lookup-virustotal

Query VirusTotal for IP, domain, hash, and URL reputation reports.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill lookup-virustotal
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: lookup-virustotal
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/lookup-virustotal
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill lookup-virustotal

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

VirusTotal reputation checks streamline IOC enrichment by providing a centralized source of truth and concise risk signals.

Core Features & Use Cases

  • Reputation lookups for IPs, domains, hashes, and URLs.
  • Aggregated verdicts, detection ratios, and community signals for quick triage.
  • Use case: when investigating an indicator, fetch malware score and top findings to guide containment.

Quick Start

Ask the AI to check an IOC against VirusTotal to obtain a structured reputation report.

Frequently Asked Questions about lookup-virustotal

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enrich IOCs with VirusTotal reputation data during a threat investigation?

To enrich IOCs with VirusTotal reputation data, query IPs, domains, file hashes, and URLs to obtain detection ratios, community scores, and verdicts. This provides a centralized source of truth and concise risk signals for quick triage during threat investigations.

What threat intelligence fields can I expect from a VirusTotal reputation lookup?

A VirusTotal reputation lookup returns a structured JSON payload containing fields like source, indicator, type, query_time, detection_ratio, community_score, verdict, and key_findings to guide containment and downstream analysis.

Can I check multiple indicator types like IPs, domains, and file hashes against VirusTotal?

Yes, you can check multiple indicator types including IPs, domains, file hashes, and URLs against VirusTotal. The lookup aggregates verdicts, detection ratios, and community signals to provide malware scores and top findings for triage.

What is the best way to automate IOC enrichment for threat intelligence workflows?

The best way to automate IOC enrichment for threat intelligence is to query VirusTotal reputation checks to fetch aggregated malware scores and top findings. This streamlines the process by providing a centralized source of truth for risk signals and detection ratios.

Do I need an API key to perform a VirusTotal lookup for malware score and detection ratios?

The metadata does not specify dependencies or API key requirements for performing a VirusTotal lookup. You can ask the AI to check an IOC against VirusTotal to obtain a structured reputation report with detection ratios and community signals.