virustotal

Retrieve VirusTotal reports and relationships for hashes, URLs, IPs, and domains.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/mgreen27/dfir-skills --skill virustotal-mgreen27
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: virustotal
Source: https://github.com/mgreen27/dfir-skills/tree/main/skills/virustotal
Command: npx skills add https://github.com/mgreen27/dfir-skills --skill virustotal-mgreen27

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires requests, json, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill enables analysts to augment hash, URL, IP, and domain indicators with VirusTotal reports, improving threat detection accuracy.

Core Features & Use Cases

  • Indicator Enrichment: Fetch detailed analysis reports and relationships for hashes, URLs, IPs, and domains.
  • Threat Investigation: Quickly identify suspicious or malicious artifacts within an investigation.
  • Use Case: A security analyst wants to verify if a suspicious URL is associated with known malware; they can request a VirusTotal analysis and review the findings to inform response actions.

Quick Start

Use the virustotal skill to analyze the hash 'd41d8cd98f00b204e9800998ecf8427e' and retrieve its report.

Frequently Asked Questions about virustotal

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enrich IP addresses and URLs with threat intelligence during incident response?

Indicator enrichment retrieves detailed threat intelligence reports for IP addresses, URLs, domains, and hashes to improve threat detection accuracy during incident response workflows. Analysts can quickly identify suspicious artifacts within an investigation.

Can I perform bulk indicator lookups for hashes and domains using VirusTotal reports?

Yes, bulk indicator lookups are supported for hashes and domains. The Skill retrieves detailed VirusTotal reports and relationship queries, allowing comprehensive threat assessment across multiple artifact types in incident response scenarios.

Do I need an API key to retrieve VirusTotal analysis reports for malware investigation?

Yes, an API key is required. The Skill assumes API key configuration is already complete to retrieve detailed VirusTotal reports and relationships for hashes, URLs, IP addresses, or domains during threat investigations.

What's the best way to verify if a suspicious URL is associated with known malware?

Request a VirusTotal analysis for the suspicious URL and review the retrieved findings. This indicator enrichment fetches detailed reports and relationships to inform your response actions and verify malware associations.

Does this threat intelligence Skill support relationship queries for comprehensive threat assessment?

Yes, relationship queries are supported alongside standard indicator lookups. The Skill retrieves detailed VirusTotal reports and relationships for hashes, URLs, IPs, and domains, enabling comprehensive threat assessment in incident response workflows.

How does indicator enrichment work for threat hunting workflows?

Indicator enrichment augments hash, URL, IP, and domain indicators by fetching detailed VirusTotal analysis reports and relationships. This mechanism streamlines threat analysis by providing comprehensive threat intelligence data for artifact verification.