For AI agents: visit https://virustotal.readme.io/llms.txt for an index of all pages formatted in Markdown and endpoints in OpenAPI.
Jump to Content
VirusTotal
HomeGuidesAPI Reference
VirusTotal
API Reference
HomeGuidesAPI Reference

Introduction

  • VirusTotal API v3 Overview
  • Public vs Premium API
  • Technology Integrations
  • Getting started
  • Authentication
  • API responses
    • Errors
    • Key concepts
    • Objects
    • Collections
    • Relationships
  • Legend
  • API v2 to v3 Migration Guide

IOC REPUTATION & ENRICHMENT

  • IP addresses
    • Get an IP address reportget
    • Request an IP address (re)scanpost
    • Get comments on an IP addressget
    • Add a comment to an IP addresspost
    • Get objects related to an IP addressget
    • Get object descriptors related to an IP addressget
    • Get votes on an IP addressget
    • Add a vote to an IP addresspost
  • Domains & Resolutions
    • Get a domain reportget
    • Request an domain (re)scanpost
    • Get comments on a domainget
    • Add a comment to a domainpost
    • Get objects related to a domainget
    • Get object descriptors related to a domainget
    • Get a DNS resolution objectget
    • Get votes on a domainget
    • Add a vote to a domainpost
  • Files
    • Upload a filepost
    • Get a URL for uploading large filesget
    • Get a file reportget
    • Request a file rescan (re-analyze)post
    • Get a file’s download URLget
    • Download a fileget
    • Get comments on a fileget
    • Add a comment to a filepost
    • Get objects related to a fileget
    • Get object descriptors related to a fileget
    • Get a crowdsourced Sigma rule objectget
    • Get a crowdsourced YARA rulesetget
    • Get votes on a fileget
    • Add a vote on a filepost
  • File Behaviours
    • Get a summary of all behavior reports for a fileget
    • Get a summary of all MITRE ATT&CK techniques observed in a fileget
    • Get all behavior reports for a fileget
    • Get a file behavior report from a sandboxget
    • Get objects related to a behaviour reportget
    • Get object descriptors related to a behaviour reportget
    • Get a detailed HTML behaviour reportget
    • Get the EVTX file generated during a file’s behavior analysisget
    • Get the PCAP file generated during a file’s behavior analysisget
    • Get the memdump file generated during a file’s behavior analysisget
  • URLs
    • Scan URLpost
    • Get a URL reportget
    • Request a URL rescan (re-analyze)post
    • Get comments on a URLget
    • Add a comment on a URLpost
    • Get objects related to a URLget
    • Get object descriptors related to a URLget
    • Get votes on a URLget
    • Add a vote on a URLpost
  • Comments
    • Get latest commentsget
    • Get a comment objectget
    • Delete a commentdel
    • Get objects related to a commentget
    • Get object descriptors related to a commentget
    • Add a vote to a commentpost
  • Analyses, Submissions & Operations
    • Get a URL / file analysisget
    • Get objects related to an analysisget
    • Get object descriptors related to an analysisget
    • Get a submission objectget
    • Get an operation objectget
  • Attack Tactics
    • Get an attack tactic objectget
    • Get objects related to an attack tacticget
    • Get object descriptors related to an attack tacticget
  • Attack Techniques
    • Get an attack technique objectget
    • Get objects related to an attack techniqueget
    • Get object descriptors related to an attack techniqueget
  • Popular Threat Categories
    • Get a list of popular threat categoriesget
  • Code Insights
    • Analyse code blocks with Code Insightspost
  • Saved Searches
    • List Saved Searchesget
    • Get a Saved Searchget
    • Create a Saved Searchpost
    • Share a Saved Searchpost
    • Update a Saved Searchpatch
    • Delete a Saved Searchdel
    • Revoke access to a Saved Searchdel
    • Get object descriptors related to a Saved Searchget
    • Get objects related to a Saved Searchget

