# VirusTotal Documentation > VirusTotal's developers hub, the place to learn about VirusTotal's public and private APIs in order to programmatically scan files, check URLs, discover malicious domains, etc. ## Guides - [How it works](https://virustotal.readme.io/docs/how-it-works.md) - [Join Community](https://virustotal.readme.io/docs/community.md) - [Contributors](https://virustotal.readme.io/docs/contributors.md) - [Comments](https://virustotal.readme.io/docs/comments.md) - [Historic Terms of Service](https://virustotal.readme.io/docs/historic-terms-of-service.md) - [Historic Privacy Policy](https://virustotal.readme.io/docs/historic-privacy-policy.md) - [Configure SAML with Okta](https://virustotal.readme.io/docs/saml-okta.md) - [Configure SAML with Ping](https://virustotal.readme.io/docs/saml-ping.md) - [Configure SAML with Entra ID](https://virustotal.readme.io/docs/saml-entraid.md) - [Single Sign On Authentication ](https://virustotal.readme.io/docs/sso-authentication.md) - [Searching for users](https://virustotal.readme.io/docs/user-searching.md) - [Walkthrough guide for VirusTotal group administrators](https://virustotal.readme.io/docs/admins-guide.md) - [Service Accounts](https://virustotal.readme.io/docs/service-account.md) - [Understanding Consumption](https://virustotal.readme.io/docs/quota-consumption.md) - [API Overview](https://virustotal.readme.io/docs/api-overview.md) - [VirusTotal Intelligence Introduction](https://virustotal.readme.io/docs/virustotal-intelligence-introduction.md) - [Searching](https://virustotal.readme.io/docs/searching.md) - [File search modifiers](https://virustotal.readme.io/docs/file-search-modifiers.md) - [IP address search modifiers](https://virustotal.readme.io/docs/ip-address-search-modifiers.md) - [Domain search modifiers](https://virustotal.readme.io/docs/domain-search-modifiers.md) - [URL search modifiers](https://virustotal.readme.io/docs/url-search-modifiers.md) - [File - List of Engines](https://virustotal.readme.io/docs/list-file-engines.md): Identifying files according to antivirus detections - [Netloc - List of engines](https://virustotal.readme.io/docs/list-netloc-engines.md) - [Full list of VirusTotal Intelligence search modifiers](https://virustotal.readme.io/docs/search-modifiers-full-list.md) - [Full list of VirusTotal Intelligence tag modifier](https://virustotal.readme.io/docs/intelligence-tag-list.md) - [Full list of VirusTotal Intelligence behaviour_tags modifier](https://virustotal.readme.io/docs/list-behaviour-tag-modifiers.md) - [Collection search modifiers](https://virustotal.readme.io/docs/collection-search-modifiers.md) - [File similarity search](https://virustotal.readme.io/docs/file-similarity-search.md) - [Content search (VTGrep)](https://virustotal.readme.io/docs/vtgrep.md) - [Searching using entities](https://virustotal.readme.io/docs/searching-entities.md) - [VirusTotal Collections Introduction](https://virustotal.readme.io/docs/collections-introduction.md) - [Saved Searches](https://virustotal.readme.io/docs/saved-searches-guide.md) - [In-house Sandboxes - behavioural analysis products](https://virustotal.readme.io/docs/in-house-sandboxes.md) - [External behavioural engines sandboxes](https://virustotal.readme.io/docs/external-sandboxes.md) - [Reports](https://virustotal.readme.io/docs/results-reports.md) - [Full list of File object attritbutes](https://virustotal.readme.io/docs/file-attributes-full-list.md) - [What's VT Hunting?](https://virustotal.readme.io/docs/whats-vthunting.md) - [Sources Subscriptions](https://virustotal.readme.io/docs/ioc-stream-sources-subscriptions.md) - [Threat Feeds](https://virustotal.readme.io/docs/ioc-stream-threat-feeds.md) - [Livehunt](https://virustotal.readme.io/docs/livehunt.md) - [File hunting: Writing YARA rules for Livehunt](https://virustotal.readme.io/docs/writing-yara-rules-for-livehunt.md) - [Network hunting: Writing YARA rules for Livehunt](https://virustotal.readme.io/docs/nethunt.md): Network hunting using YARA - [Examples of network hunting using Livehunt](https://virustotal.readme.io/docs/nethunt-examples.md): Examples of network hunting using Livehunt - [Retrohunt](https://virustotal.readme.io/docs/retrohunt.md) - [Crowdsourced IDS Rules](https://virustotal.readme.io/docs/crowdsourced-ids-rules.md) - [Crowdsourced YARA Rules](https://virustotal.readme.io/docs/crowdsourced-yara-rules.md) - [Crowdsourced YARA rules dashboard](https://virustotal.readme.io/docs/crowdsourced-yara-rules-dashboard.md) - [Sigma rules](https://virustotal.readme.io/docs/crowdsourced-sigma-rules.md) - [VTDIFF - Automatic YARA rules](https://virustotal.readme.io/docs/vtdiff-automatic-yara-rules.md) - [Introduction](https://virustotal.readme.io/docs/graph-documentation.md) - [Overview](https://virustotal.readme.io/docs/graph-overview.md) - [Search and start new investigation](https://virustotal.readme.io/docs/graph-search.md) - [Management](https://virustotal.readme.io/docs/graph-management.md) - [Nodes](https://virustotal.readme.io/docs/graph-nodes.md) - [Commonalities and Hunting](https://virustotal.readme.io/docs/graph-commonalities.md) - [Private Scanning](https://virustotal.readme.io/docs/private-scanning.md) - [OpenVPN support on private scanning](https://virustotal.readme.io/docs/openvpn-support-on-private-scanning.md) - [Integrations](https://virustotal.readme.io/docs/integrations.md): Get VirusTotal enrichment, threat and adversary intelligence in third party vendors. - [VT4Splunk, official VirusTotal app for Splunk](https://virustotal.readme.io/docs/vt4splunk-guide.md): Configuration and use guide - [Connectors](https://virustotal.readme.io/docs/connectors.md): Show data from third party vendors on VirusTotal - [Splunk](https://virustotal.readme.io/docs/splunk-connector.md): Splunk connector guide for VirusTotal - [Mandiant Advantage - Threat Intelligence](https://virustotal.readme.io/docs/mandiant-connector.md): Mandiant connector guide for VirusTotal - [MISP](https://virustotal.readme.io/docs/misp-connector.md): MISP connector guide for VirusTotal - [List of VT Integrations](https://virustotal.readme.io/docs/technology-integrations-list.md) - [Tools overview](https://virustotal.readme.io/docs/tools-overview.md) - [Desktop Apps](https://virustotal.readme.io/docs/desktop-apps.md) - [Mobile Apps](https://virustotal.readme.io/docs/mobile-apps.md) - [Browser Extensions](https://virustotal.readme.io/docs/browser-extensions.md) - [VT4Browsers + Google TI](https://virustotal.readme.io/docs/vt4browsers.md) - [API Scripts and client libraries](https://virustotal.readme.io/docs/api-scripts-and-client-libraries.md) - [Batch file downloads](https://virustotal.readme.io/docs/batch-file-downloads.md) - [VT Bot](https://virustotal.readme.io/docs/bot-overview.md) - [Frequently Asked Questions](https://virustotal.readme.io/docs/virustotal-faq.md) - [Please give me an API key](https://virustotal.readme.io/docs/please-give-me-an-api-key.md) - [How consumption quotas are handled](https://virustotal.readme.io/docs/consumption-quotas-handled.md) - [How can I have access to a higher quota?](https://virustotal.readme.io/docs/higher-quota.md) - [What is the difference between the public API and the private API?](https://virustotal.readme.io/docs/difference-public-private.md) - [What kind of files will VirusTotal scan?](https://virustotal.readme.io/docs/file-types.md) - [I accidentally uploaded a file with confidential or sensitive information to VirusTotal, can you please delete it?](https://virustotal.readme.io/docs/accidental-upload.md) - [Should I upload files larger than 650MBs ?](https://virustotal.readme.io/docs/large-files.md) - [Empty file and VirusTotal uploads](https://virustotal.readme.io/docs/empty-file.md) - [How can I link to the most recent report on a given file or URL?](https://virustotal.readme.io/docs/most-recent-report.md) - [How can I automate scans?](https://virustotal.readme.io/docs/automate-scans.md) - [File from a URL scan was not enqueued for antivirus scanning](https://virustotal.readme.io/docs/file-not-enqueued.md) - [What type of files are supported by code insight?](https://virustotal.readme.io/docs/codeinsight-supported-files.md) - [What type of compressed files are supported?](https://virustotal.readme.io/docs/compressed-files.md) - [Why does my signed file appear as "not signed" on VirusTotal?](https://virustotal.readme.io/docs/why-does-my-signed-file-appear-as-not-signed-on-virustotal.md): I have a file that appears to be digitally signed on my Windows system, but VirusTotal's "Details" tab reports it as "File is not signed." Why is there a discrepancy? - [AV product on VirusTotal detects a file and its equivalent commercial version does not](https://virustotal.readme.io/docs/antivirus-verdict-differs.md) - [URL scanner verdict differ from its corresponding antivirus solution](https://virustotal.readme.io/docs/urlscanner-differs.md) - [I am experiencing a false positive, my file or site should not be detected.](https://virustotal.readme.io/docs/false-positive.md) - [What does the green circle with a white tick mark icon