NEW Workflow v2 · the multi-agent verification layer is live
All apps

Virustotal

security & identity tools 16 tools available

VirusTotal is a free online service that analyzes files and URLs for viruses, worms, trojans, and other kinds of malicious content using multiple antivirus engines and website scanners.

About this integration

Connect Virustotal to Definable to automate repetitive tasks, sync data with the rest of your stack, trigger on real-world events. Personas call Virustotal's 16 tools directly from chat or scheduled flows. You can wire it into any persona to read, write, and react when an event fires.

Connect Virustotal to Definable and it becomes a set of typed tools your agents plan with — triggered by events, run on schedules, or invoked mid-conversation. Every write is checked by the verifier before it lands.

Auth OAuth2 · 2 clicks
Tools 16 exposed
Plans All, incl. Free
Data Never trained on

Virustotal · in workflows

What teams actually run.

Three patterns teams run with Virustotal on day one. Each one is a plain-English prompt — no canvas, no glue code — and you can remix them into anything.

01

Trigger on event

Listen for a new event
Parse and validate the payload
Take an action with the linked tool
02

Daily summary

Pull yesterday's activity
Summarise with the model of your choice
Send the digest via email or Slack
03

Cross-tool sync

Read records from one app
Transform with a persona
Write the result back via this integration

16 tools available

The Virustotal toolbox.

Every Virustotal capability your agents can call, each with a typed schema the planner reads. The router picks the right tool per step; the verifier checks the result.

Add VirusTotal Comment

Tool to add a comment to a VirusTotal resource (file, URL, domain, or IP address). Use after analyzing a resource to leave contextual feedback. Provide exactly one identifier per call.

Add Vote

Tool to add a vote (harmless/malicious) to a VirusTotal resource. Use after reviewing analysis results to submit your verdict.

Get Analysis Report

Tool to retrieve the analysis report of a file or URL submission. Use after obtaining an analysis ID to fetch its detailed report. Analysis results may be incomplete immediately after submission; poll until the report status is 'completed' before treating results as final.

Get comments

Tool to retrieve the latest comments on a VirusTotal resource. Use when you need to review user-generated comments for a file, URL, domain, or IP after obtaining its identifier.

Get Domain Relationships

Tool to retrieve relationship objects for a given domain. Use when you have a domain and need to explore its related entities.

Get Domain Report

Tool to retrieve the analysis report of a domain. Use when you need detailed insight on a domain's reputation and analysis stats. No malicious signals on obscure or low-traffic domains may indicate limited analysis history rather than safety — treat sparse results as 'unknown', not 'safe'. Covers external OSINT only (reputation, malware, SSL posture); cannot analyze internal/private assets.

Get File Report

Tool to retrieve the analysis report of a file. Use when you have a file's hash and need detailed scan metadata. Recently submitted files may return partial results; retry after a short delay before treating the report as final.

Get IP Address Relationships

Tool to retrieve objects related to a specific IP address by relationship type. Use when you have an IP and need to explore connected files, URLs, or other entities.

Get IP Address Report

Tool to retrieve the analysis report of an IP address. Use when you need detailed insight on an IP's reputation, ASN, country, and analysis stats. Low or zero detections indicate unknown risk, not safety — treat sparse data accordingly. Provides external OSINT only; insufficient as standalone compliance evidence.

Get VirusTotal Metadata

Tool to retrieve VirusTotal metadata. Use when you need information about available privileges, relationships between resources (like files, domains, IPs, URLs), and supported antivirus engines.

Get URL Report

Tool to retrieve the analysis report of a URL. Use when you have a URL identifier (base64-url without padding) and need detailed scan results, reputation, and metadata. Results may be incomplete immediately after submission; retry with short delays if scan engines are still processing before treating the report as final.

Get Votes

Tool to retrieve votes on files, URLs, domains, or IP addresses. Use when you need to view community votes for a given object.

Rescan File

Tool to re-analyze a previously submitted file. Use when you need updated analysis results after an initial scan.

Scan URL

Tool to submit a URL for scanning. Use when you have a URL and need to submit it to VirusTotal to obtain an analysis ID for later retrieval. The returned analysis ID is preliminary — scanning engines may not have finished. Poll VIRUSTOTAL_GET_URL_REPORT with the ID using short delays to retrieve complete results.

Search VirusTotal

Tool to search for objects in the VirusTotal database. Use when locating files, URLs, domains, IPs, or comments matching a query. Supports pagination with limit and cursor.

Upload File

Tool to upload a file for scanning. Use when you have binary file content ready to submit for VirusTotal analysis.

See it run

One prompt, start to finish.

A real prompt, the Virustotal tools it calls, and what comes back. This is the whole interface — describe the outcome, agents handle the rest.

Run a real Virustotal task end-to-end — plan it, execute across the API, and hand back a verified result.

virustotal.add_virustotal_comment Tool to add a comment to a VirusTotal resource (file, URL, domain, or IP address). Use aft
virustotal.add_vote Tool to add a vote (harmless/malicious) to a VirusTotal resource. Use after reviewing anal
virustotal.get_analysis_report Tool to retrieve the analysis report of a file or URL submission. Use after obtaining an a · verified
done

Done. Virustotal responded across 3 calls, the verifier signed off, and the result is logged with every payload.

FAQ · Virustotal

Questions, answered.

What teams ask before connecting Virustotal.

01 What can I automate with Virustotal on Definable?

Anything Virustotal exposes through its API. Common security & identity tools workflows on Definable include automate repetitive tasks, sync data with the rest of your stack, trigger on real-world events. Personas can call any of the 16 Virustotal tools directly, then chain the result into another integration without you writing code.

02 How does Virustotal authentication work?

Virustotal uses API_KEY on Definable. You connect once from the integrations page, scoped to the permissions you choose, and from then on any persona that has the integration enabled can act on your behalf. Tokens are encrypted at rest and rotated automatically.

03 Is the Virustotal integration included in my Definable plan?

Yes — every Definable plan, including Starter, includes access to all 16 Virustotal tools. You only need a separate Virustotal subscription if Virustotal itself charges per seat or per API call.

04 Is using Virustotal through Definable secure?

Every call from a persona to Virustotal is logged with the user, persona, prompt, and response. Tokens never leave Definable's secrets vault, scopes are configurable per persona, and you can revoke access at any time from the integration page.

05 How do I get started with Virustotal on Definable?

Sign up for Definable, open the integrations page, find Virustotal, and connect via OAuth or API key. You can immediately attach Virustotal to any persona and start running workflows. The free Starter plan includes 5,000 credits/month.

06 What Virustotal actions does Definable expose?

Definable exposes all 16 Virustotal actions as callable tools — including `Add VirusTotal Comment`, `Add Vote`, `Get Analysis Report`, plus 13 more. Each tool gets a typed parameter schema so personas know exactly how to call it.

Put Virustotal to work tonight.

Connect in two clicks, describe an outcome, and your first workflow is live in minutes. Free plan included — no card required.

← All apps