VT Enterprise

  • Search & Metadata
    • Search for files, URLs, domains, IPs and commentsget
    • Advanced corpus searchget
    • Get file content search snippetsget
    • Get VirusTotal metadataget
  • Collections
    • Create a new collectionpost
    • Get a collectionget
    • Update a collectionpatch
    • Delete a collectiondel
    • Get comments on a collectionget
    • Add a comment to a collectionpost
    • Get objects related to a collectionget
    • Get object descriptors related to a collectionget
    • Add new items to a collectionpost
    • Delete items from a collectiondel
    • 🔒 List collectionsget
    • 🔒 Export IOCs from a collectionget
    • 🔒 Export IOCs from a given collection's relationshipget
    • 🔒 Export aggregations from a collectionget
    • 🔒 Search IoCs inside a collectionget
  • Zipping files
    • Create a password-protected ZIP with VirusTotal filespost
    • Check a ZIP file’s statusget
    • Get a ZIP file’s download URLget
    • Download a ZIP fileget

VT Hunting

  • YARA Rules
    • List Crowdsourced YARA Rulesget
    • Get a Crowdsourced YARA ruleget
    • Get objects related to a Crowdsourced YARA ruleget
    • Get objects descriptors related to a Crowdsourced YARA ruleget
  • IoC Stream
    • Get objects from the IoC Streamget
    • Delete notifications from the IoC Streamdel
    • Get an IoC Stream notificationget
    • Delete an IoC Stream notificationdel
  • 🔒 Livehunt
    • Get Livehunt rulesetsget
    • Create a new Livehunt rulesetpost
    • Remove all Livehunt rulesetsdel
    • Get a Livehunt rulesetget
    • Update a Livehunt rulesetpatch
    • Check if a user or group is a Livehunt ruleset editorget
    • Revoke Livehunt ruleset edit permission from a user or groupdel
    • Delete a Livehunt rulesetdel
    • Get objects related to a Livehunt rulesetget
    • Get object descriptors related to a Livehunt rulesetget
    • Grant Livehunt ruleset edit permissions for a user or grouppost
    • Transfer Livehunt ruleset to another userpost
    • Get Livehunt notificationsget
    • Delete Livehunt notificationsdel
    • Get a Livehunt notification objectget
    • Delete a Livehunt notificationdel
    • Retrieve file objects for Livehunt notificationsget
  • 🔒 Retrohunt
    • Get a list of Retrohunt jobsget
    • Create a new Retrohunt jobpost
    • Get a Retrohunt job objectget
    • Delete a Retrohunt jobdel
    • Abort a Retrohunt jobpost
    • Retrieve matches for a Retrohunt jobget

VT GRAPH

  • VT Graphs
    • Search graphsget
    • Create a graphpost
    • Get a graph objectget
    • Update a graph objectpatch
    • Delete a graphdel
    • Get comments on a graphget
    • Add a comment to a graphpost
    • Get objects related to a graphget
    • Get object descriptors related to a graphget
  • VT Graphs Permissions & ACL
    • Get users and groups that can view a graphget
    • Grant users and groups permission to see a graphpost
    • Check if a user or group can view a graphget
    • Revoke view permission from a user or groupdel
    • Get users and groups that can edit a graphget
    • Grant users and groups permission to edit a graphpost
    • Check if a user or group can edit a graphget
    • Revoke edit graph permissions from a user or groupdel

VT Private Scanning

  • 🔒 Files
    • Upload a filepost
    • List private filesget
    • Get a URL for uploading large filesget
    • Rescan a private filepost
    • Get a private file reportget
    • Delete a private file reportdel
    • Get objects related to a private fileget
    • Get object descriptors related to a fileget
  • 🔒 Analyses
    • List private analysesget
    • Get a private analysisget
    • Get objects related to a private analysisget
    • Get object descriptors related to a private analysisget
  • 🔒 File Behaviours
    • Get a behaviour report from a private fileget
    • Get the behaviour reports from a private fileget
    • Get objects related to a private file's behaviour reportget
    • Get object descriptors related to a private file's behaviour reportget
    • Get a summary of all behavior reports for a fileget
    • Get a summary of all MITRE ATT&CK techniques observed in a fileget
    • Get a detailed HTML behaviour reportget
    • Get the EVTX file generated during a private file’s behavior analysisget
    • Get the PCAP file generated during a private file’s behavior analysisget
    • Get the memdump file generated during a private file’s behavior analysisget
  • 🔒 URLs
    • Private Scan URLpost
    • Get a URL analysis reportget
    • Get objects related to a private URLget
    • Get object descriptors related to a private URLget
  • Zipping private files
    • Create a password-protected ZIP with VirusTotal private filespost
    • Check a ZIP file’s statusget
    • Get a ZIP file’s download URLget
    • Download a ZIP fileget

