VirusTotal

VirusTotal

Threat-intelligence API for looking up and scanning files, URLs, domains, and IP addresses across 70+ antivirus engines and URL/domain scanners.

API Key83 tools

Three ways to use VirusTotal

Chat with Geni

Ask Geni to pull data, take actions, or answer questions using this integration in a conversation.

Build a workflow

Create automated workflows that trigger on events, run on a schedule, or chain multiple tools together.

Power an app

Use this integration as a data source or action layer behind a dashboard, form, or internal tool.

Supported tools

Actions your AI agents can perform with VirusTotal.

Abort a Retrohunt Job (Premium)

Abort a running Retrohunt job. Requires premium.

Tool

Add a Comment on a URL

Post a comment on a URL.

Tool

Add a Comment to a Domain

Post a comment on a domain.

Tool

Add a Comment to a File

Post a comment on a file.

Tool

Add a Comment to a Graph

Post a comment on a graph.

Tool

Add a Comment to an IP Address

Post a comment on an IP address.

Tool

Get started automating VirusTotal

01Connect your accountLink your account securely with OAuth or an API key.
02Choose a trigger or toolPick the events and actions your workflow should use.
03Configure the workflowDescribe what you want and Geni wires it up for you.
04Refine the processTest runs, review output, and tweak until it's right.
05Turn it onSet it live and it runs on a schedule or on events.

Ready-to-use workflows

Prompts using VirusTotal

Browse all

Indicator investigation workbench for security analysts

Paste a suspicious IP, hostname, or certificate and get one profile page with Censys detail, VirusTotal reputation, history, and one-click Jira escalation.

CensysVirusTotalJira

IP reputation investigation console for security teams

Paste any suspicious IP address and get a side by side verdict from AbuseIPDB and VirusTotal, plus a shared log of every past investigation.

AbuseIPDBVirusTotal

Firewall change review board for IP block and allow requests

Replace the firewall request spreadsheet with a board that checks every address against threat intelligence before anyone approves a change.

AbuseIPDBVirusTotalCloudflare

Catch phishing domains impersonating your brand each morning

Every weekday we scan new security certificates for fake versions of your domain, check them for known abuse, and alert your team in Teams.

CensysVirusTotalNotionMicrosoft Teams

Auto-triage phishing reports with VirusTotal and Slack

Every 15 minutes, phishing emails your staff forward in get checked against 70+ security engines and summarised in Slack, with a compliance log kept automatically.

VirusTotalGmailSlack BotGoogle Sheets

Check new HubSpot leads for spam and malicious domains

Every inbound form fill gets its email and website domains checked for known abuse, so reps skip the junk and your sequences stay clean.

VirusTotalHubSpotSlack Bot

Catch a blocklisted domain before your customers do

Every weekday, check your domains for new blocklist flags, log results in your spreadsheet, and get a Slack alert only when something gets worse.

VirusTotalGoogle SheetsSlack Bot

Daily malicious IP threat brief for your security team

Every weekday morning, get a short brief of the internet's most-reported malicious IPs, double-checked against a second source and posted straight to your security Slack channel.

AbuseIPDBVirusTotalSlack Bot