mean?](https://virustotal.readme.io/docs/antivirus-greencircle.md) - [Why don't you have statistics comparing antivirus performance?](https://virustotal.readme.io/docs/antivirus-stats.md) - [Intelligence - How do I search for malware detected as X](https://virustotal.readme.io/docs/malware-search.md) - [What is YARA?](https://virustotal.readme.io/docs/what-is-yara.md) - [How does VTDiff work?](https://virustotal.readme.io/docs/how-does-vtdiff-work.md) - [Error - "Need to give exclusion list for filetype"](https://virustotal.readme.io/docs/vtdiff-filetype-exclusion.md) - [When is an analysis included in the feeds?](https://virustotal.readme.io/docs/when-analysis-feeds.md) - [I lost access to my authentication device/offline codes for 2FA](https://virustotal.readme.io/docs/lost-access-2fa.md) ## API Reference - [VirusTotal API v3 Overview](https://virustotal.readme.io/reference/overview.md) - [Public vs Premium API](https://virustotal.readme.io/reference/public-vs-premium-api.md) - [Getting started](https://virustotal.readme.io/reference/getting-started.md) - [Authentication](https://virustotal.readme.io/reference/authentication.md) - [API responses](https://virustotal.readme.io/reference/api-responses.md) - [Errors](https://virustotal.readme.io/reference/errors.md) - [Key concepts](https://virustotal.readme.io/reference/key-concepts.md) - [Objects](https://virustotal.readme.io/reference/objects.md) - [Collections](https://virustotal.readme.io/reference/collections.md) - [Relationships](https://virustotal.readme.io/reference/relationships.md) - [Legend](https://virustotal.readme.io/reference/doc-legends.md) - [API v2 to v3 Migration Guide](https://virustotal.readme.io/reference/api-v2-v3-migration-guide.md) - [Get an IP address report](https://virustotal.readme.io/reference/ip-info.md) - [Request an IP address (re)scan](https://virustotal.readme.io/reference/rescan-ip.md): Reanalyse an IP address already in VirusTotal - [Get comments on an IP address](https://virustotal.readme.io/reference/ip-comments-get.md) - [Add a comment to an IP address](https://virustotal.readme.io/reference/ip-comments-post.md) - [Get objects related to an IP address](https://virustotal.readme.io/reference/ip-relationships.md) - [Get object descriptors related to an IP address](https://virustotal.readme.io/reference/ip-relationships-ids.md) - [Get votes on an IP address](https://virustotal.readme.io/reference/ip-votes.md) - [Add a vote to an IP address](https://virustotal.readme.io/reference/ip-votes-post.md) - [Get a domain report](https://virustotal.readme.io/reference/domain-info.md) - [Request an domain (re)scan](https://virustotal.readme.io/reference/domains-rescan.md): Reanalyse a domain already in VirusTotal - [Get comments on a domain](https://virustotal.readme.io/reference/domains-comments-get.md) - [Add a comment to a domain](https://virustotal.readme.io/reference/domains-comments-post.md) - [Get objects related to a domain](https://virustotal.readme.io/reference/domains-relationships.md) - [Get object descriptors related to a domain](https://virustotal.readme.io/reference/domains-relationships-ids.md) - [Get a DNS resolution object](https://virustotal.readme.io/reference/get-resolution-by-id.md) - [Get votes on a domain](https://virustotal.readme.io/reference/domains-votes-get.md) - [Add a vote to a domain](https://virustotal.readme.io/reference/domain-votes-post.md) - [Files](https://virustotal.readme.io/reference/file.md) - [Upload a file](https://virustotal.readme.io/reference/files-scan.md): Upload and analyse a file > πŸ“˜ File size If the file to be uploaded is bigger than 32MB, please use the [/files/upload_url](ref:files-upload-url) endpoint instead which admits files up to 650MB. - [Get a URL for uploading large files](https://virustotal.readme.io/reference/files-upload-url.md): Get a URL for uploading files larger than 32MB - [Get a file report](https://virustotal.readme.io/reference/file-info.md): Retrieve information about a file - [Request a file rescan (re-analyze)](https://virustotal.readme.io/reference/files-analyse.md): Reanalyse a file already in VirusTotal - [Get a file’s download URL](https://virustotal.readme.io/reference/files-download-url.md) - [Download a file](https://virustotal.readme.io/reference/files-download.md) - [Get comments on a file](https://virustotal.readme.io/reference/files-comments-get.md) - [Add a comment to a file](https://virustotal.readme.io/reference/files-comments-post.md) - [Get objects related to a file](https://virustotal.readme.io/reference/files-relationships.md) - [Get object descriptors related to a file](https://virustotal.readme.io/reference/files-relationships-ids.md) - [Get a crowdsourced Sigma rule object](https://virustotal.readme.io/reference/get-sigma-rules.md) - [Get a crowdsourced YARA ruleset](https://virustotal.readme.io/reference/get-yara-rulesets.md): Yara Ruleset used in our crowdsourced YARA results. - [Get votes on a file](https://virustotal.readme.io/reference/files-votes-get.md) - [Add a vote on a file](https://virustotal.readme.io/reference/files-votes-post.md) - [Get a summary of all behavior reports for a file](https://virustotal.readme.io/reference/file-all-behaviours-summary.md) - [Get a summary of all MITRE ATT&CK techniques observed in a file](https://virustotal.readme.io/reference/get-a-summary-of-all-mitre-attck-techniques-observed-in-a-file.md) - [Get all behavior reports for a file](https://virustotal.readme.io/reference/get-all-behavior-reports-for-a-file.md) - [Get a file behavior report from a sandbox](https://virustotal.readme.io/reference/get-file-behaviour-id.md) - [Get objects related to a behaviour report](https://virustotal.readme.io/reference/get-file-behaviours-relationship.md) - [Get object descriptors related to a behaviour report](https://virustotal.readme.io/reference/get-file-behaviours-relationship-descriptor.md) - [Get a detailed HTML behaviour report](https://virustotal.readme.io/reference/get-file-behaviours-html.md): HTML sandbox report - [Get the EVTX file generated during a file’s behavior analysis](https://virustotal.readme.io/reference/get-file-behaviours-evtx.md) - [Get the PCAP file generated during a file’s behavior analysis](https://virustotal.readme.io/reference/get-file-behaviours-pcap.md) - [Get the memdump file generated during a file’s behavior analysis](https://virustotal.readme.io/reference/get-file-behaviours-memdump.md) - [URLs](https://virustotal.readme.io/reference/url.md) - [Scan URL](https://virustotal.readme.io/reference/scan-url.md) - [Get a URL report](https://virustotal.readme.io/reference/url-info.md) - [Request a URL rescan (re-analyze)](https://virustotal.readme.io/reference/urls-analyse.md) - [Get comments on a URL](https://virustotal.readme.io/reference/urls-comments-get.md) - [Add a comment on a URL](https://virustotal.readme.io/reference/urls-comments-post.md) - [Get objects related to a URL](https://virustotal.readme.io/reference/urls-relationships.md) - [Get object descriptors related to a URL](https://virustotal.readme.io/reference/urls-relationships-ids.md) - [Get votes on a URL](https://virustotal.readme.io/reference/urls-votes-get.md) - [Add a vote on a URL](https://virustotal.readme.io/reference/urls-votes-post.md) - [Comments](https://virustotal.readme.io/reference/comments-api.md) - [Get latest comments](https://virustotal.readme.io/reference/get-comments.md) - [Get a comment object](https://virustotal.readme.io/reference/get-comment.md) - [Delete a comment](https://virustotal.readme.io/reference/comment-id-delete.md) - [Get objects related to a comment](https://virustotal.readme.io/reference/comments-relationships.md) - [Get object descriptors related to a comment](https://virustotal.readme.io/reference/comments-relationships-ids.md) - [Add a vote to a comment](https://virustotal.readme.io/reference/vote-comment.md) - [Get a URL / file analysis](https://virustotal.readme.io/reference/analysis.md) - [Get objects related to an analysis](https://virustotal.readme.io/reference/analyses-get-objects.md) - [Get object descriptors related to an analysis](https://virustotal.readme.io/reference/analyses-get-descriptors.md) - [Get a submission object](https://virustotal.readme.io/reference/get-submission.md) - [Get an operation object](https://virustotal.readme.io/reference/get-operations-id.md) - [Get an attack tactic object](https://virustotal.readme.io/reference/get-attack-tactics.md) - [Get objects related to an attack tactic](https://virustotal.readme.io/reference/get-attack-tactics-relationship.md) - [Get object descriptors related to an attack tactic](https://virustotal.readme.io/reference/get-attack-tactics-relationship-descriptor.md) - [Get an attack technique object](https://virustotal.readme.io/reference/get-attack-techniques.md) - [Get objects related to an attack technique](https://virustotal.readme.io/reference/get-attack-techniques-relationship.md) - [Get object descriptors related to an attack technique](https://virustotal.readme.io/reference/get-attack-techniques-relationship-descriptor.md) - [Popular Threat