# VirusTotal Documentation > VirusTotal's developers hub, the place to learn about VirusTotal's public and private APIs in order to programmatically scan files, check URLs, discover malicious domains, etc. Append .md to any documentation page URL to get its markdown version. ## Guides - [How it works](https://virustotal.readme.io/docs/how-it-works.md) - [Join Community](https://virustotal.readme.io/docs/community.md) - [Contributors](https://virustotal.readme.io/docs/contributors.md) - [Comments](https://virustotal.readme.io/docs/comments.md) - [Historic Terms of Service](https://virustotal.readme.io/docs/historic-terms-of-service.md) - [Historic Privacy Policy](https://virustotal.readme.io/docs/historic-privacy-policy.md) - [VirusTotal AI (VTAI)](https://virustotal.readme.io/docs/vtai-overview.md): VirusTotal intelligence for your AI agent β€” check files, URLs, domains and IPs from AI clients over MCP or a direct REST API. Free within quotas, no VirusTotal API key required. - [Configure SAML with Okta](https://virustotal.readme.io/docs/saml-okta.md) - [Configure SAML with Ping](https://virustotal.readme.io/docs/saml-ping.md) - [Configure SAML with Entra ID](https://virustotal.readme.io/docs/saml-entraid.md) - [Single Sign On Authentication ](https://virustotal.readme.io/docs/sso-authentication.md) - [Searching for users](https://virustotal.readme.io/docs/user-searching.md) - [Walkthrough guide for VirusTotal group administrators](https://virustotal.readme.io/docs/admins-guide.md) - [Unified User & Service Account Management (RBAC & Quotas)](https://virustotal.readme.io/docs/unified-user-service-account-management.md): Learn how to manage human users and service accounts in a unified console with full Role-Based Access Control (RBAC) and daily quota parity. - [Service Accounts](https://virustotal.readme.io/docs/service-account.md) - [Understanding Consumption](https://virustotal.readme.io/docs/quota-consumption.md) - [API Overview](https://virustotal.readme.io/docs/api-overview.md) - [VirusTotal Intelligence Introduction](https://virustotal.readme.io/docs/virustotal-intelligence-introduction.md) - [Searching](https://virustotal.readme.io/docs/searching.md) - [File search modifiers](https://virustotal.readme.io/docs/file-search-modifiers.md) - [IP address search modifiers](https://virustotal.readme.io/docs/ip-address-search-modifiers.md) - [Domain search modifiers](https://virustotal.readme.io/docs/domain-search-modifiers.md) - [URL search modifiers](https://virustotal.readme.io/docs/url-search-modifiers.md) - [File - List of Engines](https://virustotal.readme.io/docs/list-file-engines.md): Identifying files according to antivirus detections - [Netloc - List of engines](https://virustotal.readme.io/docs/list-netloc-engines.md) - [Full list of VirusTotal Intelligence search modifiers](https://virustotal.readme.io/docs/search-modifiers-full-list.md) - [Full list of VirusTotal Intelligence tag modifier](https://virustotal.readme.io/docs/intelligence-tag-list.md) - [Full list of VirusTotal Intelligence behaviour_tags modifier](https://virustotal.readme.io/docs/list-behaviour-tag-modifiers.md) - [Collection search modifiers](https://virustotal.readme.io/docs/collection-search-modifiers.md) - [File similarity search](https://virustotal.readme.io/docs/file-similarity-search.md) - [Content search (VTGrep)](https://virustotal.readme.io/docs/vtgrep.md) - [Searching using entities](https://virustotal.readme.io/docs/searching-entities.md) - [VirusTotal Collections Introduction](https://virustotal.readme.io/docs/collections-introduction.md) - [Saved Searches](https://virustotal.readme.io/docs/saved-searches-guide.md) - [In-house Sandboxes - behavioural analysis products](https://virustotal.readme.io/docs/in-house-sandboxes.md) - [External behavioural engines sandboxes](https://virustotal.readme.io/docs/external-sandboxes.md) - [Reports](https://virustotal.readme.io/docs/results-reports.md) - [Full list of File object attritbutes](https://virustotal.readme.io/docs/file-attributes-full-list.md) - [What's VT Hunting?](https://virustotal.readme.io/docs/whats-vthunting.md) - [Sources Subscriptions](https://virustotal.readme.io/docs/ioc-stream-sources-subscriptions.md) - [Threat Feeds](https://virustotal.readme.io/docs/ioc-stream-threat-feeds.md) - [Livehunt](https://virustotal.readme.io/docs/livehunt.md) - [File hunting: Writing YARA rules for Livehunt](https://virustotal.readme.io/docs/writing-yara-rules-for-livehunt.md) - [Network hunting: Writing YARA rules for Livehunt](https://virustotal.readme.io/docs/nethunt.md): Network hunting using YARA - [Examples of network hunting using Livehunt](https://virustotal.readme.io/docs/nethunt-examples.md): Examples of network hunting using Livehunt - [Retrohunt](https://virustotal.readme.io/docs/retrohunt.md) - [Crowdsourced IDS Rules](https://virustotal.readme.io/docs/crowdsourced-ids-rules.md) - [Crowdsourced YARA Rules](https://virustotal.readme.io/docs/crowdsourced-yara-rules.md) - [Crowdsourced YARA rules dashboard](https://virustotal.readme.io/docs/crowdsourced-yara-rules-dashboard.md) - [Sigma rules](https://virustotal.readme.io/docs/crowdsourced-sigma-rules.md) - [VTDIFF - Automatic YARA rules](https://virustotal.readme.io/docs/vtdiff-automatic-yara-rules.md) - [Introduction](https://virustotal.readme.io/docs/graph-documentation.md) - [Overview](https://virustotal.readme.io/docs/graph-overview.md) - [Search and start new investigation](https://virustotal.readme.io/docs/graph-search.md) - [Management](https://virustotal.readme.io/docs/graph-management.md) - [Nodes](https://virustotal.readme.io/docs/graph-nodes.md) - [Commonalities and Hunting](https://virustotal.readme.io/docs/graph-commonalities.md) - [Private Scanning](https://virustotal.readme.io/docs/private-scanning.md) - [OpenVPN support on private scanning](https://virustotal.readme.io/docs/openvpn-support-on-private-scanning.md) - [Integrations](https://virustotal.readme.io/docs/integrations.md): Get VirusTotal enrichment, threat and adversary intelligence in third party vendors. - [VT4Splunk, official VirusTotal app for Splunk](https://virustotal.readme.io/docs/vt4splunk-guide.md): Configuration and use guide - [Connectors](https://virustotal.readme.io/docs/connectors.md): Show data from third party vendors on VirusTotal - [Splunk](https://virustotal.readme.io/docs/splunk-connector.md): Splunk connector guide for VirusTotal - [Mandiant Advantage - Threat Intelligence](https://virustotal.readme.io/docs/mandiant-connector.md): Mandiant connector guide for VirusTotal - [MISP](https://virustotal.readme.io/docs/misp-connector.md): MISP connector guide for VirusTotal - [List of VT Integrations](https://virustotal.readme.io/docs/technology-integrations-list.md) - [Tools overview](https://virustotal.readme.io/docs/tools-overview.md) - [Desktop Apps](https://virustotal.readme.io/docs/desktop-apps.md) - [Mobile Apps](https://virustotal.readme.io/docs/mobile-apps.md) - [Browser Extensions](https://virustotal.readme.io/docs/browser-extensions.md) - [VT4Browsers + Google TI](https://virustotal.readme.io/docs/vt4browsers.md) - [API Scripts and client libraries](https://virustotal.readme.io/docs/api-scripts-and-client-libraries.md) - [Batch file downloads](https://virustotal.readme.io/docs/batch-file-downloads.md) - [VT Bot](https://virustotal.readme.io/docs/bot-overview.md) - [Frequently Asked Questions](https://virustotal.readme.io/docs/virustotal-faq.md) - [Please give me an API key](https://virustotal.readme.io/docs/please-give-me-an-api-key.md) - [How consumption quotas are handled](https://virustotal.readme.io/docs/consumption-quotas-handled.md) - [How can I have access to a higher quota?](https://virustotal.readme.io/docs/higher-quota.md) - [What is the difference between the public API and the private API?](https://virustotal.readme.io/docs/difference-public-private.md) - [What kind of files will VirusTotal scan?](https://virustotal.readme.io/docs/file-types.md) - [I accidentally uploaded a file with confidential or sensitive information to VirusTotal, can you please delete it?](https://virustotal.readme.io/docs/accidental-upload.md) - [Should I upload files larger than 650MBs ?](https://virustotal.readme.io/docs/large-files.md) - [Empty file and VirusTotal uploads](https://virustotal.readme.io/docs/empty-file.md) - [How can I link to the most recent report on a given file or URL?](https://virustotal.readme.io/docs/most-recent-report.md) - [How can I automate scans?](https://virustotal.readme.io/docs/automate-scans.md) - [File from a URL scan was not enqueued for antivirus scanning](https://virustotal.readme.io/docs/file-not-enqueued.md) - [What type of files are supported by code