Virustotal
security & identity tools 16 tools availableVirusTotal is a free online service that analyzes files and URLs for viruses, worms, trojans, and other kinds of malicious content using multiple antivirus engines and website scanners.
About this integration
Connect Virustotal to Definable to automate repetitive tasks, sync data with the rest of your stack, trigger on real-world events. Personas call Virustotal's 16 tools directly from chat or scheduled flows. You can wire it into any persona to read, write, and react when an event fires.
Connect Virustotal to Definable and it becomes a set of typed tools your agents plan with — triggered by events, run on schedules, or invoked mid-conversation. Every write is checked by the verifier before it lands.
Virustotal · in workflows
What teams actually run.
Three patterns teams run with Virustotal on day one. Each one is a plain-English prompt — no canvas, no glue code — and you can remix them into anything.
Daily summary
Cross-tool sync
16 tools available
The Virustotal toolbox.
Every Virustotal capability your agents can call, each with a typed schema the planner reads. The router picks the right tool per step; the verifier checks the result.
Add VirusTotal Comment Tool to add a comment to a VirusTotal resource (file, URL, domain, or IP address). Use after analyzing a resource to leave contextual feedback. Provide exactly one identifier per call.
Add Vote Tool to add a vote (harmless/malicious) to a VirusTotal resource. Use after reviewing analysis results to submit your verdict.
Get Analysis Report Tool to retrieve the analysis report of a file or URL submission. Use after obtaining an analysis ID to fetch its detailed report. Analysis results may be incomplete immediately after submission; poll until the report status is 'completed' before treating results as final.
Get comments Tool to retrieve the latest comments on a VirusTotal resource. Use when you need to review user-generated comments for a file, URL, domain, or IP after obtaining its identifier.
Get Domain Relationships Tool to retrieve relationship objects for a given domain. Use when you have a domain and need to explore its related entities.
Get Domain Report Tool to retrieve the analysis report of a domain. Use when you need detailed insight on a domain's reputation and analysis stats. No malicious signals on obscure or low-traffic domains may indicate limited analysis history rather than safety — treat sparse results as 'unknown', not 'safe'. Covers external OSINT only (reputation, malware, SSL posture); cannot analyze internal/private assets.
Get File Report Tool to retrieve the analysis report of a file. Use when you have a file's hash and need detailed scan metadata. Recently submitted files may return partial results; retry after a short delay before treating the report as final.
Get IP Address Relationships Tool to retrieve objects related to a specific IP address by relationship type. Use when you have an IP and need to explore connected files, URLs, or other entities.
Get IP Address Report Tool to retrieve the analysis report of an IP address. Use when you need detailed insight on an IP's reputation, ASN, country, and analysis stats. Low or zero detections indicate unknown risk, not safety — treat sparse data accordingly. Provides external OSINT only; insufficient as standalone compliance evidence.
Get VirusTotal Metadata Tool to retrieve VirusTotal metadata. Use when you need information about available privileges, relationships between resources (like files, domains, IPs, URLs), and supported antivirus engines.
Get URL Report Tool to retrieve the analysis report of a URL. Use when you have a URL identifier (base64-url without padding) and need detailed scan results, reputation, and metadata. Results may be incomplete immediately after submission; retry with short delays if scan engines are still processing before treating the report as final.
Get Votes Tool to retrieve votes on files, URLs, domains, or IP addresses. Use when you need to view community votes for a given object.
Rescan File Tool to re-analyze a previously submitted file. Use when you need updated analysis results after an initial scan.
Scan URL Tool to submit a URL for scanning. Use when you have a URL and need to submit it to VirusTotal to obtain an analysis ID for later retrieval. The returned analysis ID is preliminary — scanning engines may not have finished. Poll VIRUSTOTAL_GET_URL_REPORT with the ID using short delays to retrieve complete results.
Search VirusTotal Tool to search for objects in the VirusTotal database. Use when locating files, URLs, domains, IPs, or comments matching a query. Supports pagination with limit and cursor.
Upload File Tool to upload a file for scanning. Use when you have binary file content ready to submit for VirusTotal analysis.
See it run
One prompt, start to finish.
A real prompt, the Virustotal tools it calls, and what comes back. This is the whole interface — describe the outcome, agents handle the rest.
Run a real Virustotal task end-to-end — plan it, execute across the API, and hand back a verified result.
virustotal.add_virustotal_comment Tool to add a comment to a VirusTotal resource (file, URL, domain, or IP address). Use aft virustotal.add_vote Tool to add a vote (harmless/malicious) to a VirusTotal resource. Use after reviewing anal virustotal.get_analysis_report Tool to retrieve the analysis report of a file or URL submission. Use after obtaining an a · verified Done. Virustotal responded across 3 calls, the verifier signed off, and the result is logged with every payload.
FAQ · Virustotal
Questions, answered.
What teams ask before connecting Virustotal.
01 What can I automate with Virustotal on Definable?
Anything Virustotal exposes through its API. Common security & identity tools workflows on Definable include automate repetitive tasks, sync data with the rest of your stack, trigger on real-world events. Personas can call any of the 16 Virustotal tools directly, then chain the result into another integration without you writing code.
02 How does Virustotal authentication work?
Virustotal uses API_KEY on Definable. You connect once from the integrations page, scoped to the permissions you choose, and from then on any persona that has the integration enabled can act on your behalf. Tokens are encrypted at rest and rotated automatically.
03 Is the Virustotal integration included in my Definable plan?
Yes — every Definable plan, including Starter, includes access to all 16 Virustotal tools. You only need a separate Virustotal subscription if Virustotal itself charges per seat or per API call.
04 Is using Virustotal through Definable secure?
Every call from a persona to Virustotal is logged with the user, persona, prompt, and response. Tokens never leave Definable's secrets vault, scopes are configurable per persona, and you can revoke access at any time from the integration page.
05 How do I get started with Virustotal on Definable?
Sign up for Definable, open the integrations page, find Virustotal, and connect via OAuth or API key. You can immediately attach Virustotal to any persona and start running workflows. The free Starter plan includes 5,000 credits/month.
06 What Virustotal actions does Definable expose?
Definable exposes all 16 Virustotal actions as callable tools — including `Add VirusTotal Comment`, `Add Vote`, `Get Analysis Report`, plus 13 more. Each tool gets a typed parameter schema so personas know exactly how to call it.
Put Virustotal to work tonight.
Connect in two clicks, describe an outcome, and your first workflow is live in minutes. Free plan included — no card required.