M ManySignal
MS
VT
Integration

Virustotal Integration

Instant file, URL, domain, and IP reputation enrichment on every alert.

What this integration does

VirusTotal meets agentic SOC

VirusTotal aggregates threat intelligence from 70+ antivirus engines and security vendors. ManySignal automatically enriches alerts with VirusTotal verdicts for file hashes, URLs, domains, and IP addresses extracted from alert context — providing immediate reputation context without manual analyst lookups.

Automatic IOC enrichment for file hashes, IPs, domains, and URLs

Multi-engine scan result summary (e.g., 45/72 engines detect as malicious)

MITRE ATT&CK technique tags from VirusTotal Intelligence

Data collected

  • VirusTotal analysis reports for submitted IOCs
  • Engine verdicts and detection names
  • Threat actor and campaign attributions
  • WHOIS and hosting context for domains and IPs

Actions supported

  • Submit new file hash or URL for VirusTotal analysis
  • Add IOC to VirusTotal hunting feed
  • Export VirusTotal enrichment to MISP

Getting started

Set up in minutes

  1. 1

    Obtain a VirusTotal API key

  2. 2

    Configure in ManySignal

Virustotal Integration: frequently asked questions

Does ManySignal submit alert data to VirusTotal?

ManySignal submits only specific IOC values (hashes, URLs, IPs, domains) extracted from alerts. No alert content, user data, or full event logs are sent to VirusTotal. Submitted IOC values may be visible to VirusTotal community users unless using a VirusTotal Private Graph subscription.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.