insight?](https://virustotal.readme.io/docs/codeinsight-supported-files.md) - [What type of compressed files are supported?](https://virustotal.readme.io/docs/compressed-files.md) - [Why does my signed file appear as "not signed" on VirusTotal?](https://virustotal.readme.io/docs/why-does-my-signed-file-appear-as-not-signed-on-virustotal.md): I have a file that appears to be digitally signed on my Windows system, but VirusTotal's "Details" tab reports it as "File is not signed." Why is there a discrepancy? - [AV product on VirusTotal detects a file and its equivalent commercial version does not](https://virustotal.readme.io/docs/antivirus-verdict-differs.md) - [URL scanner verdict differ from its corresponding antivirus solution](https://virustotal.readme.io/docs/urlscanner-differs.md) - [I am experiencing a false positive, my file or site should not be detected.](https://virustotal.readme.io/docs/false-positive.md) - [What does the green circle with a white tick mark icon mean?](https://virustotal.readme.io/docs/antivirus-greencircle.md) - [Why don't you have statistics comparing antivirus performance?](https://virustotal.readme.io/docs/antivirus-stats.md) - [Intelligence - How do I search for malware detected as X](https://virustotal.readme.io/docs/malware-search.md) - [What is YARA?](https://virustotal.readme.io/docs/what-is-yara.md) - [How does VTDiff work?](https://virustotal.readme.io/docs/how-does-vtdiff-work.md) - [Error - "Need to give exclusion list for filetype"](https://virustotal.readme.io/docs/vtdiff-filetype-exclusion.md) - [When is an analysis included in the feeds?](https://virustotal.readme.io/docs/when-analysis-feeds.md) - [I lost access to my authentication device/offline codes for 2FA](https://virustotal.readme.io/docs/lost-access-2fa.md) ## API Reference - [VirusTotal API v3 Overview](https://virustotal.readme.io/reference/overview.md) - [Public vs Premium API](https://virustotal.readme.io/reference/public-vs-premium-api.md) - [Getting started](https://virustotal.readme.io/reference/getting-started.md) - [Authentication](https://virustotal.readme.io/reference/authentication.md) - [API responses](https://virustotal.readme.io/reference/api-responses.md) - [Errors](https://virustotal.readme.io/reference/errors.md) - [Key concepts](https://virustotal.readme.io/reference/key-concepts.md) - [Objects](https://virustotal.readme.io/reference/objects.md) - [Collections](https://virustotal.readme.io/reference/collections.md) - [Relationships](https://virustotal.readme.io/reference/relationships.md) - [Legend](https://virustotal.readme.io/reference/doc-legends.md) - [API v2 to v3 Migration Guide](https://virustotal.readme.io/reference/api-v2-v3-migration-guide.md) - [Get an IP address report](https://virustotal.readme.io/reference/ip-info.md) - [Request an IP address (re)scan](https://virustotal.readme.io/reference/rescan-ip.md): Reanalyse an IP address already in VirusTotal - [Get comments on an IP address](https://virustotal.readme.io/reference/ip-comments-get.md) - [Add a comment to an IP address](https://virustotal.readme.io/reference/ip-comments-post.md) - [Get objects related to an IP address](https://virustotal.readme.io/reference/ip-relationships.md) - [Get object descriptors related to an IP address](https://virustotal.readme.io/reference/ip-relationships-ids.md) - [Get votes on an IP address](https://virustotal.readme.io/reference/ip-votes.md) - [Add a vote to an IP address](https://virustotal.readme.io/reference/ip-votes-post.md) - [Get a domain report](https://virustotal.readme.io/reference/domain-info.md) - [Request an domain (re)scan](https://virustotal.readme.io/reference/domains-rescan.md): Reanalyse a domain already in VirusTotal - [Get comments on a domain](https://virustotal.readme.io/reference/domains-comments-get.md) - [Add a comment to a domain](https://virustotal.readme.io/reference/domains-comments-post.md) - [Get objects related to a domain](https://virustotal.readme.io/reference/domains-relationships.md) - [Get object descriptors related to a domain](https://virustotal.readme.io/reference/domains-relationships-ids.md) - [Get a DNS resolution object](https://virustotal.readme.io/reference/get-resolution-by-id.md) - [Get votes on a domain](https://virustotal.readme.io/reference/domains-votes-get.md) - [Add a vote to a domain](https://virustotal.readme.io/reference/domain-votes-post.md) - [Files](https://virustotal.readme.io/reference/file.md) - [Upload a file](https://virustotal.readme.io/reference/files-scan.md): Upload and analyse a file > πŸ“˜ File size If the file to be uploaded is bigger than 32MB, please use the [/files/upload_url](ref:files-upload-url) endpoint instead which admits files up to 650MB. - [Get a URL for uploading large files](https://virustotal.readme.io/reference/files-upload-url.md): Get a URL for uploading files larger than 32MB - [Get a file report](https://virustotal.readme.io/reference/file-info.md): Retrieve information about a file - [Request a file rescan (re-analyze)](https://virustotal.readme.io/reference/files-analyse.md): Reanalyse a file already in VirusTotal - [Get a file’s download URL](https://virustotal.readme.io/reference/files-download-url.md) - [Download a file](https://virustotal.readme.io/reference/files-download.md) - [Get comments on a file](https://virustotal.readme.io/reference/files-comments-get.md) - [Add a comment to a file](https://virustotal.readme.io/reference/files-comments-post.md) - [Get objects related to a file](https://virustotal.readme.io/reference/files-relationships.md) - [Get object descriptors related to a file](https://virustotal.readme.io/reference/files-relationships-ids.md) - [Get a crowdsourced Sigma rule object](https://virustotal.readme.io/reference/get-sigma-rules.md) - [Get a crowdsourced YARA ruleset](https://virustotal.readme.io/reference/get-yara-rulesets.md): Yara Ruleset used in our crowdsourced YARA results. - [Get votes on a file](https://virustotal.readme.io/reference/files-votes-get.md) - [Add a vote on a file](https://virustotal.readme.io/reference/files-votes-post.md) - [Get a summary of all behavior reports for a file](https://virustotal.readme.io/reference/file-all-behaviours-summary.md) - [Get a summary of all MITRE ATT&CK techniques observed in a file](https://virustotal.readme.io/reference/get-a-summary-of-all-mitre-attck-techniques-observed-in-a-file.md) - [Get all behavior reports for a file](https://virustotal.readme.io/reference/get-all-behavior-reports-for-a-file.md) - [Get a file behavior report from a sandbox](https://virustotal.readme.io/reference/get-file-behaviour-id.md) - [Get objects related to a behaviour report](https://virustotal.readme.io/reference/get-file-behaviours-relationship.md) - [Get object descriptors related to a behaviour report](https://virustotal.readme.io/reference/get-file-behaviours-relationship-descriptor.md) - [Get a detailed HTML behaviour report](https://virustotal.readme.io/reference/get-file-behaviours-html.md): HTML sandbox report - [Get the EVTX file generated during a file’s behavior analysis](https://virustotal.readme.io/reference/get-file-behaviours-evtx.md) - [Get the PCAP file generated during a file’s behavior analysis](https://virustotal.readme.io/reference/get-file-behaviours-pcap.md) - [Get the memdump file generated during a file’s behavior analysis](https://virustotal.readme.io/reference/get-file-behaviours-memdump.md) - [URLs](https://virustotal.readme.io/reference/url.md) - [Scan URL](https://virustotal.readme.io/reference/scan-url.md) - [Get a URL report](https://virustotal.readme.io/reference/url-info.md) - [Request a URL rescan (re-analyze)](https://virustotal.readme.io/reference/urls-analyse.md) - [Get comments on a URL](https://virustotal.readme.io/reference/urls-comments-get.md) - [Add a comment on a URL](https://virustotal.readme.io/reference/urls-comments-post.md) - [Get objects related to a URL](https://virustotal.readme.io/reference/urls-relationships.md) - [Get object descriptors related to a URL](https://virustotal.readme.io/reference/urls-relationships-ids.md) - [Get votes on a URL](https://virustotal.readme.io/reference/urls-votes-get.md) - [Add a vote on a URL](https://virustotal.readme.io/reference/urls-votes-post.md) - [Comments](https://virustotal.readme.io/reference/comments-api.md) - [Get latest comments](https://virustotal.readme.io/reference/get-comments.md) - [Get a comment object](https://virustotal.readme.io/reference/get-comment.md) - [Delete a comment](https://virustotal.readme.io/reference/comment-id-delete.md) - [Get objects related to a comment](https://virustotal.readme.io/reference/comments-relationships.md) - [Get object descriptors related to a comment](https://virustotal.readme.io/reference/comments-relationships-ids.md) - [Add