Filtering gif

  • Status - Status of the Sandbox submission and can be: Success, Pending, Collecting Data, Started,Delayed, Failed Reimbursed, Timeout Reimbursed or Failed
  • Sandbox Provider - Name of the Sandbox provider.
  • SHA256 - Specific sha256 value of the Sandboxing submission.
  • Date Range - Start and End Date for the Sandboxing submission.

At the bottom of the My Sandbox page you can navigate to the next page if further results exist.

Team Sandboxing

The Team Sandbox tab shows you Artifacts that you and your team members you have Sandboxed, and the status of these submissions.

Team Sandboxing

The table of submissions displays the following information:

Column What is it for?
Sandboxed On Date and Time that the Artifact was Sandboxed on.
Target File name of file uploaded, or hash of the file is resandboxed.
Type Type of item sandboxed, i.e. file, url.
SHA-256 The sha256 of the Artifact that has been Sandboxed.
Sandbox Provider Name of the sandbox provider used.
Mal Score Independent Score provided by the Sandbox, between 0-10.
Status The status of the Sandbox submission is color coded. The statuses can be: Success, Pending, Collecting Data, Started, Delayed, Failed Reimbursed, Timeout Reimbursed or Failed
Actions Single Action button will open the Results page for that Artifact once the Status has changed to Success.

Filtering

The Filter button at the top right of Team Sandbox page provides the ability to Filter the results being seen. The following filter options are available:

My Sandbox Filtering gif

  • Status - Status of the Sandbox submission and can be: Success, Pending, Collecting Data, Started,Delayed, Failed Reimbursed, Timeout Reimbursed or Failed
  • Sandbox Provider - Name of the Sandbox provider.
  • SHA256 - Specific sha256 value of the Sandboxing submission.
  • Date Range - Start and End Date for the Sandboxing submission.

At the bottom of the Team Sandbox page you can navigate to the next page if further results exist.

Sandbox History

The Sandbox History tab allows you to search by sha256 hash to get a list of every time that artifact was Sandboxed, by any user.

Sandbox History

Once you have searched for a Hash value, the table of submissions provides the following information:

Column What is it for?
Sandboxed On Date and Time that the Artifact was Sandboxed on.
Target File name of file uploaded, or hash of the file is resandboxed.
Type Type of item sandboxed, i.e. file, url.
Sandbox Provider Name of the sandbox provider used.
Status The status of the Sandbox submission is color coded. The statuses can be: Success, Pending, Collecting Data, Started, Delayed, Failed Reimbursed, Timeout Reimbursed or Failed
Actions Single Action button will open the Results page for that Artifact once the Status has changed to Success.

Filtering

The Filter button at the top right of the Sandbox History page provides the ability to Filter the results being seen. The following filter options are available:

  • Status - Status of the Sandbox submission and can be: Success, Pending, Collecting Data, Started, Delayed, Failed Reimbursed, Timeout Reimbursed or Failed
  • Sandbox Provider - Name of the Sandbox provider.
  • Date Range - Start and End Date for the Sandboxing submission.

At the bottom of the Sandbox History page you can navigate to the next page if further results exist.

Where Results Appear

Sandbox results are shown on the Artifact's Results page, alongside the engine verdicts and the static analysis metadata. There is no separate sandbox results page.

Each provider has its own section on that page:

  • Triage Sandbox — score and verdict, malware family, analysis tags, behavioral signatures, network activity, dropped files, extracted config, downloads, and the detonation video.
  • CAPE Sandbox — score and verdict, malware family, detections, behavioral signatures, network activity, dropped files, extracted config, downloads, and screenshots.
  • HTTP Requests — HTTP traffic captured by Triage.

Behaviour seen across both detonations is also rolled up into the MITRE ATT&CK and Indicators of Compromise sections.

Both sandboxes score the same Artifact independently and can disagree. See Reading the Scores.

2026 © Swarm Technologies Inc.