VT FeedS

  • 🔒 File intelligence feed
    • Get a per-minute file feed batchget
    • Get a hourly file feed batchget
    • Download a file published in the file feedget
  • 🔒 Sandbox analyses feed
    • Get a per-minute file behaviour feed batchget
    • Get an hourly file behaviour feed batchget
    • Get the EVTX file generated during a file’s behavior analysisget
    • Get the memdump file generated during a file’s behavior analysisget
    • Get the PCAP file generated during a file’s behavior analysisget
    • Get a file behaviour's detailed HTML reportget
  • 🔒 Domain intelligence feed
    • Get a minutely domain feed batchget
    • Get an hourly domain feed batchget
  • 🔒 IP intelligence feed
    • Get a minutely IP address feed batchget
    • Get an hourly IP address feed batchget
  • 🔒 URL intelligence feed
    • Get a minutely URL feed batchget
    • Get an hourly URL feed batchget

VT ENTERPRISE ADMINISTRATION

  • User management
    • Get a user objectget
    • Update a user objectpatch
    • Delete a userdel
    • Get objects related to a userget
    • Get object descriptors related to a userget
  • Group management
    • Get a group objectget
    • Update a group objectpatch
    • Get administrators for a groupget
    • Manage Rolespatch
    • Check if a user is a group adminget
    • Get group usersget
    • Check if a user is a group memberget
    • Remove a user from a groupdel
    • Add users to a grouppost
    • Get objects related to a groupget
    • Get object descriptors related to a groupget
  • Quota management
    • Get a user’s API usageget
    • Get a group’s API usageget
    • Get a group's usage per featureget
  • Service Account Management
    • Create a new Service Accountpost
    • Get Service Accounts of a groupget
    • Get a Service Account objectget
  • Audit Log
    • Get Activity Logsget

VT Augment

  • Overview
  • Rendering
    • Get a widget rendering URLget
    • Retrieve the widget's HTML contentget
  • Theming

