# VirusTotal integration

> Threat-intelligence API for looking up and scanning files, URLs, domains, and IP addresses across 70+ antivirus engines and URL/domain scanners.

- Authentication: apiKey

## Tools (83)

- **Abort a Retrohunt Job (Premium)**: Abort a running Retrohunt job. Requires premium.
- **Add a Comment on a URL**: Post a comment on a URL.
- **Add a Comment to a Domain**: Post a comment on a domain.
- **Add a Comment to a File**: Post a comment on a file.
- **Add a Comment to a Graph**: Post a comment on a graph.
- **Add a Comment to an IP Address**: Post a comment on an IP address.
- **Add a Vote on a File**: Vote a file harmless or malicious.
- **Add a Vote on a URL**: Vote a URL harmless or malicious.
- **Add a Vote to a Comment**: Vote a comment positive, negative, or abuse.
- **Add a Vote to a Domain**: Vote a domain harmless or malicious.
- **Add a Vote to an IP Address**: Vote an IP address harmless or malicious.
- **Advanced Corpus Search (Premium)**: VT Intelligence search over the full file/URL/domain/IP corpus. Requires premium.
- **Create a Graph**: Create a VT Graph of linked IoC nodes.
- **Create a Livehunt Ruleset (Premium)**: Create a Livehunt YARA ruleset. Requires premium.
- **Create a Retrohunt Job (Premium)**: Launch a Retrohunt YARA scan over the historical corpus. Requires premium.
- **Delete a Comment**: Delete a comment you own.
- **Delete a Graph**: Delete a graph by id.
- **Delete a Livehunt Notification (Premium)**: Delete a Livehunt notification by id. Requires premium.
- **Delete a Livehunt Ruleset (Premium)**: Delete a Livehunt ruleset. Requires premium.
- **Delete a Retrohunt Job (Premium)**: Delete a Retrohunt job by id. Requires premium.
- **Download a File (Premium)**: Download a file's raw bytes by hash. Requires premium.
- **Get a Comment Object**: Retrieve a single comment by id.
- **Get a DNS Resolution Object**: Retrieve a host-to-IP DNS resolution record by id.
- **Get a Domain Report**: Retrieve the report for a domain.
- **Get a File Behavior Report from a Sandbox**: Retrieve one sandbox behaviour report by its {sha256}_{sandbox} id.
- **Get a File Behaviour Summary**: Merged summary of all behaviour reports for a file.
- **Get a File MITRE ATT&CK Summary**: Summary of MITRE ATT&CK tactics/techniques observed in a file's sandbox runs.
- **Get a File Report**: Retrieve the analysis report for a file by hash (MD5, SHA-1, or SHA-256).
- **Get a File's Download URL (Premium)**: Get a signed URL to download a file. Requires premium.
- **Get a Graph Object**: Retrieve a graph by id.
- **Get a Livehunt Notification (Premium)**: Retrieve a single Livehunt notification by id. Requires premium.
- **Get a Livehunt Ruleset (Premium)**: Retrieve a Livehunt ruleset by id. Requires premium.
- **Get All Behavior Reports for a File**: List sandbox behaviour reports produced for a file.
- **Get an Analysis**: Retrieve a file or URL analysis by id and check its status.
- **Get an Attack Tactic Object**: Retrieve a MITRE ATT&CK tactic object by id.
- **Get an Attack Technique Object**: Retrieve a MITRE ATT&CK technique object by id.
- **Get an IP Address Report**: Retrieve the report for an IP address.
- **Get an Operation Object**: Retrieve the status of an asynchronous operation (job) by id.
- **Get a Retrohunt Job (Premium)**: Retrieve a Retrohunt job's status by id. Requires premium.
- **Get a URL Report**: Retrieve the analysis report for a URL by id.
- **Get Comments on a Domain**: List comments on a domain.
- **Get Comments on a File**: List community comments on a file.
- **Get Comments on a Graph**: List comments on a graph.
- **Get Comments on an IP Address**: List comments on an IP address.
- **Get Comments on a URL**: List comments on a URL.
