building-automated-malware-submission-pipeline - Automate malware submission and sandbox analysis
Collects suspicious files, checks known hashes, submits unknown samples to sandboxes, and produces malware verdicts and IOCs for SIEM integration.
Tags
Updated: 2026-10-05Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Collect suspicious files
- Compute file hashes
- Query VirusTotal hashes
- Query MalwareBazaar hashes
- Submit samples to sandboxes
- Retrieve sandbox reports
- Extract indicators and verdicts
Inputs
- Quarantined endpoint files
- Email gateway quarantine files
- EDR API credentials
- VirusTotal API key
- MalwareBazaar API access
- Sandbox endpoint
- Sample file hashes
Outputs
- Quarantined sample files
- File hashes
- Pre-screening verdicts
- Sandbox analysis reports
- Malware verdicts
- Extracted IOCs
- SIEM integration data
Requirements
- Python 3.8 or later
- requests library
- vt-py library
- pefile library
- Isolated analysis network
- Sandbox environment
- Production network isolation
