Analyze an IP address with VirusTotal to retrieve reputation, detection statistics, country, ASN, and network information. Requires a VirusTotal API key.
Query VirusTotal for threat intelligence on a file hash. Get detection results from 70+ antivirus engines, file metadata, and behavioral analysis to validate suspicious files or enrich IOCs.
Retrieve detailed sandbox behavioral analysis for a file hash to understand malware capabilities, including process activity, network connections, and MITRE ATT&CK techniques. Essential for threat detection and incident response.
Query VirusTotal for domain threat intelligence including reputation, WHOIS, DNS, and detection results from 90+ security vendors. Investigate suspicious domains in incident response.
Retrieve threat intelligence for an IP address from VirusTotal, including reputation scores, geolocation, and network ownership for investigating suspicious activity.
Retrieve a consolidated sandbox behavior summary for a file by hash, merging processes, files, registry, network, MITRE ATT&CK techniques, IDS alerts, and signatures across all sandbox analyses.
Retrieve a VirusTotal collection by its ID to access threat actors, malware families, campaigns, or curated IOC sets. Optionally include relationships to fetch related IOCs like files, URLs, and domains.
Query historical threat data from surface, deep, and dark web sources using Lucene syntax. Filter by document type or threat type to find relevant intelligence.