- **Get Large-File Upload URL**: Get a one-time URL for uploading files larger than 32 MB.
- **Get Latest Comments**: List the most recent comments across VirusTotal, optionally filtered.
- **Get Livehunt Notification Files (Premium)**: List file objects that triggered Livehunt notifications. Requires premium.
- **Get Livehunt Notifications (Premium)**: List Livehunt match notifications. Requires premium. Poll-trigger candidate.
- **Get Object Descriptors Related to a Comment**: Fetch lightweight related-object descriptors for a comment.
- **Get Object Descriptors Related to a Domain**: Fetch lightweight related-object descriptors for a domain.
- **Get Object Descriptors Related to a File**: Fetch lightweight related-object descriptors (id + type + context) for a file.
- **Get Object Descriptors Related to a Graph**: Fetch lightweight related-object descriptors for a graph.
- **Get Object Descriptors Related to an Analysis**: Fetch lightweight related-object descriptors for an analysis.
- **Get Object Descriptors Related to an IP Address**: Fetch lightweight related-object descriptors for an IP address.
- **Get Object Descriptors Related to a URL**: Fetch lightweight related-object descriptors for a URL.
- **Get Objects from the IoC Stream (Premium)**: Fetch the aggregated IoC Stream feed of Livehunt/Retrohunt/subscription matches. Requires premium.
- **Get Objects Related to a Comment**: Fetch full related objects for a comment (e.g. author, item).
- **Get Objects Related to a Domain**: Fetch full related objects for a domain.
- **Get Objects Related to a File**: Fetch full related objects for a file (relationship name in path).
- **Get Objects Related to a Graph**: Fetch full related objects for a graph (owner, viewers, editors, etc.).
- **Get Objects Related to an Analysis**: Fetch full related objects for an analysis (e.g. item).
- **Get Objects Related to an IP Address**: Fetch full related objects for an IP address.
- **Get Objects Related to a URL**: Fetch full related objects for a URL.
- **Get Popular Threat Categories**: List VirusTotal's popular threat categories.
- **Get Retrohunt Job Matches (Premium)**: Retrieve the matching files for a Retrohunt job. Requires premium.
- **Get VirusTotal Metadata**: Retrieve engine list and other service metadata.
- **Get Votes on a Domain**: List votes on a domain.
- **Get Votes on a File**: List community votes (harmless/malicious) on a file.
- **Get Votes on an IP Address**: List votes on an IP address.
- **Get Votes on a URL**: List votes on a URL.
- **List Livehunt Rulesets (Premium)**: List your Livehunt YARA rulesets. Requires premium.
- **List Retrohunt Jobs (Premium)**: List your Retrohunt jobs. Requires premium.
- **Request a Domain Rescan**: Reanalyse a domain already in VirusTotal.
- **Request a File Rescan**: Reanalyse a file already present in VirusTotal.
- **Request an IP Address Rescan**: Reanalyse an IP address already in VirusTotal.
- **Request a URL Rescan**: Reanalyse a URL already in VirusTotal.
- **Scan a URL**: Submit a URL for analysis; returns an analysis object id to poll.
- **Search**: Search VirusTotal for a file hash, URL, domain, IP, or keyword.
- **Search Graphs**: List/search VT Graphs visible to you.
- **Update a Graph**: Update a graph's data, nodes, or links.
- **Update a Livehunt Ruleset (Premium)**: Update a Livehunt ruleset. Requires premium.
- **Upload / Scan a File**: Upload a file (up to 32 MB) for multi-engine analysis; returns an analysis object id to poll.

## Related prompts

- [Daily malicious IP threat brief for your security team](https://www.generalinput.com/prompts/daily-malicious-ip-threat-brief-for-your-security-team.md)

Connect VirusTotal in General Input: https://www.generalinput.com/apps/virustotal