Categories](https://virustotal.readme.io/reference/popular-threat-categories.md): List of malware categories commonly used in AV verdicts (e.g., trojan, dropper, ...). - [Get a list of popular threat categories](https://virustotal.readme.io/reference/get-popular-threat-categories.md) - [Analyse code blocks with Code Insights](https://virustotal.readme.io/reference/analyse-binary.md) - [List Saved Searches](https://virustotal.readme.io/reference/list-saved-searches.md) - [Get a Saved Search](https://virustotal.readme.io/reference/get-saved-searches.md) - [Create a Saved Search](https://virustotal.readme.io/reference/create-saved-searches.md) - [Share a Saved Search](https://virustotal.readme.io/reference/share-saved-searches.md) - [Update a Saved Search](https://virustotal.readme.io/reference/update-saved-searches.md) - [Delete a Saved Search](https://virustotal.readme.io/reference/delete-saved-searches.md) - [Revoke access to a Saved Search](https://virustotal.readme.io/reference/revoke-saved-searches-access.md) - [Get object descriptors related to a Saved Search](https://virustotal.readme.io/reference/get-saved-searches-related-descriptors.md) - [Get objects related to a Saved Search](https://virustotal.readme.io/reference/get-saved-searches-relationships.md) - [Search & Metadata](https://virustotal.readme.io/reference/search.md) - [Search for files, URLs, domains, IPs and comments](https://virustotal.readme.io/reference/api-search.md) - [Advanced corpus search](https://virustotal.readme.io/reference/intelligence-search.md) - [Get file content search snippets](https://virustotal.readme.io/reference/intelligence-search-snippets.md) - [Get VirusTotal metadata](https://virustotal.readme.io/reference/metadata.md) - [Create a new collection](https://virustotal.readme.io/reference/collections-create.md) - [Get a collection](https://virustotal.readme.io/reference/collections-get.md) - [Update a collection](https://virustotal.readme.io/reference/collections-update.md) - [Delete a collection](https://virustotal.readme.io/reference/collections-delete.md) - [Get comments on a collection](https://virustotal.readme.io/reference/collections-comments.md) - [Add a comment to a collection](https://virustotal.readme.io/reference/collections-comments-create.md) - [Get objects related to a collection](https://virustotal.readme.io/reference/get-collections-relationship.md) - [Get object descriptors related to a collection](https://virustotal.readme.io/reference/get-collections-relationship-descriptor.md) - [Add new items to a collection](https://virustotal.readme.io/reference/collections-add-element.md) - [Delete items from a collection](https://virustotal.readme.io/reference/collections-delete-element.md) - [πŸ”’ List collections](https://virustotal.readme.io/reference/list-collections.md) - [πŸ”’ Export IOCs from a collection](https://virustotal.readme.io/reference/collections-export-iocs.md) - [πŸ”’ Export IOCs from a given collection's relationship](https://virustotal.readme.io/reference/collections-export-iocs-relationship.md) - [πŸ”’ Export aggregations from a collection](https://virustotal.readme.io/reference/collections-export-aggregations.md) - [πŸ”’ Search IoCs inside a collection](https://virustotal.readme.io/reference/search-iocs-inside-a-collection.md) - [Zipping files](https://virustotal.readme.io/reference/zip-files.md) - [Create a password-protected ZIP with VirusTotal files](https://virustotal.readme.io/reference/create-zip-files.md) - [Check a ZIP file’s status](https://virustotal.readme.io/reference/get-zip-files.md) - [Get a ZIP file’s download URL](https://virustotal.readme.io/reference/zip-files-download-url.md) - [Download a ZIP file](https://virustotal.readme.io/reference/zip-files-download.md) - [List Crowdsourced YARA Rules](https://virustotal.readme.io/reference/list-crowdsourced-yara-rules.md) - [Get a Crowdsourced YARA rule](https://virustotal.readme.io/reference/get-a-crowdsourced-yara-rule.md) - [Get objects related to a Crowdsourced YARA rule](https://virustotal.readme.io/reference/crowdsourced-yara-rule-relationship-endpoint.md) - [Get objects descriptors related to a Crowdsourced YARA rule](https://virustotal.readme.io/reference/crowdsourced-yara-rule-relationship-descriptors-endpoint.md) - [IoC Stream](https://virustotal.readme.io/reference/ioc-stream-introduction.md) - [Get objects from the IoC Stream](https://virustotal.readme.io/reference/get-objects-from-the-ioc-stream.md) - [Delete notifications from the IoC Stream](https://virustotal.readme.io/reference/delete-notifications-from-the-ioc-stream.md) - [Get an IoC Stream notification](https://virustotal.readme.io/reference/get-an-ioc-stream-notification.md) - [Delete an IoC Stream notification](https://virustotal.readme.io/reference/delete-an-ioc-stream-notification.md) - [πŸ”’ Livehunt](https://virustotal.readme.io/reference/api-livehunt.md) - [Get Livehunt rulesets](https://virustotal.readme.io/reference/list-hunting-rulesets.md) - [Create a new Livehunt ruleset](https://virustotal.readme.io/reference/create-hunting-ruleset.md) - [Remove all Livehunt rulesets](https://virustotal.readme.io/reference/delete-all-hunting-rulesets.md) - [Get a Livehunt ruleset](https://virustotal.readme.io/reference/get-hunting-ruleset.md) - [Update a Livehunt ruleset](https://virustotal.readme.io/reference/modify-hunting-ruleset.md) - [Check if a user or group is a Livehunt ruleset editor](https://virustotal.readme.io/reference/check-user-hunting-ruleset-editor.md) - [Revoke Livehunt ruleset edit permission from a user or group](https://virustotal.readme.io/reference/delete-hunting-ruleset-editor.md) - [Delete a Livehunt ruleset](https://virustotal.readme.io/reference/delete-hunting-ruleset.md) - [Get objects related to a Livehunt ruleset](https://virustotal.readme.io/reference/get-hunting-ruleset-full-relationships.md) - [Get object descriptors related to a Livehunt ruleset](https://virustotal.readme.io/reference/get-hunting-ruleset-relationship.md) - [Grant Livehunt ruleset edit permissions for a user or group](https://virustotal.readme.io/reference/edit-hunting-ruleset-relationship.md) - [Transfer Livehunt ruleset to another user](https://virustotal.readme.io/reference/transfer-livehunt-ruleset-to-another-user.md) - [Get Livehunt notifications](https://virustotal.readme.io/reference/list-hunting-notifications.md) - [Delete Livehunt notifications](https://virustotal.readme.io/reference/delete-hunting-notifications.md) - [Get a Livehunt notification object](https://virustotal.readme.io/reference/get-hunting-notification.md) - [Delete a Livehunt notification](https://virustotal.readme.io/reference/delete-hunting-notification.md) - [Retrieve file objects for Livehunt notifications](https://virustotal.readme.io/reference/get-hunting-notification-files.md) - [πŸ”’ Retrohunt](https://virustotal.readme.io/reference/api-retrohunt.md) - [Get a list of Retrohunt jobs](https://virustotal.readme.io/reference/get-retrohunt-jobs.md) - [Create a new Retrohunt job](https://virustotal.readme.io/reference/create-retrohunt-job.md) - [Get a Retrohunt job object](https://virustotal.readme.io/reference/get-retrohunt-job.md) - [Delete a Retrohunt job](https://virustotal.readme.io/reference/delete-retrohunt-job.md) - [Abort a Retrohunt job](https://virustotal.readme.io/reference/abort-retrohunt-job.md) - [Retrieve matches for a Retrohunt job](https://virustotal.readme.io/reference/get-retrohunt-job-relationships.md) - [Search graphs](https://virustotal.readme.io/reference/graphs.md) - [Create a graph](https://virustotal.readme.io/reference/create-graphs.md) - [Get a graph object](https://virustotal.readme.io/reference/graphs-info.md) - [Update a graph object](https://virustotal.readme.io/reference/graphs-update.md) - [Delete a graph](https://virustotal.readme.io/reference/graphs-delete.md) - [Get comments on a graph](https://virustotal.readme.io/reference/get-graph-comments.md) - [Add a comment to a graph](https://virustotal.readme.io/reference/post-graphs-comments.md) - [Get objects related to a graph](https://virustotal.readme.io/reference/graphs-relationships.md) - [Get object descriptors related to a graph](https://virustotal.readme.io/reference/graphs-relationships-ids.md) - [Get users and groups that can view a graph](https://virustotal.readme.io/reference/graphs-viewers.md) - [Grant users and groups permission to see a graph](https://virustotal.readme.io/reference/graphs-add-viewer.md) - [Check if a user or group can view a graph](https://virustotal.readme.io/reference/graphs-check-viewer.md) - [Revoke view permission from a user or group](https://virustotal.readme.io/reference/graphs-delete-viewer.md) - [Get users and groups that can edit a graph](https://virustotal.readme.io/reference/graphs-editors.md) - [Grant users and groups permission to edit a graph](https://virustotal.readme.io/reference/graphs-add-editor.md) - [Check if a user or group can edit a graph](https://virustotal.readme.io/reference/graphs-check-editor.md) - [Revoke edit graph permissions from a user or group](https://virustotal.readme.io/reference/graphs-delete-editor.md) - [πŸ”’ Files](https://virustotal.readme.io/reference/private-files-api.md) - [Upload a file](https://virustotal.readme.io/reference/upload-file-private-scanning.md): Privately upload and analyse a file. > πŸ“˜ File size If the file to be uploaded is bigger than 32MB, please use the [/private/files/upload_url](ref:private-files-upload-url) endpoint instead which admits files up to 650MB. - [List private files](https://virustotal.readme.io/reference/list-private-files.md) - [Get a URL for uploading large files](https://virustotal.readme.io/reference/private-files-upload-url.md) - [Rescan a private file](https://virustotal.readme.io/reference/rescan-a-private-file.md) - [Get a private file report](https://virustotal.readme.io/reference/private-files-info.md) - [Delete a private file report](https://virustotal.readme.io/reference/delete-file-private-scanning.md) - [Get objects related to a private file](https://virustotal.readme.io/reference/private-files-relationships.md) - [Get object descriptors related to a file](https://virustotal.readme.io/reference/get-private-files-relationship-descriptor.md) - [List private analyses](https://virustotal.readme.io/reference/list-private-analyses.md) - [Get a private analysis](https://virustotal.readme.io/reference/private-analysis.md) - [Get objects related to a private analysis](https://virustotal.readme.io/reference/get-private-analyses-relationship.md) - [Get object descriptors related to a private analysis](https://virustotal.readme.io/reference/get-private-analyses-relationship-descriptor.md) - [Get a behaviour report from a private file](https://virustotal.readme.io/reference/get-private-file-behaviour-id.md) - [Get the behaviour reports from a private file](https://virustotal.readme.io/reference/get-all-behaviour-reports-from-a-private-file.md) - [Get objects related to a private file's behaviour report](https://virustotal.readme.io/reference/get-private-file-behaviours-relationship.md) - [Get object descriptors related to a private file's behaviour report](https://virustotal.readme.io/reference/get-private-file-behaviours-relationship-descriptor.md) - [Get a summary of all behavior reports for a file](https://virustotal.readme.io/reference/get-private-files-behaviour-summary.md) - [Get a summary of all MITRE ATT&CK techniques observed in a file](https://virustotal.readme.io/reference/get-summary-all-mitre-attack-techniques-observed-in-a-file.md) - [Get a detailed HTML behaviour report](https://virustotal.readme.io/reference/get-private-files-behaviours-html.md): HTML sandbox report - [Get the EVTX file generated during a private file’s behavior analysis](https://virustotal.readme.io/reference/get-private-files-behaviours-evtx.md) - [Get the PCAP file generated during a private file’s behavior analysis](https://virustotal.readme.io/reference/get-private-files-behaviours-pcap.md) - [Get the memdump file generated during a private file’s behavior analysis](https://virustotal.readme.io/reference/get-private-files-behaviours-memdump.md) - [πŸ”’ URLs](https://virustotal.readme.io/reference/private-urls-api.md) - [Private Scan URL](https://virustotal.readme.io/reference/private-scan-url.md) - [Get a URL analysis report](https://virustotal.readme.io/reference/get-a-private-url-analysis-report.md) - [Get objects related to a private URL](https://virustotal.readme.io/reference/private-get-objects-related-to-a-url.md) - [Get object descriptors related to a private URL](https://virustotal.readme.io/reference/private-get-object-descriptors-related-to-a-url.md) - [Zipping private files](https://virustotal.readme.io/reference/private-scanning-zipping-files.md) - [Create a password-protected ZIP with VirusTotal private files](https://virustotal.readme.io/reference/private-scanning-zip-files.md) - [Check a ZIP file’s status](https://virustotal.readme.io/reference/private-scanning-get-zip-file.md) - [Get a ZIP file’s download URL](https://virustotal.readme.io/reference/private-scanning-get-zip-download-url.md) - [Download a ZIP file](https://virustotal.readme.io/reference/private-scanning-download-zip-file.md) - [πŸ”’ File intelligence feed](https://virustotal.readme.io/reference/file-feed.md) - [Get a per-minute file feed batch](https://virustotal.readme.io/reference/feeds-file.md) - [Get a hourly file feed batch](https://virustotal.readme.io/reference/feeds-file-hourly.md) - [Download a file published in the file feed](https://virustotal.readme.io/reference/file-feed-download.md) - [πŸ”’ Sandbox analyses feed](https://virustotal.readme.io/reference/sandbox-feed.md) - [Get a per-minute file behaviour feed batch](https://virustotal.readme.io/reference/feeds-file-behaviour.md) - [Get an hourly file behaviour feed batch](https://virustotal.readme.io/reference/feeds-file-behaviour-hourly.md) - [Get the EVTX file generated during a file’s behavior analysis](https://virustotal.readme.io/reference/file-behaviour-feed-evtx.md) - [Get the memdump file generated during a file’s behavior analysis](https://virustotal.readme.io/reference/file-behaviour-feed-memdump.md) - [Get the PCAP file generated during a file’s behavior analysis](https://virustotal.readme.io/reference/file-behaviour-feed-pcap.md) - [Get a file behaviour's detailed HTML report](https://virustotal.readme.io/reference/file-behaviour-feed-html.md) - [πŸ”’ Domain intelligence feed](https://virustotal.readme.io/reference/domain-feed.md) - [Get a minutely domain feed batch](https://virustotal.readme.io/reference/feedsdomains2time.md) - [Get an hourly domain feed batch](https://virustotal.readme.io/reference/feedsdomainshourly2time.md) - [πŸ”’ IP intelligence feed](https://virustotal.readme.io/reference/ip-feed.md) - [Get a minutely IP address feed batch](https://virustotal.readme.io/reference/get-feeds-ip-addresses.md) - [Get an hourly IP address feed batch](https://virustotal.readme.io/reference/get-feeds-ip-addresses-hourly.md) - [πŸ”’ URL intelligence feed](https://virustotal.readme.io/reference/url-feed.md) - [Get a minutely URL feed batch](https://virustotal.readme.io/reference/feeds-url.md) - [Get an hourly URL feed batch](https://virustotal.readme.io/reference/feeds-url-hourly.md) - [Get a user object](https://virustotal.readme.io/reference/user.md) - [Update a user object](https://virustotal.readme.io/reference/patch-user-id.md) - [Delete a user](https://virustotal.readme.io/reference/delete-user-id.md) - [Get objects related to a user](https://virustotal.readme.io/reference/users-relationships.md): Retrieve related objects IDs to an User - [Get object descriptors related to a user](https://virustotal.readme.io/reference/get-users-relationships-ids.md) - [Get a group object](https://virustotal.readme.io/reference/groups.md) - [Update a group object](https://virustotal.readme.io/reference/patch-group.md) - [Get administrators for a group](https://virustotal.readme.io/reference/get-group-administrators.md) - [Manage Roles](https://virustotal.readme.io/reference/patch-group-users-roles.md) - [Check if a user is a group admin](https://virustotal.readme.io/reference/check-user-group-administrator.md) - [Get group users](https://virustotal.readme.io/reference/get-group-users.md) - [Check if a user is a group member](https://virustotal.readme.io/reference/check-user-in-group.md) - [Remove a user from a group](https://virustotal.readme.io/reference/delete-user-from-group.md) - [Add users to a group](https://virustotal.readme.io/reference/update-group-users.md) - [Get objects related to a group](https://virustotal.readme.io/reference/groups-relationships.md) - [Get object descriptors related to a group](https://virustotal.readme.io/reference/groups-relationships-ids.md) - [Get a user’s API usage](https://virustotal.readme.io/reference/user-api-usage.md) - [Get a group’s API usage](https://virustotal.readme.io/reference/group-api-usage.md) - [Get a group's usage per feature](https://virustotal.readme.io/reference/get-group-usage.md) - [Create a new Service Account](https://virustotal.readme.io/reference/create-a-new-service-account.md) - [Get Service Accounts of a group](https://virustotal.readme.io/reference/get-service-accounts-of-a-group.md) - [Get a Service Account object](https://virustotal.readme.io/reference/get-a-service-account-object.md) - [Get Activity Logs](https://virustotal.readme.io/reference/get-activity-log.md) - [Overview](https://virustotal.readme.io/reference/widget-overview.md) - [Rendering](https://virustotal.readme.io/reference/render-widget.md) - [Get a widget rendering URL](https://virustotal.readme.io/reference/widgeturl.md) - [Retrieve the widget's HTML content](https://virustotal.readme.io/reference/widgethtmltoken.md) - [Theming](https://virustotal.readme.io/reference/theme.md) - [Activity Log](https://virustotal.readme.io/reference/activity-log.md) - [Analyses](https://virustotal.readme.io/reference/analyses-object.md): Partner contributors' analyses for files and URLs. - [πŸ”€ item](https://virustotal.readme.io/reference/analysis-object-item.md): Item being analysed - [Attack Tactics](https://virustotal.readme.io/reference/attack-tactics.md): Information