a vote to a comment](https://virustotal.readme.io/reference/vote-comment.md) - [Get a URL / file analysis](https://virustotal.readme.io/reference/analysis.md) - [Get objects related to an analysis](https://virustotal.readme.io/reference/analyses-get-objects.md) - [Get object descriptors related to an analysis](https://virustotal.readme.io/reference/analyses-get-descriptors.md) - [Get a submission object](https://virustotal.readme.io/reference/get-submission.md) - [Get an operation object](https://virustotal.readme.io/reference/get-operations-id.md) - [Get an attack tactic object](https://virustotal.readme.io/reference/get-attack-tactics.md) - [Get objects related to an attack tactic](https://virustotal.readme.io/reference/get-attack-tactics-relationship.md) - [Get object descriptors related to an attack tactic](https://virustotal.readme.io/reference/get-attack-tactics-relationship-descriptor.md) - [Get an attack technique object](https://virustotal.readme.io/reference/get-attack-techniques.md) - [Get objects related to an attack technique](https://virustotal.readme.io/reference/get-attack-techniques-relationship.md) - [Get object descriptors related to an attack technique](https://virustotal.readme.io/reference/get-attack-techniques-relationship-descriptor.md) - [Popular Threat Categories](https://virustotal.readme.io/reference/popular-threat-categories.md): List of malware categories commonly used in AV verdicts (e.g., trojan, dropper, ...). - [Get a list of popular threat categories](https://virustotal.readme.io/reference/get-popular-threat-categories.md) - [Analyse code blocks with Code Insights](https://virustotal.readme.io/reference/analyse-binary.md) - [List Saved Searches](https://virustotal.readme.io/reference/list-saved-searches.md) - [Get a Saved Search](https://virustotal.readme.io/reference/get-saved-searches.md) - [Create a Saved Search](https://virustotal.readme.io/reference/create-saved-searches.md) - [Share a Saved Search](https://virustotal.readme.io/reference/share-saved-searches.md) - [Update a Saved Search](https://virustotal.readme.io/reference/update-saved-searches.md) - [Delete a Saved Search](https://virustotal.readme.io/reference/delete-saved-searches.md) - [Revoke access to a Saved Search](https://virustotal.readme.io/reference/revoke-saved-searches-access.md) - [Get object descriptors related to a Saved Search](https://virustotal.readme.io/reference/get-saved-searches-related-descriptors.md) - [Get objects related to a Saved Search](https://virustotal.readme.io/reference/get-saved-searches-relationships.md) - [Search & Metadata](https://virustotal.readme.io/reference/search.md) - [Search for files, URLs, domains, IPs and comments](https://virustotal.readme.io/reference/api-search.md) - [Advanced corpus search](https://virustotal.readme.io/reference/intelligence-search.md) - [Get file content search snippets](https://virustotal.readme.io/reference/intelligence-search-snippets.md) - [Get VirusTotal metadata](https://virustotal.readme.io/reference/metadata.md) - [Create a new collection](https://virustotal.readme.io/reference/collections-create.md) - [Get a collection](https://virustotal.readme.io/reference/collections-get.md) - [Update a collection](https://virustotal.readme.io/reference/collections-update.md) - [Delete a collection](https://virustotal.readme.io/reference/collections-delete.md) - [Get comments on a collection](https://virustotal.readme.io/reference/collections-comments.md) - [Add a comment to a collection](https://virustotal.readme.io/reference/collections-comments-create.md) - [Get objects related to a collection](https://virustotal.readme.io/reference/get-collections-relationship.md) - [Get object descriptors related to a collection](https://virustotal.readme.io/reference/get-collections-relationship-descriptor.md) - [Add new items to a collection](https://virustotal.readme.io/reference/collections-add-element.md) - [Delete items from a collection](https://virustotal.readme.io/reference/collections-delete-element.md) - [πŸ”’ List collections](https://virustotal.readme.io/reference/list-collections.md) - [πŸ”’ Export IOCs from a collection](https://virustotal.readme.io/reference/collections-export-iocs.md) - [πŸ”’ Export IOCs from a given collection's relationship](https://virustotal.readme.io/reference/collections-export-iocs-relationship.md) - [πŸ”’ Export aggregations from a collection](https://virustotal.readme.io/reference/collections-export-aggregations.md) - [πŸ”’ Search IoCs inside a collection](https://virustotal.readme.io/reference/search-iocs-inside-a-collection.md) - [Zipping files](https://virustotal.readme.io/reference/zip-files.md) - [Create a password-protected ZIP with VirusTotal files](https://virustotal.readme.io/reference/create-zip-files.md) - [Check a ZIP file’s status](https://virustotal.readme.io/reference/get-zip-files.md) - [Get a ZIP file’s download URL](https://virustotal.readme.io/reference/zip-files-download-url.md) - [Download a ZIP file](https://virustotal.readme.io/reference/zip-files-download.md) - [List Crowdsourced YARA Rules](https://virustotal.readme.io/reference/list-crowdsourced-yara-rules.md) - [Get a Crowdsourced YARA rule](https://virustotal.readme.io/reference/get-a-crowdsourced-yara-rule.md) - [Get objects related to a Crowdsourced YARA rule](https://virustotal.readme.io/reference/crowdsourced-yara-rule-relationship-endpoint.md) - [Get objects descriptors related to a Crowdsourced YARA rule](https://virustotal.readme.io/reference/crowdsourced-yara-rule-relationship-descriptors-endpoint.md) - [IoC Stream](https://virustotal.readme.io/reference/ioc-stream-introduction.md) - [Get objects from the IoC Stream](https://virustotal.readme.io/reference/get-objects-from-the-ioc-stream.md) - [Delete notifications from the IoC Stream](https://virustotal.readme.io/reference/delete-notifications-from-the-ioc-stream.md) - [Get an IoC Stream notification](https://virustotal.readme.io/reference/get-an-ioc-stream-notification.md) - [Delete an IoC Stream notification](https://virustotal.readme.io/reference/delete-an-ioc-stream-notification.md) - [πŸ”’ Livehunt](https://virustotal.readme.io/reference/api-livehunt.md) - [Get Livehunt rulesets](https://virustotal.readme.io/reference/list-hunting-rulesets.md) - [Create a new Livehunt ruleset](https://virustotal.readme.io/reference/create-hunting-ruleset.md) - [Remove all Livehunt rulesets](https://virustotal.readme.io/reference/delete-all-hunting-rulesets.md) - [Get a Livehunt ruleset](https://virustotal.readme.io/reference/get-hunting-ruleset.md) - [Update a Livehunt ruleset](https://virustotal.readme.io/reference/modify-hunting-ruleset.md) - [Check if a user or group is a Livehunt ruleset editor](https://virustotal.readme.io/reference/check-user-hunting-ruleset-editor.md) - [Revoke Livehunt ruleset edit permission from a user or group](https://virustotal.readme.io/reference/delete-hunting-ruleset-editor.md) - [Delete a Livehunt ruleset](https://virustotal.readme.io/reference/delete-hunting-ruleset.md) - [Get objects related to a Livehunt ruleset](https://virustotal.readme.io/reference/get-hunting-ruleset-full-relationships.md) - [Get object descriptors related to a Livehunt ruleset](https://virustotal.readme.io/reference/get-hunting-ruleset-relationship.md) - [Grant Livehunt ruleset edit permissions for a user or group](https://virustotal.readme.io/reference/edit-hunting-ruleset-relationship.md) - [Transfer Livehunt ruleset to another user](https://virustotal.readme.io/reference/transfer-livehunt-ruleset-to-another-user.md) - [Get Livehunt notifications](https://virustotal.readme.io/reference/list-hunting-notifications.md) - [Delete Livehunt notifications](https://virustotal.readme.io/reference/delete-hunting-notifications.md) - [Get a Livehunt notification object](https://virustotal.readme.io/reference/get-hunting-notification.md) - [Delete a Livehunt notification](https://virustotal.readme.io/reference/delete-hunting-notification.md) - [Retrieve file objects for Livehunt notifications](https://virustotal.readme.io/reference/get-hunting-notification-files.md) - [πŸ”’ Retrohunt](https://virustotal.readme.io/reference/api-retrohunt.md) - [Get a list of Retrohunt jobs](https://virustotal.readme.io/reference/get-retrohunt-jobs.md) - [Create a new Retrohunt job](https://virustotal.readme.io/reference/create-retrohunt-job.md) - [Get a Retrohunt job object](https://virustotal.readme.io/reference/get-retrohunt-job.md) - [Delete a Retrohunt job](https://virustotal.readme.io/reference/delete-retrohunt-job.md) - [Abort a Retrohunt job](https://virustotal.readme.io/reference/abort-retrohunt-job.md) - [Retrieve matches for a Retrohunt