building-automated-malware-submission-pipeline - Automate malware submission and sandbox analysis
Collects suspicious files, checks hashes, submits unknown samples to sandboxes, and produces malware verdicts and IOCs for SIEM integration.
Tags
Updated: 2026-10-05Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Collect suspicious files
- Compute file hashes
- Check VirusTotal hashes
- Check MalwareBazaar hashes
- Pre-screen malware samples
- Submit files to sandboxes
- Poll analysis status
- Retrieve sandbox reports
- Extract behavioral indicators
- Generate malware verdicts
Inputs
- EDR quarantine API
- Email gateway quarantine files
- Network capture files
- VirusTotal API key
- MalwareBazaar API access
- Sandbox API endpoint
- File paths
- Sandbox configuration
Outputs
- Collected sample files
- File hashes
- Pre-screening verdicts
- Sandbox task identifiers
- Sandbox analysis reports
- Behavioral indicators
- Malware verdicts
- SIEM-ready IOCs
Requirements
- Python 3.8 or later
- requests library
- vt-py library
- pefile library
- Sandbox infrastructure
- VirusTotal API permissions
- MalwareBazaar API access
- Isolated analysis network
- No production connectivity
