Virustotal Integration
Instant file, URL, domain, and IP reputation enrichment on every alert.
What this integration does
VirusTotal meets agentic SOC
VirusTotal aggregates threat intelligence from 70+ antivirus engines and security vendors. ManySignal automatically enriches alerts with VirusTotal verdicts for file hashes, URLs, domains, and IP addresses extracted from alert context — providing immediate reputation context without manual analyst lookups.
Automatic IOC enrichment for file hashes, IPs, domains, and URLs
Multi-engine scan result summary (e.g., 45/72 engines detect as malicious)
MITRE ATT&CK technique tags from VirusTotal Intelligence
Data collected
- VirusTotal analysis reports for submitted IOCs
- Engine verdicts and detection names
- Threat actor and campaign attributions
- WHOIS and hosting context for domains and IPs
Actions supported
- Submit new file hash or URL for VirusTotal analysis
- Add IOC to VirusTotal hunting feed
- Export VirusTotal enrichment to MISP
Getting started
Set up in minutes
- 1
Obtain a VirusTotal API key
- 2
Configure in ManySignal
Virustotal Integration: frequently asked questions
Does ManySignal submit alert data to VirusTotal?
ManySignal submits only specific IOC values (hashes, URLs, IPs, domains) extracted from alerts. No alert content, user data, or full event logs are sent to VirusTotal. Submitted IOC values may be visible to VirusTotal community users unless using a VirusTotal Private Graph subscription.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.