job](https://virustotal.readme.io/reference/get-retrohunt-job-relationships.md) - [Search graphs](https://virustotal.readme.io/reference/graphs.md) - [Create a graph](https://virustotal.readme.io/reference/create-graphs.md) - [Get a graph object](https://virustotal.readme.io/reference/graphs-info.md) - [Update a graph object](https://virustotal.readme.io/reference/graphs-update.md) - [Delete a graph](https://virustotal.readme.io/reference/graphs-delete.md) - [Get comments on a graph](https://virustotal.readme.io/reference/get-graph-comments.md) - [Add a comment to a graph](https://virustotal.readme.io/reference/post-graphs-comments.md) - [Get objects related to a graph](https://virustotal.readme.io/reference/graphs-relationships.md) - [Get object descriptors related to a graph](https://virustotal.readme.io/reference/graphs-relationships-ids.md) - [Get users and groups that can view a graph](https://virustotal.readme.io/reference/graphs-viewers.md) - [Grant users and groups permission to see a graph](https://virustotal.readme.io/reference/graphs-add-viewer.md) - [Check if a user or group can view a graph](https://virustotal.readme.io/reference/graphs-check-viewer.md) - [Revoke view permission from a user or group](https://virustotal.readme.io/reference/graphs-delete-viewer.md) - [Get users and groups that can edit a graph](https://virustotal.readme.io/reference/graphs-editors.md) - [Grant users and groups permission to edit a graph](https://virustotal.readme.io/reference/graphs-add-editor.md) - [Check if a user or group can edit a graph](https://virustotal.readme.io/reference/graphs-check-editor.md) - [Revoke edit graph permissions from a user or group](https://virustotal.readme.io/reference/graphs-delete-editor.md) - [πŸ”’ Files](https://virustotal.readme.io/reference/private-files-api.md) - [Upload a file](https://virustotal.readme.io/reference/upload-file-private-scanning.md): Privately upload and analyse a file. > πŸ“˜ File size If the file to be uploaded is bigger than 32MB, please use the [/private/files/upload_url](ref:private-files-upload-url) endpoint instead which admits files up to 650MB. - [List private files](https://virustotal.readme.io/reference/list-private-files.md) - [Get a URL for uploading large files](https://virustotal.readme.io/reference/private-files-upload-url.md) - [Rescan a private file](https://virustotal.readme.io/reference/rescan-a-private-file.md) - [Get a private file report](https://virustotal.readme.io/reference/private-files-info.md) - [Delete a private file report](https://virustotal.readme.io/reference/delete-file-private-scanning.md) - [Get objects related to a private file](https://virustotal.readme.io/reference/private-files-relationships.md) - [Get object descriptors related to a file](https://virustotal.readme.io/reference/get-private-files-relationship-descriptor.md) - [List private analyses](https://virustotal.readme.io/reference/list-private-analyses.md) - [Get a private analysis](https://virustotal.readme.io/reference/private-analysis.md) - [Get objects related to a private analysis](https://virustotal.readme.io/reference/get-private-analyses-relationship.md) - [Get object descriptors related to a private analysis](https://virustotal.readme.io/reference/get-private-analyses-relationship-descriptor.md) - [Get a behaviour report from a private file](https://virustotal.readme.io/reference/get-private-file-behaviour-id.md) - [Get the behaviour reports from a private file](https://virustotal.readme.io/reference/get-all-behaviour-reports-from-a-private-file.md) - [Get objects related to a private file's behaviour report](https://virustotal.readme.io/reference/get-private-file-behaviours-relationship.md) - [Get object descriptors related to a private file's behaviour report](https://virustotal.readme.io/reference/get-private-file-behaviours-relationship-descriptor.md) - [Get a summary of all behavior reports for a file](https://virustotal.readme.io/reference/get-private-files-behaviour-summary.md) - [Get a summary of all MITRE ATT&CK techniques observed in a file](https://virustotal.readme.io/reference/get-summary-all-mitre-attack-techniques-observed-in-a-file.md) - [Get a detailed HTML behaviour report](https://virustotal.readme.io/reference/get-private-files-behaviours-html.md): HTML sandbox report - [Get the EVTX file generated during a private file’s behavior analysis](https://virustotal.readme.io/reference/get-private-files-behaviours-evtx.md) - [Get the PCAP file generated during a private file’s behavior analysis](https://virustotal.readme.io/reference/get-private-files-behaviours-pcap.md) - [Get the memdump file generated during a private file’s behavior analysis](https://virustotal.readme.io/reference/get-private-files-behaviours-memdump.md) - [πŸ”’ URLs](https://virustotal.readme.io/reference/private-urls-api.md) - [Private Scan URL](https://virustotal.readme.io/reference/private-scan-url.md) - [Get a URL analysis report](https://virustotal.readme.io/reference/get-a-private-url-analysis-report.md) - [Get objects related to a private URL](https://virustotal.readme.io/reference/private-get-objects-related-to-a-url.md) - [Get object descriptors related to a private URL](https://virustotal.readme.io/reference/private-get-object-descriptors-related-to-a-url.md) - [Zipping private files](https://virustotal.readme.io/reference/private-scanning-zipping-files.md) - [Create a password-protected ZIP with VirusTotal private files](https://virustotal.readme.io/reference/private-scanning-zip-files.md) - [Check a ZIP file’s status](https://virustotal.readme.io/reference/private-scanning-get-zip-file.md) - [Get a ZIP file’s download URL](https://virustotal.readme.io/reference/private-scanning-get-zip-download-url.md) - [Download a ZIP file](https://virustotal.readme.io/reference/private-scanning-download-zip-file.md) - [πŸ”’ File intelligence feed](https://virustotal.readme.io/reference/file-feed.md) - [Get a per-minute file feed batch](https://virustotal.readme.io/reference/feeds-file.md) - [Get a hourly file feed batch](https://virustotal.readme.io/reference/feeds-file-hourly.md) - [Download a file published in the file feed](https://virustotal.readme.io/reference/file-feed-download.md) - [πŸ”’ Sandbox analyses feed](https://virustotal.readme.io/reference/sandbox-feed.md) - [Get a per-minute file behaviour feed batch](https://virustotal.readme.io/reference/feeds-file-behaviour.md) - [Get an hourly file behaviour feed batch](https://virustotal.readme.io/reference/feeds-file-behaviour-hourly.md) - [Get the EVTX file generated during a file’s behavior analysis](https://virustotal.readme.io/reference/file-behaviour-feed-evtx.md) - [Get the memdump file generated during a file’s behavior analysis](https://virustotal.readme.io/reference/file-behaviour-feed-memdump.md) - [Get the PCAP file generated during a file’s behavior analysis](https://virustotal.readme.io/reference/file-behaviour-feed-pcap.md) - [Get a file behaviour's detailed HTML report](https://virustotal.readme.io/reference/file-behaviour-feed-html.md) - [πŸ”’ Domain intelligence feed](https://virustotal.readme.io/reference/domain-feed.md) - [Get a minutely domain feed batch](https://virustotal.readme.io/reference/feedsdomains2time.md) - [Get an hourly domain feed batch](https://virustotal.readme.io/reference/feedsdomainshourly2time.md) - [πŸ”’ IP intelligence feed](https://virustotal.readme.io/reference/ip-feed.md) - [Get a minutely IP address feed batch](https://virustotal.readme.io/reference/get-feeds-ip-addresses.md) - [Get an hourly IP address feed batch](https://virustotal.readme.io/reference/get-feeds-ip-addresses-hourly.md) - [πŸ”’ URL intelligence feed](https://virustotal.readme.io/reference/url-feed.md) - [Get a minutely URL feed batch](https://virustotal.readme.io/reference/feeds-url.md) - [Get an hourly URL feed batch](https://virustotal.readme.io/reference/feeds-url-hourly.md) - [Get a user object](https://virustotal.readme.io/reference/user.md) - [Update a user object](https://virustotal.readme.io/reference/patch-user-id.md) - [Delete a user](https://virustotal.readme.io/reference/delete-user-id.md) - [Get objects related to a user](https://virustotal.readme.io/reference/users-relationships.md): Retrieve related objects IDs to an User - [Get object descriptors related to a user](https://virustotal.readme.io/reference/get-users-relationships-ids.md) - [Get a group object](https://virustotal.readme.io/reference/groups.md) - [Update a group object](https://virustotal.readme.io/reference/patch-group.md) - [Get administrators for a group](https://virustotal.readme.io/reference/get-group-administrators.md) - [Manage Roles](https://virustotal.readme.io/reference/patch-group-users-roles.md) - [Check if a user is a group