API Objects

  • Activity Log
  • Analyses
    • 🔀 item
  • Attack Tactics
    • 🔀 attack_techniques
  • Attack Techniques
    • 🔀 attack_tactics
    • 🔀 parent_technique
    • 🔀 revoking_technique
    • 🔀 subtechniques
    • 🔀🔒 threat_actors
  • Collections
    • 🔀 autogenerated_graphs
    • 🔀 comments
    • 🔀 domains
    • 🔀 files
    • 🔀 ip_addresses
    • 🔀 owner
    • 🔀 references
    • 🔀🔒 related_collections
    • 🔀🔒 related_references
    • 🔀🔒 threat_actors
    • 🔀 urls
  • Comments
    • 🔀 author
  • Domains
    • 🔀🔒 caa_records
    • 🔀🔒 cname_records
    • 🔀 collections
    • 🔀 comments
    • 🔀 communicating_files
    • 🔀🔒 downloaded_files
    • 🔀 graphs
    • 🔀 historical_ssl_certificates
    • 🔀 historical_whois
    • 🔀 immediate_parent
    • 🔀🔒 mx_records
    • 🔀🔒 ns_records
    • 🔀 parent
    • 🔀 referrer_files
    • 🔀 related_comments
    • 🔀🔒 related_references
    • 🔀🔒 related_threat_actors
    • 🔀 resolutions
    • 🔀 siblings
    • 🔀🔒 soa_records
    • 🔀 subdomains
    • 🔀🔒 urls
    • 🔀🧑‍💻 user_votes
    • 🔀 votes
  • Files
    • androguard
    • asf_info
    • authentihash
    • bundle_info
    • class_info
    • crowdsourced_ids_results
    • crowdsourced_ids_stats
    • crowdsourced_yara_results
    • deb_info
    • detectiteasy
    • dmg_info
    • dot_net_assembly
    • dot_net_guids
    • elf_info
    • 🔒 exiftool
    • html_info
    • image_code_injections
    • ipa_info
    • isoimage_info
    • jar_info
    • javascript_info
    • known_distributors
    • lnk_info
    • macho_info
    • magic
    • 🔒 malware_config
    • monitor_info
    • nsrl_info
    • 🔒 office_info
    • 🔒 openxml_info
    • packers
    • password_info
    • pdf_info
    • pe_info
    • popular_threat_classification
    • powershell_info
    • rombios_info
    • 🔒 rtf_info
    • sandbox_verdicts
    • sigma_analysis_results
    • sigma_analysis_stats
    • signature_info
    • snort
    • suricata
    • ssdeep
    • swf_info
    • telfhash
    • tlsh
    • traffic_inspection
    • trid
    • vba_info
    • wireshark
    • 🔀🔒 analyses
    • 🔀 behaviours
    • 🔀 bundled_files
    • 🔀🔒 carbonblack_children
    • 🔀🔒 carbonblack_parents
    • 🔀 collections
    • 🔀 comments
    • 🔀🔒 compressed_parents
    • 🔀 contacted_domains
    • 🔀 contacted_ips
    • 🔀 contacted_urls
    • 🔀 dropped_files
    • 🔀🔒 email_attachments
    • 🔀🔒 email_parents
    • 🔀🔒 embedded_domains
    • 🔀🔒 embedded_ips
    • 🔀🔒 embedded_urls
    • 🔀 execution_parents
    • 🔀 graphs
    • 🔀🔒 itw_domains
    • 🔀🔒 itw_ips
    • 🔀🔒 itw_urls
    • 🔀🔒 overlay_children
    • 🔀🔒 overlay_parents
    • 🔀🔒 pcap_children
    • 🔀🔒 pcap_parents
    • 🔀 pe_resource_children
    • 🔀 pe_resource_parents
    • 🔀🔒 related_references
    • 🔀🔒 related_threat_actors
    • 🔀🔒 screenshots
    • 🔀 sigma_analysis
    • 🔀🔒 similar_files
    • 🔀🔒 submissions
    • 🔀🔒 urls_for_embedded_js
    • 🔀🧑‍💻 user_votes
    • 🔀 votes
    • 🔀 memory_pattern_domains
    • 🔀 memory_pattern_ips
    • 🔀 memory_pattern_urls
  • Files Behaviour
    • dns_lookups
    • files_copied
    • files_dropped
    • http_conversations
    • ip_traffic
    • permissions_checked
    • processes_tree
    • sms_sent
    • tags
    • verdicts
    • 🔀 file
    • 🔀 attack_techniques
  • Graphs
    • 🔀 comments
    • 🔀 editors
    • 🔀 group
    • 🔀 items
    • 🔀 owner
    • 🔀 viewers
  • Groups
    • 🔀🧑‍💻 administrators
    • 🔀🧑‍💻 graphs
    • 🔀🧑‍💻 users
  • Hunting Notifications
  • Hunting Rulesets
    • 🔀 🧑‍💻owner
    • 🔀🧑‍💻 editors
    • 🔀🧑‍💻 viewers
    • 🔀🧑‍💻 hunting_notification_files
  • IoC-Stream Notifications
  • IP addresses
    • 🔀 collections
    • 🔀 comments
    • 🔀 communicating_files
    • 🔀🔒 downloaded_files
    • 🔀 graphs
    • 🔀 historical_ssl_certificates
    • 🔀 historical_whois
    • 🔀 related_comments
    • 🔀🔒 related_references
    • 🔀🔒 related_threat_actors
    • 🔀 referrer_files
    • 🔀 resolutions
    • 🔀🔒 urls
    • 🔀🧑‍💻 user_votes
    • 🔀 votes
  • Operations
  • 🔒 Private Analyses
    • 🔀 item
    • 🔀 submitter
  • 🔒 Private Files
    • 🔀 behaviours
    • 🔀 dropped_files
    • 🔀 execution_parents
    • 🔀 embedded_urls
    • 🔀 embedded_domains
    • 🔀 embedded_ips
  • 🔒 Private Files Behaviours
    • 🔀 attack_techniques
    • 🔀 file
  • 🔒 Private URLs
  • 🔒 Private URLs Behaviours
  • Resolutions
  • Retrohunt Jobs
    • 🔀🧑‍💻 matching_files
    • 🔀🧑‍💻 owner
  • Screenshots
  • Sigma Analyses
    • 🔀 rules
  • Sigma Rules
  • SSL Certificate
  • Submissions
  • URLs
    • 🔀🔒 analyses
    • 🔀 collections
    • 🔀 comments
    • 🔀🔒 communicating_files
    • 🔀🔒 contacted_domains
    • 🔀🔒 contacted_ips
    • 🔀🔒 downloaded_files
    • 🔀🔒 embedded_js_files
    • 🔀 graphs
    • 🔀 last_serving_ip_address
    • 🔀 network_location
    • 🔀🔒 redirecting_urls
    • 🔀🔒 redirects_to
    • 🔀🔒 referrer_files
    • 🔀🔒 referrer_urls
    • 🔀 related_comments
    • 🔀🔒 related_references
    • 🔀🔒 related_threat_actors
    • 🔀🔒 submissions
    • 🔀🧑‍💻 user_votes
    • 🔀 votes
    • 🔀🔒 urls_related_by_tracker_id
  • Users
    • 🔀🧑‍💻 api_quota_group
    • 🔀 collections
    • 🔀 comments
    • 🔀 graphs
    • 🔀🧑‍💻 groups
    • 🔀🧑‍💻 hunting_rulesets
    • 🔀🧑‍💻 hunting_notifications
    • 🔀🧑‍💻 hunting_notification_files
    • 🔀🧑‍💻 intelligence_quota_group
    • 🔀 mentions
    • 🔀🧑‍💻 retrohunt_jobs
    • 🔀 votes
  • Saved Searches
  • Service Accounts
    • 🔀🧑‍💻 api_quota_group
    • 🔀 comments
    • 🔀🧑‍💻 groups
    • 🔀🧑‍💻 intelligence_quota_group
    • 🔀 mentions
  • Votes
  • Whois
  • YARA Rules
  • YARA Rulesets