about attack tactics - [πŸ”€ attack_techniques](https://virustotal.readme.io/reference/attack-tactic-object-attack-techniques.md): Attack tactic's techniques. - [Attack Techniques](https://virustotal.readme.io/reference/attack-techniques.md): Information about attack techniques - [πŸ”€ attack_tactics](https://virustotal.readme.io/reference/attack-technique-object-attack-tactics.md): Attack technique's tactics. - [πŸ”€ parent_technique](https://virustotal.readme.io/reference/attack-technique-object-parent-technique.md): Attack technique's parent technique. - [πŸ”€ revoking_technique](https://virustotal.readme.io/reference/attack-technique-object-revoking-technique.md): Attack technique's revoking technique. - [πŸ”€ subtechniques](https://virustotal.readme.io/reference/attack-technique-object-subtechniques.md): Attack technique's sub-techniques. - [πŸ”€πŸ”’ threat_actors](https://virustotal.readme.io/reference/attack-technique-object-threat-actors.md): Attack technique's threat actors - [Collections](https://virustotal.readme.io/reference/collections-object.md): Information about collections - [πŸ”€ autogenerated_graphs](https://virustotal.readme.io/reference/collection-object-autogenerated-graphs.md): Collection's techniques. - [πŸ”€ comments](https://virustotal.readme.io/reference/collection-object-comments.md): Collection's comments - [πŸ”€ domains](https://virustotal.readme.io/reference/collection-object-domains.md): Collection's domains - [πŸ”€ files](https://virustotal.readme.io/reference/collection-object-files.md): Collection's files. - [πŸ”€ ip_addresses](https://virustotal.readme.io/reference/collection-object-ip-addresses.md): Collection's IP addresses - [πŸ”€ owner](https://virustotal.readme.io/reference/collection-object-owner.md): Collection's owner - [πŸ”€ references](https://virustotal.readme.io/reference/collection-object-references.md): Collection's references - [πŸ”€πŸ”’ related_collections](https://virustotal.readme.io/reference/collection-object-related-collections.md): Related collections for a given collection. - [πŸ”€πŸ”’ related_references](https://virustotal.readme.io/reference/collection-object-related-references.md): Related references for a given collection. - [πŸ”€πŸ”’ threat_actors](https://virustotal.readme.io/reference/collection-object-threat-actors.md): Collection's threat actors - [πŸ”€ urls](https://virustotal.readme.io/reference/collection-object-urls.md): Collection's URLs - [Comments](https://virustotal.readme.io/reference/comment-object.md): comment object - [πŸ”€ author](https://virustotal.readme.io/reference/comment-object-author.md): Comment votes. - [Domains](https://virustotal.readme.io/reference/domains-object.md): Along with URLs, VirusTotal stores information related network locations, as domains and IP addresses. Within this section we will go through the information provided by Domain objects. - [πŸ”€πŸ”’ caa_records](https://virustotal.readme.io/reference/domain-object-caa-record.md): Records CAA for the domain. - [πŸ”€πŸ”’ cname_records](https://virustotal.readme.io/reference/domain-object-cname-records.md): Records CNAME for the domain. - [πŸ”€ collections](https://virustotal.readme.io/reference/domain-object-collections.md): Collections containing this domain. - [πŸ”€ comments](https://virustotal.readme.io/reference/domain-object-comments.md): Comments in Domain objects - [πŸ”€ communicating_files](https://virustotal.readme.io/reference/domain-object-communicating-files.md) - [πŸ”€πŸ”’ downloaded_files](https://virustotal.readme.io/reference/domain-object-downloaded-files.md) - [πŸ”€ graphs](https://virustotal.readme.io/reference/domain-object-graphs.md) - [πŸ”€ historical_ssl_certificates](https://virustotal.readme.io/reference/domain-object-historical-ssl-certificates.md): All SSL certificates that have been associated with the domain at some moment in time. - [πŸ”€ historical_whois](https://virustotal.readme.io/reference/domain-object-historical-whois.md): All whois records that have been associated with the domain at some moment in time. - [πŸ”€ immediate_parent](https://virustotal.readme.io/reference/domain-object-immediate-parent.md): Domain's immediate parent. - [πŸ”€πŸ”’ mx_records](https://virustotal.readme.io/reference/domain-object-mx-records.md): Records MX for the domain. - [πŸ”€πŸ”’ ns_records](https://virustotal.readme.io/reference/domain-object-ns-records.md): Records NS for the domain. - [πŸ”€ parent](https://virustotal.readme.io/reference/domain-object-parent.md): Domain's parent. - [πŸ”€ referrer_files](https://virustotal.readme.io/reference/domain-object-referrer-files.md): Files containing the domain on its strings. - [πŸ”€ related_comments](https://virustotal.readme.io/reference/domain-object-related-comments.md): Comments posted in related objects - [πŸ”€πŸ”’ related_references](https://virustotal.readme.io/reference/domain-object-related-references.md): Related references for a given domain. - [πŸ”€πŸ”’ related_threat_actors](https://virustotal.readme.io/reference/domain-object-related-threat-actors.md): Related Threat Actors for a given domain. - [πŸ”€ resolutions](https://virustotal.readme.io/reference/domain-object-resolutions.md): Domain's IP resolutions. - [πŸ”€ siblings](https://virustotal.readme.io/reference/domain-object-siblings.md) - [πŸ”€πŸ”’ soa_records](https://virustotal.readme.io/reference/domain-object-soa-records.md): Records SOA for the domain. - [πŸ”€ subdomains](https://virustotal.readme.io/reference/domain-object-subdomains.md): Domain's subdomains. - [πŸ”€πŸ”’ urls](https://virustotal.readme.io/reference/domain-object-urls.md): Domain's URLs. - [πŸ”€πŸ§‘β€πŸ’» user_votes](https://virustotal.readme.io/reference/domain-object-user-votes.md): Domain's user votes. - [πŸ”€ votes](https://virustotal.readme.io/reference/domain-object-votes.md): Domain's votes. - [Files](https://virustotal.readme.io/reference/files.md): Information about files - [androguard](https://virustotal.readme.io/reference/file-object-androguard.md): information about Android files. - [asf_info](https://virustotal.readme.io/reference/file-object-asf-info.md): information about Microsoft Advanced Streaming/Systems Format (ASF) files. - [authentihash](https://virustotal.readme.io/reference/file-object-authentihash.md): hash to verify PE files. - [bundle_info](https://virustotal.readme.io/reference/file-object-bundle-info.md): information about compressed files. - [class_info](https://virustotal.readme.io/reference/file-object-class-info.md): information about Java .class bytecode files. - [crowdsourced_ids_results](https://virustotal.readme.io/reference/file-object-crowdsourced-ids-results.md): IDS matches for the file. - [crowdsourced_ids_stats](https://virustotal.readme.io/reference/file-object-crowdsourced-ids-stats.md): IDS results stats. - [crowdsourced_yara_results](https://virustotal.readme.io/reference/file-object-crowdsourced-yara-results.md): YARA matches from crowdsourced rules. - [deb_info](https://virustotal.readme.io/reference/file-object-deb-info.md): information about Debian packages. - [detectiteasy](https://virustotal.readme.io/reference/file-object-detectiteasy.md): File type identification tool. - [dmg_info](https://virustotal.readme.io/reference/file-object-dmg-info.md): information about mountable macOS disk images. - [dot_net_assembly](https://virustotal.readme.io/reference/file-object-dot-net-assembly.md): information about Microsoft .NET files. - [dot_net_guids](https://virustotal.readme.io/reference/file-object-dot-net-guids.md): identifiers for Microsoft .NET assemblies. - [elf_info](https://virustotal.readme.io/reference/file-object-elf-info.md): information about Unix ELF files. - [πŸ”’ exiftool](https://virustotal.readme.io/reference/file-object-exiftool.md): information about EXIF metadata from files. - [html_info](https://virustotal.readme.io/reference/file-object-html-info.md): Information from HTML files - [image_code_injections](https://virustotal.readme.io/reference/file-object-image-code-injections.md): code injection inside image files. - [ipa_info](https://virustotal.readme.io/reference/file-object-ipa-info.md): information about iOS App Store Package files. - [isoimage_info](https://virustotal.readme.io/reference/file-object-isoimage-info.md): information about ISO image files. - [jar_info](https://virustotal.readme.io/reference/file-object-jar-info.md): information about Java Archive files. - [javascript_info](https://virustotal.readme.io/reference/file-object-file-javascript-info.md): Information extracted out of Javascript files - [known_distributors](https://virustotal.readme.io/reference/file-object-known-distributors.md): Information about the file's distributors - [lnk_info](https://virustotal.readme.io/reference/file-object-lnk-info.md): information about Microsoft Windows LNK files - [macho_info](https://virustotal.readme.io/reference/file-object-macho-info.md): information about Apple MachO files. - [magic](https://virustotal.readme.io/reference/file-object-magic.md): identification of files via magic number. - [πŸ”’ malware_config](https://virustotal.readme.io/reference/file-object-malware-config.md): Malware configuration for certain malware families - [monitor_info](https://virustotal.readme.io/reference/file-object-monitor-info.md): Information from VT monitor - [nsrl_info](https://virustotal.readme.io/reference/file-object-nsrl-info.md): Whitelisted files from the NSRL. - [πŸ”’ office_info](https://virustotal.readme.io/reference/file-object-office-info.md): Microsoft Office files structure information. - [πŸ”’ openxml_info](https://virustotal.readme.io/reference/file-object-openxml-info.md): Microsoft OpenXML files information. - [packers](https://virustotal.readme.io/reference/file-object-packers.md): identification of packers used by files. - [password_info](https://virustotal.readme.io/reference/file-object-password-info.md): Information from password protected files - [pdf_info](https://virustotal.readme.io/reference/file-object-pdf-info.md): information about Adobe PDF files. - [pe_info](https://virustotal.readme.io/reference/file-object-pe-info.md): Microsoft Windows Portable Executable file format info. - [popular_threat_classification](https://virustotal.readme.io/reference/file-object-popular-threat-classification.md): Human readable names extracted from the AV verdicts and clustering hashes - [powershell_info](https://virustotal.readme.io/reference/file-object-powershell-info.md) - [rombios_info](https://virustotal.readme.io/reference/file-object-rombios-info.md): information about BIOS, EFI, UEFI and related archives. - [πŸ”’ rtf_info](https://virustotal.readme.io/reference/file-object-rtf-info.md): information about Microsoft Rich Text Format files. - [sandbox_verdicts](https://virustotal.readme.io/reference/file-object-sandbox-verdicts.md): Sandbox verdicts for the file. - [sigma_analysis_results](https://virustotal.readme.io/reference/file-object-sigma-analysis-results.md): Sigma results for the file. - [sigma_analysis_stats](https://virustotal.readme.io/reference/file-object-sigma-analysis-stats.md): Sigma analysis stats for the file. - [signature_info](https://virustotal.readme.io/reference/file-object-signature-info.md): Information about signed PE and Mach-O files. - [snort](https://virustotal.readme.io/reference/file-object-snort.md): Matched Snort alerts in PCAP network captures. - [suricata](https://virustotal.readme.io/reference/file-object-suricata.md): Matched suricata alerts for PCAP network captures. - [ssdeep](https://virustotal.readme.io/reference/file-object-ssdeep.md): CTPH hash of the file content. - [swf_info](https://virustotal.readme.io/reference/file-object-swf-info.md): Information about Adobe Shockwave Flash files. - [telfhash](https://virustotal.readme.io/reference/file-object-telfhash.md): File's Trend Micro ELF Hash (aka telfhash) - [tlsh](https://virustotal.readme.io/reference/file-object-tlsh.md): Trend Micro's TLSH hash - [traffic_inspection](https://virustotal.readme.io/reference/file-object-files-traffic-inspection.md): Traffic notions extracted from PCAP network captures. - [trid](https://virustotal.readme.io/reference/file-object-trid.md): file type identification tool. - [vba_info](https://virustotal.readme.io/reference/file-object-vba-info.md): VBA macros information - [wireshark](https://virustotal.readme.io/reference/file-object-wireshark.md): Metadata produced by Wireshark when acting on the file. - [πŸ”€πŸ”’ analyses](https://virustotal.readme.io/reference/file-object-analyses.md): All analyses made for a given file. - [πŸ”€ behaviours](https://virustotal.readme.io/reference/file-object-behaviours.md): Behaviour reports for the file. - [πŸ”€ bundled_files](https://virustotal.readme.io/reference/file-object-bundled-files.md): Files bundled within the file. - [πŸ”€πŸ”’ carbonblack_children](https://virustotal.readme.io/reference/file-object-carbonblack-children.md): Files derived from the file according to Carbon Black. - [πŸ”€πŸ”’ carbonblack_parents](https://virustotal.readme.io/reference/file-object-carbonblack-parents.md): Files from where the file was derived according to Carbon Black. - [πŸ”€ collections](https://virustotal.readme.io/reference/file-object-collections.md): Collections containing this file. - [πŸ”€ comments](https://virustotal.readme.io/reference/file-object-comments.md): Comments in file objects. - [πŸ”€πŸ”’ compressed_parents](https://virustotal.readme.io/reference/file-object-compressed-parents.md): File bundles from where the file was found inside. - [πŸ”€ contacted_domains](https://virustotal.readme.io/reference/file-object-contacted-domains.md): Domains contacted by a given file - [πŸ”€ contacted_ips](https://virustotal.readme.io/reference/file-object-contacted-ips.md): IP addresses contacted by a given file - [πŸ”€ contacted_urls](https://virustotal.readme.io/reference/file-object-contacted-urls.md): URL addresses contacted by a given file - [πŸ”€ dropped_files](https://virustotal.readme.io/reference/file-object-dropped-files.md) - [πŸ”€πŸ”’ email_attachments](https://virustotal.readme.io/reference/file-object-email-attachments.md): Files attached to a given email file. - [πŸ”€πŸ”’ email_parents](https://virustotal.readme.io/reference/file-object-email-parents.md): Email files containing the file. - [πŸ”€πŸ”’ embedded_domains](https://virustotal.readme.io/reference/file-object-embedded-domains.md): Domain names embedded in the file. - [πŸ”€πŸ”’ embedded_ips](https://virustotal.readme.io/reference/file-object-embedded-ips.md): IP addresses embedded in the file. - [πŸ”€πŸ”’ embedded_urls](https://virustotal.readme.io/reference/file-object-embedded-urls.md): IP addresses embedded in the file. - [πŸ”€ execution_parents](https://virustotal.readme.io/reference/file-object-execution-parents.md): Files that executed the file. - [πŸ”€ graphs](https://virustotal.readme.io/reference/file-object-graphs.md) - [πŸ”€πŸ”’ itw_domains](https://virustotal.readme.io/reference/file-object-itw-domains.md): In the wild domain names from where the file has been downloaded. - [πŸ”€πŸ”’ itw_ips](https://virustotal.readme.io/reference/file-object-itw-ips.md): In the wild IP addresses from where the file has been downloaded. - [πŸ”€πŸ”’ itw_urls](https://virustotal.readme.io/reference/file-object-files-itw-urls.md): In the wild URLs from where the file has been downloaded. - [πŸ”€πŸ”’ overlay_children](https://virustotal.readme.io/reference/file-object-overlay-children.md): Files contained by the file as an overlay. - [πŸ”€πŸ”’ overlay_parents](https://virustotal.readme.io/reference/file-object-overlay-parents.md): Files containing the file as an overlay. - [πŸ”€πŸ”’ pcap_children](https://virustotal.readme.io/reference/file-object-pcap-children.md): PCAP files seen in the file. - [πŸ”€πŸ”’ pcap_parents](https://virustotal.readme.io/reference/file-object-pcap-parents.md): PCAP files that contain the file. - [πŸ”€ pe_resource_children](https://virustotal.readme.io/reference/file-object-pe-resource-children.md): PE files contained by the file as a resource. - [πŸ”€ pe_resource_parents](https://virustotal.readme.io/reference/file-object-pe-resource-parents.md): PE files containing the file as a resource. - [πŸ”€πŸ”’ related_references](https://virustotal.readme.io/reference/file-object-related-references.md): Related references for a given file. - [πŸ”€πŸ”’ related_threat_actors](https://virustotal.readme.io/reference/file-object-related-threat-actors.md): Related Threat Actors for a given file. - [πŸ”€πŸ”’ screenshots](https://virustotal.readme.io/reference/file-object-screenshots.md): Screenshots obtained from the execution of the file. - [πŸ”€ sigma_analysis](https://virustotal.readme.io/reference/file-object-sigma-analysis.md): Last Sigma analysis results. - [πŸ”€πŸ”’ similar_files](https://virustotal.readme.io/reference/file-object-similar-files.md): Files similar to the file. - [πŸ”€πŸ”’ submissions](https://virustotal.readme.io/reference/file-object-submissions.md): File submissions - [πŸ”€πŸ”’ urls_for_embedded_js](https://virustotal.readme.io/reference/file-object-urls-for-embedded-js.md): URLs where a given JS file is embedded - [πŸ”€πŸ§‘β€πŸ’» user_votes](https://virustotal.readme.io/reference/file-object-user-votes.md): Votes for a given file made by the current user - [πŸ”€ votes](https://virustotal.readme.io/reference/file-object-votes.md): Votes for a given file - [πŸ”€ memory_pattern_domains](https://virustotal.readme.io/reference/file-object-memory-pattern-domains.md) - [πŸ”€ memory_pattern_ips](https://virustotal.readme.io/reference/file-object-memory-pattern-ips.md) - [πŸ”€ memory_pattern_urls](https://virustotal.readme.io/reference/file-object-memory-pattern-urls.md) - [Files Behaviour](https://virustotal.readme.io/reference/file-behaviour-summary.md): File behaviour reports - [dns_lookups](https://virustotal.readme.io/reference/dns-lookup.md): DNS queries - [files_copied](https://virustotal.readme.io/reference/file-behaviour-object-files-copied.md): Object that describes a file copy or move. - [files_dropped](https://virustotal.readme.io/reference/dropped-files.md): Interesting files