admin](https://virustotal.readme.io/reference/check-user-group-administrator.md) - [Get group users](https://virustotal.readme.io/reference/get-group-users.md) - [Check if a user is a group member](https://virustotal.readme.io/reference/check-user-in-group.md) - [Remove a user from a group](https://virustotal.readme.io/reference/delete-user-from-group.md) - [Add users to a group](https://virustotal.readme.io/reference/update-group-users.md) - [Get objects related to a group](https://virustotal.readme.io/reference/groups-relationships.md) - [Get object descriptors related to a group](https://virustotal.readme.io/reference/groups-relationships-ids.md) - [Get a user’s API usage](https://virustotal.readme.io/reference/user-api-usage.md) - [Get a group’s API usage](https://virustotal.readme.io/reference/group-api-usage.md) - [Get a group's usage per feature](https://virustotal.readme.io/reference/get-group-usage.md) - [Create a new Service Account](https://virustotal.readme.io/reference/create-a-new-service-account.md) - [Get Service Accounts of a group](https://virustotal.readme.io/reference/get-service-accounts-of-a-group.md) - [Get a Service Account object](https://virustotal.readme.io/reference/get-a-service-account-object.md) - [Update a service account object](https://virustotal.readme.io/reference/patch-group-service-accounts-roles.md): Update roles and quota limits of Service Accounts within your group. - [Get Activity Logs](https://virustotal.readme.io/reference/get-activity-log.md) - [Overview](https://virustotal.readme.io/reference/widget-overview.md) - [Rendering](https://virustotal.readme.io/reference/render-widget.md) - [Get a widget rendering URL](https://virustotal.readme.io/reference/widgeturl.md) - [Retrieve the widget's HTML content](https://virustotal.readme.io/reference/widgethtmltoken.md) - [Theming](https://virustotal.readme.io/reference/theme.md) - [Activity Log](https://virustotal.readme.io/reference/activity-log.md) - [Analyses](https://virustotal.readme.io/reference/analyses-object.md): Partner contributors' analyses for files and URLs. - [πŸ”€ item](https://virustotal.readme.io/reference/analysis-object-item.md): Item being analysed - [Attack Tactics](https://virustotal.readme.io/reference/attack-tactics.md): Information about attack tactics - [πŸ”€ attack_techniques](https://virustotal.readme.io/reference/attack-tactic-object-attack-techniques.md): Attack tactic's techniques. - [Attack Techniques](https://virustotal.readme.io/reference/attack-techniques.md): Information about attack techniques - [πŸ”€ attack_tactics](https://virustotal.readme.io/reference/attack-technique-object-attack-tactics.md): Attack technique's tactics. - [πŸ”€ parent_technique](https://virustotal.readme.io/reference/attack-technique-object-parent-technique.md): Attack technique's parent technique. - [πŸ”€ revoking_technique](https://virustotal.readme.io/reference/attack-technique-object-revoking-technique.md): Attack technique's revoking technique. - [πŸ”€ subtechniques](https://virustotal.readme.io/reference/attack-technique-object-subtechniques.md): Attack technique's sub-techniques. - [πŸ”€πŸ”’ threat_actors](https://virustotal.readme.io/reference/attack-technique-object-threat-actors.md): Attack technique's threat actors - [Collections](https://virustotal.readme.io/reference/collections-object.md): Information about collections - [πŸ”€ autogenerated_graphs](https://virustotal.readme.io/reference/collection-object-autogenerated-graphs.md): Collection's techniques. - [πŸ”€ comments](https://virustotal.readme.io/reference/collection-object-comments.md): Collection's comments - [πŸ”€ domains](https://virustotal.readme.io/reference/collection-object-domains.md): Collection's domains - [πŸ”€ files](https://virustotal.readme.io/reference/collection-object-files.md): Collection's files. - [πŸ”€ ip_addresses](https://virustotal.readme.io/reference/collection-object-ip-addresses.md): Collection's IP addresses - [πŸ”€ owner](https://virustotal.readme.io/reference/collection-object-owner.md): Collection's owner - [πŸ”€ references](https://virustotal.readme.io/reference/collection-object-references.md): Collection's references - [πŸ”€πŸ”’ related_collections](https://virustotal.readme.io/reference/collection-object-related-collections.md): Related collections for a given collection. - [πŸ”€πŸ”’ related_references](https://virustotal.readme.io/reference/collection-object-related-references.md): Related references for a given collection. - [πŸ”€πŸ”’ threat_actors](https://virustotal.readme.io/reference/collection-object-threat-actors.md): Collection's threat actors - [πŸ”€ urls](https://virustotal.readme.io/reference/collection-object-urls.md): Collection's URLs - [Comments](https://virustotal.readme.io/reference/comment-object.md): comment object - [πŸ”€ author](https://virustotal.readme.io/reference/comment-object-author.md): Comment votes. - [Domains](https://virustotal.readme.io/reference/domains-object.md): Along with URLs, VirusTotal stores information related network locations, as domains and IP addresses. Within this section we will go through the information provided by Domain objects. - [πŸ”€πŸ”’ caa_records](https://virustotal.readme.io/reference/domain-object-caa-record.md): Records CAA for the domain. - [πŸ”€πŸ”’ cname_records](https://virustotal.readme.io/reference/domain-object-cname-records.md): Records CNAME for the domain. - [πŸ”€ collections](https://virustotal.readme.io/reference/domain-object-collections.md): Collections containing this domain. - [πŸ”€ comments](https://virustotal.readme.io/reference/domain-object-comments.md): Comments in Domain objects - [πŸ”€ communicating_files](https://virustotal.readme.io/reference/domain-object-communicating-files.md) - [πŸ”€πŸ”’ downloaded_files](https://virustotal.readme.io/reference/domain-object-downloaded-files.md) - [πŸ”€ graphs](https://virustotal.readme.io/reference/domain-object-graphs.md) - [πŸ”€ historical_ssl_certificates](https://virustotal.readme.io/reference/domain-object-historical-ssl-certificates.md): All SSL certificates that have been associated with the domain at some moment in time. - [πŸ”€ historical_whois](https://virustotal.readme.io/reference/domain-object-historical-whois.md): All whois records that have been associated with the domain at some moment in time. - [πŸ”€ immediate_parent](https://virustotal.readme.io/reference/domain-object-immediate-parent.md): Domain's immediate parent. - [πŸ”€πŸ”’ mx_records](https://virustotal.readme.io/reference/domain-object-mx-records.md): Records MX for the domain. - [πŸ”€πŸ”’ ns_records](https://virustotal.readme.io/reference/domain-object-ns-records.md): Records NS for the domain. - [πŸ”€ parent](https://virustotal.readme.io/reference/domain-object-parent.md): Domain's parent. - [πŸ”€ referrer_files](https://virustotal.readme.io/reference/domain-object-referrer-files.md): Files containing the domain on its strings. - [πŸ”€ related_comments](https://virustotal.readme.io/reference/domain-object-related-comments.md): Comments posted in related objects - [πŸ”€πŸ”’ related_references](https://virustotal.readme.io/reference/domain-object-related-references.md): Related references for a given domain. - [πŸ”€πŸ”’ related_threat_actors](https://virustotal.readme.io/reference/domain-object-related-threat-actors.md): Related Threat Actors for a given domain. - [πŸ”€ resolutions](https://virustotal.readme.io/reference/domain-object-resolutions.md): Domain's IP resolutions. - [πŸ”€ siblings](https://virustotal.readme.io/reference/domain-object-siblings.md) - [πŸ”€πŸ”’ soa_records](https://virustotal.readme.io/reference/domain-object-soa-records.md): Records SOA for the domain. - [πŸ”€ subdomains](https://virustotal.readme.io/reference/domain-object-subdomains.md): Domain's subdomains. - [πŸ”€πŸ”’ urls](https://virustotal.readme.io/reference/domain-object-urls.md): Domain's URLs. - [πŸ”€πŸ§‘β€πŸ’» user_votes](https://virustotal.readme.io/reference/domain-object-user-votes.md): Domain's user votes. - [πŸ”€ votes](https://virustotal.readme.io/reference/domain-object-votes.md): Domain's votes. - [Files](https://virustotal.readme.io/reference/files.md): Information about files - [androguard](https://virustotal.readme.io/reference/file-object-androguard.md): information about Android files. - [asf_info](https://virustotal.readme.io/reference/file-object-asf-info.md): information about Microsoft Advanced Streaming/Systems Format (ASF) files. - [authentihash](https://virustotal.readme.io/reference/file-object-authentihash.md): hash to verify PE files. - [bundle_info](https://virustotal.readme.io/reference/file-object-bundle-info.md): information about compressed files. - [class_info](https://virustotal.readme.io/reference/file-object-class-info.md): information