VT Monitor

  • Software Publishers
    • Monitor Items
    • Get a list of MonitorItem objects by path or tagget
    • Upload a file or create a new folderpost
    • Get a URL for uploading files larger than 32MBget
    • Get attributes and metadata for a specific MonitorItemget
    • Delete a VirusTotal Monitor file or folderdel
    • Configure a given VirusTotal Monitor item (file or folder)patch
    • Download a file in VirusTotal Monitorget
    • Get a URL for downloading a file in VirusTotal Monitorget
    • Get the latest file analysesget
    • Get user owning the MonitorItem objectget
    • Retrieve partner's comments on a fileget
    • Retrieve statistics about analyses performed on your software collectionget
    • Retrieve historical events about your software collectionget
  • Antivirus Partners
    • Get a list of MonitorHashes detected by an engineget
    • Get a list of analyses for a fileget
    • Get a list of items with a given sha256 hashget
    • Create a comment over a hashpost
    • Get comments on a sha256 hashget
    • Add a comment on a sha256 hashpatch
    • Remove a comment detection for a hash.del
    • Download a file with a given sha256 hashget
    • Retrieve a download url for a file with a given sha256 hashget
    • Download a daily detection bundle directlyget
    • Get a daily detection bundle download URLget
    • Get a list of MonitorHashes detected by an engineget

🔒 Retrohunt

🚧

Special privileges required

This endpoint is only available for users with premium privileges.

Updated 7 months ago


Retrieve file objects for Livehunt notifications
Get a list of Retrohunt jobs

Updated 7 months ago


Retrieve file objects for Livehunt notifications
Get a list of Retrohunt jobs