written to disk during execution. - [http_conversations](https://virustotal.readme.io/reference/http-conversation.md): HTTP Calls. - [ip_traffic](https://virustotal.readme.io/reference/ip-traffic.md): Outgoing connections seen during the execution of the given file. - [permissions_checked](https://virustotal.readme.io/reference/permission-check.md): Records a query to see whether a given component/package/process/service has a particular permission. - [processes_tree](https://virustotal.readme.io/reference/process.md): Created processes during the execution of a given file. - [sms_sent](https://virustotal.readme.io/reference/sms.md): Sent SMSs during the execution of the file under study. - [tags](https://virustotal.readme.io/reference/behaviour-tag.md): Sandbox behavior tagged with a complex operation - [verdicts](https://virustotal.readme.io/reference/verdict-tag.md): Verdicts to tag a sample from sandbox behaviour - [πŸ”€ file](https://virustotal.readme.io/reference/file-behaviour-object-file.md): File behaviour's file - [πŸ”€ attack_techniques](https://virustotal.readme.io/reference/file-behaviour-object-attack-techniques.md): File behaviour's ATT&CK techniques - [Graphs](https://virustotal.readme.io/reference/graph-object.md): Information about graphs. - [πŸ”€ comments](https://virustotal.readme.io/reference/graph-comments.md): Comments in a graph - [πŸ”€ editors](https://virustotal.readme.io/reference/graph-editors.md): Users that can edit a graph - [πŸ”€ group](https://virustotal.readme.io/reference/graph-group.md): Group owning the graph - [πŸ”€ items](https://virustotal.readme.io/reference/graph-items.md): Contained objects in the graph - [πŸ”€ owner](https://virustotal.readme.io/reference/graph-owner.md): User owning the graph - [πŸ”€ viewers](https://virustotal.readme.io/reference/graph-viewers.md): Users that can view a graph - [Groups](https://virustotal.readme.io/reference/group-object.md): Groups of users in VirusTotal - [πŸ”€πŸ§‘β€πŸ’» administrators](https://virustotal.readme.io/reference/group-administrators.md): Users administrating the group - [πŸ”€πŸ§‘β€πŸ’» graphs](https://virustotal.readme.io/reference/group-graphs.md): VT Graphs the group is owner/editor/viewer of. - [πŸ”€πŸ§‘β€πŸ’» users](https://virustotal.readme.io/reference/group-users.md): Group members - [Hunting Notifications](https://virustotal.readme.io/reference/hunting-notification-object.md): Generated notifications by matches in Hunting Rulesets - [Hunting Rulesets](https://virustotal.readme.io/reference/hunting-ruleset-object.md): User's hunting rulesets - [πŸ”€ πŸ§‘β€πŸ’»owner](https://virustotal.readme.io/reference/rulesets-owner.md): Collection's owner - [πŸ”€πŸ§‘β€πŸ’» editors](https://virustotal.readme.io/reference/hunting-rulesets-editors.md): Users and groups that can edit the rules - [πŸ”€πŸ§‘β€πŸ’» viewers](https://virustotal.readme.io/reference/rulesets-viewers.md): Users and groups that can edit the rules - [πŸ”€πŸ§‘β€πŸ’» hunting_notification_files](https://virustotal.readme.io/reference/hunting-ruleset-notification-files.md): Files associated to notifications triggered by the ruleset. - [IoC-Stream Notifications](https://virustotal.readme.io/reference/ioc-stream-notifications.md): Generated notifications by matches in the IoC-Stream - [IP addresses](https://virustotal.readme.io/reference/ip-object.md): IPv4 and IPv6 addresses are other of the network locations that VirusTotal stores information about. A description of the fields stored within these objects follows. - [πŸ”€ collections](https://virustotal.readme.io/reference/ip-object-collections.md): Collections containing this IP address. - [πŸ”€ comments](https://virustotal.readme.io/reference/ip-object-comments.md): Comments posted in a IP address. - [πŸ”€ communicating_files](https://virustotal.readme.io/reference/ip-object-communicating-files.md) - [πŸ”€πŸ”’ downloaded_files](https://virustotal.readme.io/reference/ip-object-downloaded-files.md) - [πŸ”€ graphs](https://virustotal.readme.io/reference/ip-object-graphs.md) - [πŸ”€ historical_ssl_certificates](https://virustotal.readme.io/reference/ip-object-historical-ssl-certificates.md): All SSL certificates that have been associated with the IP at some moment in time. - [πŸ”€ historical_whois](https://virustotal.readme.io/reference/ip-object-historical-whois.md): All whois records associated with the IP address at some moment in time. - [πŸ”€ related_comments](https://virustotal.readme.io/reference/ip-object-related-comments.md): Comments posted in related objects. - [πŸ”€πŸ”’ related_references](https://virustotal.readme.io/reference/ip-object-related-references.md): Related references for a given domain. - [πŸ”€πŸ”’ related_threat_actors](https://virustotal.readme.io/reference/ip-object-related-threat-actors.md): Related Threat Actors for a given IP address. - [πŸ”€ referrer_files](https://virustotal.readme.io/reference/ip-object-referrer-files.md): File containing the IP address on its strings. - [πŸ”€ resolutions](https://virustotal.readme.io/reference/ip-object-resolutions.md): Domain resolutions for a IP address. - [πŸ”€πŸ”’ urls](https://virustotal.readme.io/reference/ip-object-urls.md): IP address' URLs - [πŸ”€πŸ§‘β€πŸ’» user_votes](https://virustotal.readme.io/reference/ip-object-user-votes.md): IP address' user votes. - [πŸ”€ votes](https://virustotal.readme.io/reference/ip-object-votes.md): IP address' votes. - [Operations](https://virustotal.readme.io/reference/operation-object.md): Asynchronous operations - [πŸ”’ Private Analyses](https://virustotal.readme.io/reference/private-analyses.md): Private file's analyses - [πŸ”€ item](https://virustotal.readme.io/reference/private-analyses-object-item.md): Item being analysed - [πŸ”€ submitter](https://virustotal.readme.io/reference/submitter.md): User who submitted the analysis - [πŸ”’ Private Files](https://virustotal.readme.io/reference/private-files.md): Information about private files - [πŸ”€ behaviours](https://virustotal.readme.io/reference/private-file-object-behaviours.md): Behaviour reports for the private file - [πŸ”€ dropped_files](https://virustotal.readme.io/reference/private-file-object-dropped-files.md): Files dropped during the file's execution - [πŸ”€ execution_parents](https://virustotal.readme.io/reference/private-file-object-execution-parents.md): Files dropping the file during its execution - [πŸ”€ embedded_urls](https://virustotal.readme.io/reference/private-file-object-embedded-urls.md): URLs contained in the file - [πŸ”€ embedded_domains](https://virustotal.readme.io/reference/private-file-object-embedded-domains.md): Domains contained in the file - [πŸ”€ embedded_ips](https://virustotal.readme.io/reference/private-file-object-embedded-ips.md): IP addresses contained in the file - [πŸ”’ Private Files Behaviours](https://virustotal.readme.io/reference/private-file-behaviours.md): Information about private file behaviours - [πŸ”€ attack_techniques](https://virustotal.readme.io/reference/private-files-behaviour-object-attack-techniques.md): Private file behaviour's ATT&CK techniques - [πŸ”€ file](https://virustotal.readme.io/reference/private-files-behaviour-object-file.md): Private file behaviour's file. - [πŸ”’ Private URLs](https://virustotal.readme.io/reference/private-urls.md): Information about private URLs - [πŸ”’ Private URLs Behaviours](https://virustotal.readme.io/reference/private-url-behaviours.md): Information about private URL behaviours - [Resolutions](https://virustotal.readme.io/reference/resolution-object.md): Domain-IP resolutions. - [Retrohunt Jobs](https://virustotal.readme.io/reference/retrohunt-job-object.md): YARA matching against VirusTotal's file corpus - [πŸ”€πŸ§‘β€πŸ’» matching_files](https://virustotal.readme.io/reference/retrohunt-job-matching-files.md): Files matching the Retrohunt job. - [πŸ”€πŸ§‘β€πŸ’» owner](https://virustotal.readme.io/reference/retrohunt-job-owner.md): Retrohunt job's owner - [Screenshots](https://virustotal.readme.io/reference/screenshots.md): screenshot objects - [Sigma Analyses](https://virustotal.readme.io/reference/sigma-analyses.md): Sigma analyses run in sandbox generated sysmon logs. - [πŸ”€ rules](https://virustotal.readme.io/reference/sigma-analysis-object-rules.md): Matched rules in a Sigma analysis. - [Sigma Rules](https://virustotal.readme.io/reference/sigma-rule-object.md): Sigma rules matched in Sigma analyses - [SSL Certificate](https://virustotal.readme.io/reference/ssl-certificate.md): SSL certificates information. - [Submissions](https://virustotal.readme.io/reference/submission-object.md): Information about submissions - [URLs](https://virustotal.readme.io/reference/url-object.md): Information about URLs. - [πŸ”€πŸ”’ analyses](https://virustotal.readme.io/reference/url-object-analyses.md): All analyses made for a given URL. - [πŸ”€ collections](https://virustotal.readme.io/reference/url-object-collections.md): Collections containing this URL. - [πŸ”€ comments](https://virustotal.readme.io/reference/url-object-comments.md): Comments in URL objects. - [πŸ”€πŸ”’ communicating_files](https://virustotal.readme.io/reference/url-object-communicating-files.md): Files that communicate with this url when they are executed. - [πŸ”€πŸ”’ contacted_domains](https://virustotal.readme.io/reference/url-object-contacted-domains.md): Distinct domains from which the URL loads some kind of resource. - [πŸ”€πŸ”’ contacted_ips](https://virustotal.readme.io/reference/url-object-contacted-ips.md): Distinct IP addresses from which the URL loads some kind of resource. - [πŸ”€πŸ”’ downloaded_files](https://virustotal.readme.io/reference/url-object-downloaded-files.md): Files downloaded from the URL. - [πŸ”€πŸ”’ embedded_js_files](https://virustotal.readme.io/reference/url-object-embedded-js-files.md): Found javascript scripts in the URL's HTML response - [πŸ”€ graphs](https://virustotal.readme.io/reference/url-object-graphs.md) - [πŸ”€ last_serving_ip_address](https://virustotal.readme.io/reference/url-object-last-serving-ip-address.md): Last IP address that served the URL. - [πŸ”€ network_location](https://virustotal.readme.io/reference/url-object-network-location.md): Domain or IP address for the URL. - [πŸ”€πŸ”’ redirecting_urls](https://virustotal.readme.io/reference/url-object-redirecting-urls.md): URLs that redirected to the given URL. - [πŸ”€πŸ”’ redirects_to](https://virustotal.readme.io/reference/url-object-redirects-to.md): URLs that this url redirects to. - [πŸ”€πŸ”’ referrer_files](https://virustotal.readme.io/reference/url-object-referrer-files.md): Files containing a given URL. - [πŸ”€πŸ”’ referrer_urls](https://virustotal.readme.io/reference/url-object-referrer-urls.md): URLs that refer to the given URL. - [πŸ”€ related_comments](https://virustotal.readme.io/reference/url-object-related-comments.md): Comments in URL's related objects. - [πŸ”€πŸ”’ related_references](https://virustotal.readme.io/reference/url-object-related-references.md): Related references for a given URL. - [πŸ”€πŸ”’ related_threat_actors](https://virustotal.readme.io/reference/url-object-related-threat-actors.md): Related Threat Actors for a given URL. - [πŸ”€πŸ”’ submissions](https://virustotal.readme.io/reference/url-object-submissions.md): URL submissions - [πŸ”€πŸ§‘β€πŸ’» user_votes](https://virustotal.readme.io/reference/url-object-user-votes.md): Votes for a given URL made by the current user - [πŸ”€ votes](https://virustotal.readme.io/reference/url-object-votes.md): Votes for a given URL - [πŸ”€πŸ”’ urls_related_by_tracker_id](https://virustotal.readme.io/reference/url-object-urls-related-by-tracker-id.md): URLs having trackers with the same IDs - [Users](https://virustotal.readme.io/reference/user-object.md): Information about a VirusTotal user - [πŸ”€πŸ§‘β€πŸ’» api_quota_group](https://virustotal.readme.io/reference/user-object-api-quota-group.md): Group which the user consumes API quota from. - [πŸ”€ collections](https://virustotal.readme.io/reference/user-object-collections.md) - [πŸ”€ comments](https://virustotal.readme.io/reference/user-object-comments.md): Comments posted by a certain user - [πŸ”€ graphs](https://virustotal.readme.io/reference/user-object-graphs.md): VT Graphs the user is owner/editor/viewer of - [πŸ”€πŸ§‘β€πŸ’» groups](https://virustotal.readme.io/reference/user-object-groups.md): Groups for which the user is a member. - [πŸ”€πŸ§‘β€πŸ’» hunting_rulesets](https://virustotal.readme.io/reference/user-object-hunting-rulesets.md): Hunting rulesets editable by the user. - [πŸ”€πŸ§‘β€πŸ’» hunting_notifications](https://virustotal.readme.io/reference/user-object-hunting-notifications.md): Hunting notifications for the user. - [πŸ”€πŸ§‘β€πŸ’» hunting_notification_files](https://virustotal.readme.io/reference/user-object-hunting-notification-files.md): Files flagged in the hunting notifications for the user. - [πŸ”€πŸ§‘β€πŸ’» intelligence_quota_group](https://virustotal.readme.io/reference/user-object-intelligence-quota-group.md): Group which the user consumes Intelligence quota from. - [πŸ”€ mentions](https://virustotal.readme.io/reference/user-object-mentions.md): Comments mentioning the user. - [πŸ”€πŸ§‘β€πŸ’» retrohunt_jobs](https://virustotal.readme.io/reference/user-object-retrohunt-job.md): User's Retrohunt jobs - [πŸ”€ votes](https://virustotal.readme.io/reference/user-object-votes.md): Votes posted by a certain user - [Saved Searches](https://virustotal.readme.io/reference/saved-search-object.md) - [Service Accounts](https://virustotal.readme.io/reference/service-accounts-object.md): Information about a VirusTotal Service Account - [πŸ”€πŸ§‘β€πŸ’» api_quota_group](https://virustotal.readme.io/reference/service-account-object-api-quota-group.md): Group which the user consumes API quota from. - [πŸ”€ comments](https://virustotal.readme.io/reference/service-account-object-comments.md): Comments posted by a certain user - [πŸ”€πŸ§‘β€πŸ’» groups](https://virustotal.readme.io/reference/service-account-object-groups.md): Groups for which the user is a member. - [πŸ”€πŸ§‘β€πŸ’» intelligence_quota_group](https://virustotal.readme.io/reference/service-account-object-intelligence-quota-group.md): Group which the user consumes Intelligence quota from. - [πŸ”€ mentions](https://virustotal.readme.io/reference/service-account-object-mentions.md): Comments mentioning the user. - [Votes](https://virustotal.readme.io/reference/vote-object.md): vote objects - [Whois](https://virustotal.readme.io/reference/whois.md): Domain and IP addresses whois records. - [YARA Rules](https://virustotal.readme.io/reference/yara-rule.md): YARA rules objects - [YARA Rulesets](https://virustotal.readme.io/reference/yara-rulesets.md): YARA rulesets objects - [Software Publishers](https://virustotal.readme.io/reference/software-publishers.md) - [Monitor Items](https://virustotal.readme.io/reference/monitoritem-description.md): Details about objects stored in the VirusTotal Monitor service. - [Get a list of MonitorItem objects by path or tag](https://virustotal.readme.io/reference/monitor-items-filter.md) - [Upload a file or create a new folder](https://virustotal.readme.io/reference/monitor-items-create.md) - [Get a URL for uploading files larger than 32MB](https://virustotal.readme.io/reference/monitor-items-upload-url.md) - [Get attributes and metadata for a specific MonitorItem](https://virustotal.readme.io/reference/monitor-items-stat.md) - [Delete a VirusTotal Monitor file or folder](https://virustotal.readme.io/reference/monitor-items-delete.md) - [Configure a given VirusTotal Monitor item (file or folder)](https://virustotal.readme.io/reference/monitor-items-config.md) - [Download a file in VirusTotal Monitor](https://virustotal.readme.io/reference/monitor-items-download.md) - [Get a URL for downloading a file in VirusTotal Monitor](https://virustotal.readme.io/reference/monitor-items-download-url.md) - [Get the latest file analyses](https://virustotal.readme.io/reference/monitor-items-analyses.md) - [Get user owning the MonitorItem object](https://virustotal.readme.io/reference/monitor-items-owner.md) - [Retrieve partner's comments on a file](https://virustotal.readme.io/reference/monitor-item-comments.md) - [Retrieve statistics about analyses performed on your software collection](https://virustotal.readme.io/reference/monitor-statistics.md) - [Retrieve historical events about your software collection](https://virustotal.readme.io/reference/events.md) - [Antivirus Partners](https://virustotal.readme.io/reference/antivirus-partners.md) - [Get a list of MonitorHashes detected by an engine](https://virustotal.readme.io/reference/monitorpartner-hashes.md) - [Get a list of analyses for a file](https://virustotal.readme.io/reference/monitorpartner-hashes-analyses.md) - [Get a list of items with a given sha256 hash](https://virustotal.readme.io/reference/monitorpartner-hashes-items.md) - [Create a comment over a hash](https://virustotal.readme.io/reference/monitorpartner-hashes-comments.md): Create a comment and if necessary confirm detection over a hash - [Get comments on a sha256 hash](https://virustotal.readme.io/reference/get-sha256-hash-comments.md) - [Add a comment on a sha256 hash](https://virustotal.readme.io/reference/monitorpartner-comments-patch.md): Create a comment and if necessary confirm detection over a hash - [Remove a comment detection for a hash.](https://virustotal.readme.io/reference/monitorpartner-comments-delete.md): Remove a comment and reset confirmed detection for a hash. - [Download a file with a given sha256 hash](https://virustotal.readme.io/reference/monitorpartner-files-download.md) - [Retrieve a download url for a file with a given sha256 hash](https://virustotal.readme.io/reference/monitorpartner-files-download-url.md) - [Download a daily detection bundle directly](https://virustotal.readme.io/reference/monitorpartner-detectionsbundle-download.md) - [Get a daily detection bundle download URL](https://virustotal.readme.io/reference/monitorpartner-detectionsbundle-download-url.md) - [Get a list of MonitorHashes detected by an engine](https://virustotal.readme.io/reference/monitorpartner-statistics.md) ## Pages - [Title](https://virustotal.readme.io/title.md)