about Java .class bytecode files. - [crowdsourced_ids_results](https://virustotal.readme.io/reference/file-object-crowdsourced-ids-results.md): IDS matches for the file. - [crowdsourced_ids_stats](https://virustotal.readme.io/reference/file-object-crowdsourced-ids-stats.md): IDS results stats. - [crowdsourced_yara_results](https://virustotal.readme.io/reference/file-object-crowdsourced-yara-results.md): YARA matches from crowdsourced rules. - [deb_info](https://virustotal.readme.io/reference/file-object-deb-info.md): information about Debian packages. - [detectiteasy](https://virustotal.readme.io/reference/file-object-detectiteasy.md): File type identification tool. - [dmg_info](https://virustotal.readme.io/reference/file-object-dmg-info.md): information about mountable macOS disk images. - [dot_net_assembly](https://virustotal.readme.io/reference/file-object-dot-net-assembly.md): information about Microsoft .NET files. - [dot_net_guids](https://virustotal.readme.io/reference/file-object-dot-net-guids.md): identifiers for Microsoft .NET assemblies. - [elf_info](https://virustotal.readme.io/reference/file-object-elf-info.md): information about Unix ELF files. - [πŸ”’ exiftool](https://virustotal.readme.io/reference/file-object-exiftool.md): information about EXIF metadata from files. - [html_info](https://virustotal.readme.io/reference/file-object-html-info.md): Information from HTML files - [image_code_injections](https://virustotal.readme.io/reference/file-object-image-code-injections.md): code injection inside image files. - [ipa_info](https://virustotal.readme.io/reference/file-object-ipa-info.md): information about iOS App Store Package files. - [isoimage_info](https://virustotal.readme.io/reference/file-object-isoimage-info.md): information about ISO image files. - [jar_info](https://virustotal.readme.io/reference/file-object-jar-info.md): information about Java Archive files. - [javascript_info](https://virustotal.readme.io/reference/file-object-file-javascript-info.md): Information extracted out of Javascript files - [known_distributors](https://virustotal.readme.io/reference/file-object-known-distributors.md): Information about the file's distributors - [lnk_info](https://virustotal.readme.io/reference/file-object-lnk-info.md): information about Microsoft Windows LNK files - [macho_info](https://virustotal.readme.io/reference/file-object-macho-info.md): information about Apple MachO files. - [magic](https://virustotal.readme.io/reference/file-object-magic.md): identification of files via magic number. - [πŸ”’ malware_config](https://virustotal.readme.io/reference/file-object-malware-config.md): Malware configuration for certain malware families - [monitor_info](https://virustotal.readme.io/reference/file-object-monitor-info.md): Information from VT monitor - [nsrl_info](https://virustotal.readme.io/reference/file-object-nsrl-info.md): Whitelisted files from the NSRL. - [πŸ”’ office_info](https://virustotal.readme.io/reference/file-object-office-info.md): Microsoft Office files structure information. - [πŸ”’ openxml_info](https://virustotal.readme.io/reference/file-object-openxml-info.md): Microsoft OpenXML files information. - [packers](https://virustotal.readme.io/reference/file-object-packers.md): identification of packers used by files. - [password_info](https://virustotal.readme.io/reference/file-object-password-info.md): Information from password protected files - [pdf_info](https://virustotal.readme.io/reference/file-object-pdf-info.md): information about Adobe PDF files. - [pe_info](https://virustotal.readme.io/reference/file-object-pe-info.md): Microsoft Windows Portable Executable file format info. - [popular_threat_classification](https://virustotal.readme.io/reference/file-object-popular-threat-classification.md): Human readable names extracted from the AV verdicts and clustering hashes - [powershell_info](https://virustotal.readme.io/reference/file-object-powershell-info.md) - [rombios_info](https://virustotal.readme.io/reference/file-object-rombios-info.md): information about BIOS, EFI, UEFI and related archives. - [πŸ”’ rtf_info](https://virustotal.readme.io/reference/file-object-rtf-info.md): information about Microsoft Rich Text Format files. - [sandbox_verdicts](https://virustotal.readme.io/reference/file-object-sandbox-verdicts.md): Sandbox verdicts for the file. - [sigma_analysis_results](https://virustotal.readme.io/reference/file-object-sigma-analysis-results.md): Sigma results for the file. - [sigma_analysis_stats](https://virustotal.readme.io/reference/file-object-sigma-analysis-stats.md): Sigma analysis stats for the file. - [signature_info](https://virustotal.readme.io/reference/file-object-signature-info.md): Information about signed PE and Mach-O files. - [snort](https://virustotal.readme.io/reference/file-object-snort.md): Matched Snort alerts in PCAP network captures. - [suricata](https://virustotal.readme.io/reference/file-object-suricata.md): Matched suricata alerts for PCAP network captures. - [ssdeep](https://virustotal.readme.io/reference/file-object-ssdeep.md): CTPH hash of the file content. - [swf_info](https://virustotal.readme.io/reference/file-object-swf-info.md): Information about Adobe Shockwave Flash files. - [telfhash](https://virustotal.readme.io/reference/file-object-telfhash.md): File's Trend Micro ELF Hash (aka telfhash) - [tlsh](https://virustotal.readme.io/reference/file-object-tlsh.md): Trend Micro's TLSH hash - [traffic_inspection](https://virustotal.readme.io/reference/file-object-files-traffic-inspection.md): Traffic notions extracted from PCAP network captures. - [trid](https://virustotal.readme.io/reference/file-object-trid.md): file type identification tool. - [vba_info](https://virustotal.readme.io/reference/file-object-vba-info.md): VBA macros information - [wireshark](https://virustotal.readme.io/reference/file-object-wireshark.md): Metadata produced by Wireshark when acting on the file. - [πŸ”€πŸ”’ analyses](https://virustotal.readme.io/reference/file-object-analyses.md): All analyses made for a given file. - [πŸ”€ behaviours](https://virustotal.readme.io/reference/file-object-behaviours.md): Behaviour reports for the file. - [πŸ”€ bundled_files](https://virustotal.readme.io/reference/file-object-bundled-files.md): Files bundled within the file. - [πŸ”€πŸ”’ carbonblack_children](https://virustotal.readme.io/reference/file-object-carbonblack-children.md): Files derived from the file according to Carbon Black. - [πŸ”€πŸ”’ carbonblack_parents](https://virustotal.readme.io/reference/file-object-carbonblack-parents.md): Files from where the file was derived according to Carbon Black. - [πŸ”€ collections](https://virustotal.readme.io/reference/file-object-collections.md): Collections containing this file. - [πŸ”€ comments](https://virustotal.readme.io/reference/file-object-comments.md): Comments in file objects. - [πŸ”€πŸ”’ compressed_parents](https://virustotal.readme.io/reference/file-object-compressed-parents.md): File bundles from where the file was found inside. - [πŸ”€ contacted_domains](https://virustotal.readme.io/reference/file-object-contacted-domains.md): Domains contacted by a given file - [πŸ”€ contacted_ips](https://virustotal.readme.io/reference/file-object-contacted-ips.md): IP addresses contacted by a given file - [πŸ”€ contacted_urls](https://virustotal.readme.io/reference/file-object-contacted-urls.md): URL addresses contacted by a given file - [πŸ”€ dropped_files](https://virustotal.readme.io/reference/file-object-dropped-files.md) - [πŸ”€πŸ”’ email_attachments](https://virustotal.readme.io/reference/file-object-email-attachments.md): Files attached to a given email file. - [πŸ”€πŸ”’ email_parents](https://virustotal.readme.io/reference/file-object-email-parents.md): Email files containing the file. - [πŸ”€πŸ”’ embedded_domains](https://virustotal.readme.io/reference/file-object-embedded-domains.md): Domain names embedded in the file. - [πŸ”€πŸ”’ embedded_ips](https://virustotal.readme.io/reference/file-object-embedded-ips.md): IP addresses embedded in the file. - [πŸ”€πŸ”’ embedded_urls](https://virustotal.readme.io/reference/file-object-embedded-urls.md): IP addresses embedded in the file. - [πŸ”€ execution_parents](https://virustotal.readme.io/reference/file-object-execution-parents.md): Files that executed the file. - [πŸ”€ graphs](https://virustotal.readme.io/reference/file-object-graphs.md) - [πŸ”€πŸ”’ itw_domains](https://virustotal.readme.io/reference/file-object-itw-domains.md): In the wild domain names from where the file has been downloaded. - [πŸ”€πŸ”’ itw_ips](https://virustotal.readme.io/reference/file-object-itw-ips.md): In the wild IP addresses from where the