• Last Updated
    Jul 7, 2026
  • Version
    1.0.0
  • Compatibility
    ThreatQ Versions >= 5.29.0
  • Joe Sandbox Action Bundle

    ThreatQuotient

    Overview

    The Joe Sandbox Action Bundle enables ThreatQ users to automate malware analysis by submitting supported URL indicators and ThreatQ files to Joe Sandbox Cloud and retrieving analysis results directly into ThreatQ. The bundle streamlines submission and enrichment workflows, allowing analysts to incorporate Joe Sandbox intelligence into their ThreatQ investigations.

    The integration provides the following actions:

    • Joe Sandbox - Submit - submits supported URL indicators and ThreatQ files to Joe Sandbox Cloud for analysis. URL indicators can be submitted either as browser URLs or as URL-hosted file samples, depending on the configured submission type.
    • Joe Sandbox - Get Report - retrieves the analysis report for an existing Joe Sandbox submission and enriches the associated ThreatQ indicator with report details and related intelligence.

    The integration is compatible with the following object types:

    • Indicators
      • Filename
      • MD5
      • SHA-1
      • SHA-256
      • URL
    • Files

    The integration returns the following enriched object types:

    • Indicators
      • Indicator Attributes
    • Files
      • File Attributes
    • Reports
      • Report Attributes

    Note: This action is intended for use with ThreatQ TDR Orchestrator (TQO). An active TQO license is required for this feature.

    Copyright © 2026, ThreatQuotient, Inc. All Rights Reserved. Privacy Policy