VirusTotal
Threat-intelligence API for looking up and scanning files, URLs, domains, and IP addresses across 70+ antivirus engines and URL/domain scanners.
Three ways to use VirusTotal
Chat with Geni
Ask Geni to pull data, take actions, or answer questions using this integration in a conversation.
Build a workflow
Create automated workflows that trigger on events, run on a schedule, or chain multiple tools together.
Power an app
Use this integration as a data source or action layer behind a dashboard, form, or internal tool.
Supported tools
Actions your AI agents can perform with VirusTotal.
Abort a Retrohunt Job (Premium)
Abort a running Retrohunt job. Requires premium.
Add a Comment on a URL
Post a comment on a URL.
Add a Comment to a Domain
Post a comment on a domain.
Add a Comment to a File
Post a comment on a file.
Add a Comment to a Graph
Post a comment on a graph.
Add a Comment to an IP Address
Post a comment on an IP address.
Get started automating VirusTotal
Ready-to-use workflows
Prompts using VirusTotal
Indicator investigation workbench for security analysts
Paste a suspicious IP, hostname, or certificate and get one profile page with Censys detail, VirusTotal reputation, history, and one-click Jira escalation.
IP reputation investigation console for security teams
Paste any suspicious IP address and get a side by side verdict from AbuseIPDB and VirusTotal, plus a shared log of every past investigation.
Firewall change review board for IP block and allow requests
Replace the firewall request spreadsheet with a board that checks every address against threat intelligence before anyone approves a change.
Catch phishing domains impersonating your brand each morning
Every weekday we scan new security certificates for fake versions of your domain, check them for known abuse, and alert your team in Teams.
Auto-triage phishing reports with VirusTotal and Slack
Every 15 minutes, phishing emails your staff forward in get checked against 70+ security engines and summarised in Slack, with a compliance log kept automatically.
Check new HubSpot leads for spam and malicious domains
Every inbound form fill gets its email and website domains checked for known abuse, so reps skip the junk and your sequences stay clean.
Catch a blocklisted domain before your customers do
Every weekday, check your domains for new blocklist flags, log results in your spreadsheet, and get a Slack alert only when something gets worse.
Daily malicious IP threat brief for your security team
Every weekday morning, get a short brief of the internet's most-reported malicious IPs, double-checked against a second source and posted straight to your security Slack channel.