file has been downloaded. - [πŸ”€πŸ”’ itw_urls](https://virustotal.readme.io/reference/file-object-files-itw-urls.md): In the wild URLs from where the file has been downloaded. - [πŸ”€πŸ”’ overlay_children](https://virustotal.readme.io/reference/file-object-overlay-children.md): Files contained by the file as an overlay. - [πŸ”€πŸ”’ overlay_parents](https://virustotal.readme.io/reference/file-object-overlay-parents.md): Files containing the file as an overlay. - [πŸ”€πŸ”’ pcap_children](https://virustotal.readme.io/reference/file-object-pcap-children.md): PCAP files seen in the file. - [πŸ”€πŸ”’ pcap_parents](https://virustotal.readme.io/reference/file-object-pcap-parents.md): PCAP files that contain the file. - [πŸ”€ pe_resource_children](https://virustotal.readme.io/reference/file-object-pe-resource-children.md): PE files contained by the file as a resource. - [πŸ”€ pe_resource_parents](https://virustotal.readme.io/reference/file-object-pe-resource-parents.md): PE files containing the file as a resource. - [πŸ”€πŸ”’ related_references](https://virustotal.readme.io/reference/file-object-related-references.md): Related references for a given file. - [πŸ”€πŸ”’ related_threat_actors](https://virustotal.readme.io/reference/file-object-related-threat-actors.md): Related Threat Actors for a given file. - [πŸ”€πŸ”’ screenshots](https://virustotal.readme.io/reference/file-object-screenshots.md): Screenshots obtained from the execution of the file. - [πŸ”€ sigma_analysis](https://virustotal.readme.io/reference/file-object-sigma-analysis.md): Last Sigma analysis results. - [πŸ”€πŸ”’ similar_files](https://virustotal.readme.io/reference/file-object-similar-files.md): Files similar to the file. - [πŸ”€πŸ”’ submissions](https://virustotal.readme.io/reference/file-object-submissions.md): File submissions - [πŸ”€πŸ”’ urls_for_embedded_js](https://virustotal.readme.io/reference/file-object-urls-for-embedded-js.md): URLs where a given JS file is embedded - [πŸ”€πŸ§‘β€πŸ’» user_votes](https://virustotal.readme.io/reference/file-object-user-votes.md): Votes for a given file made by the current user - [πŸ”€ votes](https://virustotal.readme.io/reference/file-object-votes.md): Votes for a given file - [πŸ”€ memory_pattern_domains](https://virustotal.readme.io/reference/file-object-memory-pattern-domains.md) - [πŸ”€ memory_pattern_ips](https://virustotal.readme.io/reference/file-object-memory-pattern-ips.md) - [πŸ”€ memory_pattern_urls](https://virustotal.readme.io/reference/file-object-memory-pattern-urls.md) - [Files Behaviour](https://virustotal.readme.io/reference/file-behaviour-summary.md): File behaviour reports - [dns_lookups](https://virustotal.readme.io/reference/dns-lookup.md): DNS queries - [files_copied](https://virustotal.readme.io/reference/file-behaviour-object-files-copied.md): Object that describes a file copy or move. - [files_dropped](https://virustotal.readme.io/reference/dropped-files.md): Interesting files written to disk during execution. - [http_conversations](https://virustotal.readme.io/reference/http-conversation.md): HTTP Calls. - [ip_traffic](https://virustotal.readme.io/reference/ip-traffic.md): Outgoing connections seen during the execution of the given file. - [permissions_checked](https://virustotal.readme.io/reference/permission-check.md): Records a query to see whether a given component/package/process/service has a particular permission. - [processes_tree](https://virustotal.readme.io/reference/process.md): Created processes during the execution of a given file. - [sms_sent](https://virustotal.readme.io/reference/sms.md): Sent SMSs during the execution of the file under study. - [tags](https://virustotal.readme.io/reference/behaviour-tag.md): Sandbox behavior tagged with a complex operation - [verdicts](https://virustotal.readme.io/reference/verdict-tag.md): Verdicts to tag a sample from sandbox behaviour - [πŸ”€ file](https://virustotal.readme.io/reference/file-behaviour-object-file.md): File behaviour's file - [πŸ”€ attack_techniques](https://virustotal.readme.io/reference/file-behaviour-object-attack-techniques.md): File behaviour's ATT&CK techniques - [Graphs](https://virustotal.readme.io/reference/graph-object.md): Information about graphs. - [πŸ”€ comments](https://virustotal.readme.io/reference/graph-comments.md): Comments in a graph - [πŸ”€ editors](https://virustotal.readme.io/reference/graph-editors.md): Users that can edit a graph - [πŸ”€ group](https://virustotal.readme.io/reference/graph-group.md): Group owning the graph - [πŸ”€ items](https://virustotal.readme.io/reference/graph-items.md): Contained objects in the graph - [πŸ”€ owner](https://virustotal.readme.io/reference/graph-owner.md): User owning the graph - [πŸ”€ viewers](https://virustotal.readme.io/reference/graph-viewers.md): Users that can view a graph - [Groups](https://virustotal.readme.io/reference/group-object.md): Groups of users in VirusTotal - [πŸ”€πŸ§‘β€πŸ’» administrators](https://virustotal.readme.io/reference/group-administrators.md): Users administrating the group - [πŸ”€πŸ§‘β€πŸ’» graphs](https://virustotal.readme.io/reference/group-graphs.md): VT Graphs the group is owner/editor/viewer of. - [πŸ”€πŸ§‘β€πŸ’» users](https://virustotal.readme.io/reference/group-users.md): Group members - [Hunting Notifications](https://virustotal.readme.io/reference/hunting-notification-object.md): Generated notifications by matches in Hunting Rulesets - [Hunting Rulesets](https://virustotal.readme.io/reference/hunting-ruleset-object.md): User's hunting rulesets - [πŸ”€ πŸ§‘β€πŸ’»owner](https://virustotal.readme.io/reference/rulesets-owner.md): Collection's owner - [πŸ”€πŸ§‘β€πŸ’» editors](https://virustotal.readme.io/reference/hunting-rulesets-editors.md): Users and groups that can edit the rules - [πŸ”€πŸ§‘β€πŸ’» viewers](https://virustotal.readme.io/reference/rulesets-viewers.md): Users and groups that can edit the rules - [πŸ”€πŸ§‘β€πŸ’» hunting_notification_files](https://virustotal.readme.io/reference/hunting-ruleset-notification-files.md): Files associated to notifications triggered by the ruleset. - [IoC-Stream Notifications](https://virustotal.readme.io/reference/ioc-stream-notifications.md): Generated notifications by matches in the IoC-Stream - [IP addresses](https://virustotal.readme.io/reference/ip-object.md): IPv4 and IPv6 addresses are other of the network locations that VirusTotal stores information about. A description of the fields stored within these objects follows. - [πŸ”€ collections](https://virustotal.readme.io/reference/ip-object-collections.md): Collections containing this IP address. - [πŸ”€ comments](https://virustotal.readme.io/reference/ip-object-comments.md): Comments posted in a IP address. - [πŸ”€ communicating_files](https://virustotal.readme.io/reference/ip-object-communicating-files.md) - [πŸ”€πŸ”’ downloaded_files](https://virustotal.readme.io/reference/ip-object-downloaded-files.md) - [πŸ”€ graphs](https://virustotal.readme.io/reference/ip-object-graphs.md) - [πŸ”€ historical_ssl_certificates](https://virustotal.readme.io/reference/ip-object-historical-ssl-certificates.md): All SSL certificates that have been associated with the IP at some moment in time. - [πŸ”€ historical_whois](https://virustotal.readme.io/reference/ip-object-historical-whois.md): All whois records associated with the IP address at some moment in time. - [πŸ”€ related_comments](https://virustotal.readme.io/reference/ip-object-related-comments.md): Comments posted in related objects. - [πŸ”€πŸ”’ related_references](https://virustotal.readme.io/reference/ip-object-related-references.md): Related references for a given domain. - [πŸ”€πŸ”’ related_threat_actors](https://virustotal.readme.io/reference/ip-object-related-threat-actors.md): Related Threat Actors for a given IP address. - [πŸ”€ referrer_files](https://virustotal.readme.io/reference/ip-object-referrer-files.md): File containing the IP address on its strings. - [πŸ”€ resolutions](https://virustotal.readme.io/reference/ip-object-resolutions.md): Domain resolutions for a IP address. - [πŸ”€πŸ”’ urls](https://virustotal.readme.io/reference/ip-object-urls.md): IP address' URLs - [πŸ”€πŸ§‘β€πŸ’» user_votes](https://virustotal.readme.io/reference/ip-object-user-votes.md): IP address' user votes. - [πŸ”€ votes](https://virustotal.readme.io/reference/ip-object-votes.md): IP address' votes. - [Operations](https://virustotal.readme.io/reference/operation-object.md): Asynchronous operations - [πŸ”’ Private Analyses](https://virustotal.readme.io/reference/private-analyses.md): Private file's analyses - [πŸ”€ item](https://virustotal.readme.io/reference/private-analyses-object-item.md): Item being analysed - [πŸ”€ submitter](https://virustotal.readme.io/reference/submitter.md): User who submitted the analysis - [πŸ”’ Private Files](https://virustotal.readme.io/reference/private-files.md): Information about private files - [πŸ”€ behaviours](https://virustotal.readme.io/reference/private-file-object-behaviours.md): Behaviour reports for the private file - [πŸ”€ dropped_files](https://virustotal.readme.io/reference/private-file-object-dropped-files.md): Files dropped during the file's execution - [πŸ”€ execution_parents](https://virustotal.readme.io/reference/private-file-object-execution-parents.md): Files dropping the file during its execution - [πŸ”€ embedded_urls](https://virustotal.readme.io/reference/private-file-object-embedded-urls.md): URLs contained in the file - [πŸ”€ embedded_domains](https://virustotal.readme.io/reference/private-file-object-embedded-domains.md): Domains contained in the file - [πŸ”€ embedded_ips](https://virustotal.readme.io/reference/private-file-object-embedded-ips.md): IP addresses contained in the file - [πŸ”’ Private Files Behaviours](https://virustotal.readme.io/reference/private-file-behaviours.md): Information about private file behaviours - [πŸ”€ attack_techniques](https://virustotal.readme.io/reference/private-files-behaviour-object-attack-techniques.md): Private file behaviour's ATT&CK techniques - [πŸ”€ file](https://virustotal.readme.io/reference/private-files-behaviour-object-file.md): Private file behaviour's file. - [πŸ”’ Private URLs](https://virustotal.readme.io/reference/private-urls.md): Information about private URLs - [πŸ”’ Private URLs Behaviours](https://virustotal.readme.io/reference/private-url-behaviours.md): Information about private URL behaviours - [Resolutions](https://virustotal.readme.io/reference/resolution-object.md): Domain-IP resolutions. - [Retrohunt Jobs](https://virustotal.readme.io/reference/retrohunt-job-object.md): YARA matching against VirusTotal's file corpus - [πŸ”€πŸ§‘β€πŸ’» matching_files](https://virustotal.readme.io/reference/retrohunt-job-matching-files.md): Files matching the Retrohunt job. - [πŸ”€πŸ§‘β€πŸ’» owner](https://virustotal.readme.io/reference/retrohunt-job-owner.md): Retrohunt job's owner - [Screenshots](https://virustotal.readme.io/reference/screenshots.md): screenshot objects - [Sigma Analyses](https://virustotal.readme.io/reference/sigma-analyses.md): Sigma analyses run in sandbox generated sysmon logs. - [πŸ”€ rules](https://virustotal.readme.io/reference/sigma-analysis-object-rules.md): Matched rules in a Sigma analysis. - [Sigma Rules](https://virustotal.readme.io/reference/sigma-rule-object.md): Sigma rules matched in Sigma analyses - [SSL Certificate](https://virustotal.readme.io/reference/ssl-certificate.md): SSL certificates information. - [Submissions](https://virustotal.readme.io/reference/submission-object.md): Information about submissions - [URLs](https://virustotal.readme.io/reference/url-object.md): Information about URLs. - [πŸ”€πŸ”’ analyses](https://virustotal.readme.io/reference/url-object-analyses.md): All analyses made for a given URL. - [πŸ”€ collections](https://virustotal.readme.io/reference/url-object-collections.md): Collections containing this URL. - [πŸ”€ comments](https://virustotal.readme.io/reference/url-object-comments.md): Comments in URL objects. - [πŸ”€πŸ”’ communicating_files](https://virustotal.readme.io/reference/url-object-communicating-files.md): Files that communicate with this url when they are executed. - [πŸ”€πŸ”’ contacted_domains](https://virustotal.readme.io/reference/url-object-contacted-domains.md): Distinct domains from which the URL loads some kind of resource. - [πŸ”€πŸ”’ contacted_ips](https://virustotal.readme.io/reference/url-object-contacted-ips.md): Distinct IP addresses from which the URL loads some kind of resource. - [πŸ”€πŸ”’ downloaded_files](https://virustotal.readme.io/reference/url-object-downloaded-files.md): Files downloaded from the URL. - [πŸ”€πŸ”’ embedded_js_files](https://virustotal.readme.io/reference/url-object-embedded-js-files.md): Found javascript scripts in the URL's HTML response - [πŸ”€ graphs](https://virustotal.readme.io/reference/url-object-graphs.md) - [πŸ”€ last_serving_ip_address](https://virustotal.readme.io/reference/url-object-last-serving-ip-address.md): Last IP address that served the URL. - [πŸ”€ network_location](https://virustotal.readme.io/reference/url-object-network-location.md): Domain or IP address for the URL. - [πŸ”€πŸ”’ redirecting_urls](https://virustotal.readme.io/reference/url-object-redirecting-urls.md): URLs that redirected to the given URL. - [πŸ”€πŸ”’ redirects_to](https://virustotal.readme.io/reference/url-object-redirects-to.md): URLs that this url redirects to. - [πŸ”€πŸ”’ referrer_files](https://virustotal.readme.io/reference/url-object-referrer-files.md): Files containing a given URL. - [πŸ”€πŸ”’ referrer_urls](https://virustotal.readme.io/reference/url-object-referrer-urls.md): URLs that refer to the given URL. - [πŸ”€ related_comments](https://virustotal.readme.io/reference/url-object-related-comments.md): Comments in URL's related objects. - [πŸ”€πŸ”’ related_references](https://virustotal.readme.io/reference/url-object-related-references.md): Related references for a given URL. - [πŸ”€πŸ”’ related_threat_actors](https://virustotal.readme.io/reference/url-object-related-threat-actors.md): Related Threat Actors for a given URL. - [πŸ”€πŸ”’ submissions](https://virustotal.readme.io/reference/url-object-submissions.md): URL submissions - [πŸ”€πŸ§‘β€πŸ’» user_votes](https://virustotal.readme.io/reference/url-object-user-votes.md): Votes for a given URL made by the current user - [πŸ”€ votes](https://virustotal.readme.io/reference/url-object-votes.md): Votes for a given URL - [πŸ”€πŸ”’ urls_related_by_tracker_id](https://virustotal.readme.io/reference/url-object-urls-related-by-tracker-id.md): URLs having trackers with the same IDs - [Users](https://virustotal.readme.io/reference/user-object.md): Information about a VirusTotal user - [πŸ”€πŸ§‘β€πŸ’» api_quota_group](https://virustotal.readme.io/reference/user-object-api-quota-group.md): Group which the user consumes API quota from. - [πŸ”€ collections](https://virustotal.readme.io/reference/user-object-collections.md) - [πŸ”€ comments](https://virustotal.readme.io/reference/user-object-comments.md): Comments posted by a certain user - [πŸ”€ graphs](https://virustotal.readme.io/reference/user-object-graphs.md): VT Graphs the user is owner/editor/viewer of - [πŸ”€πŸ§‘β€πŸ’» groups](https://virustotal.readme.io/reference/user-object-groups.md): Groups for which the user is a member. - [πŸ”€πŸ§‘β€πŸ’» hunting_rulesets](https://virustotal.readme.io/reference/user-object-hunting-rulesets.md): Hunting rulesets editable by the user. - [πŸ”€πŸ§‘β€πŸ’» hunting_notifications](https://virustotal.readme.io/reference/user-object-hunting-notifications.md): Hunting notifications for the user. - [πŸ”€πŸ§‘β€πŸ’» hunting_notification_files](https://virustotal.readme.io/reference/user-object-hunting-notification-files.md): Files flagged in the hunting notifications for the user. - [πŸ”€πŸ§‘β€πŸ’» intelligence_quota_group](https://virustotal.readme.io/reference/user-object-intelligence-quota-group.md): Group which the user consumes Intelligence quota from. - [πŸ”€ mentions](https://virustotal.readme.io/reference/user-object-mentions.md): Comments mentioning the user. - [πŸ”€πŸ§‘β€πŸ’» retrohunt_jobs](https://virustotal.readme.io/reference/user-object-retrohunt-job.md): User's Retrohunt jobs - [πŸ”€ votes](https://virustotal.readme.io/reference/user-object-votes.md): Votes posted by a certain user - [Saved Searches](https://virustotal.readme.io/reference/saved-search-object.md) - [Service Accounts](https://virustotal.readme.io/reference/service-accounts-object.md): Information about a VirusTotal Service Account - [πŸ”€πŸ§‘β€πŸ’» api_quota_group](https://virustotal.readme.io/reference/service-account-object-api-quota-group.md): Group which the user consumes API quota from. - [πŸ”€ comments](https://virustotal.readme.io/reference/service-account-object-comments.md): Comments posted by a certain user - [πŸ”€πŸ§‘β€πŸ’» groups](https://virustotal.readme.io/reference/service-account-object-groups.md): Groups for which the user is a member. - [πŸ”€πŸ§‘β€πŸ’» intelligence_quota_group](https://virustotal.readme.io/reference/service-account-object-intelligence-quota-group.md): Group which the user consumes Intelligence quota from. - [πŸ”€ mentions](https://virustotal.readme.io/reference/service-account-object-mentions.md): Comments mentioning the user. - [Votes](https://virustotal.readme.io/reference/vote-object.md): vote objects - [Whois](https://virustotal.readme.io/reference/whois.md): Domain and IP addresses whois records. - [YARA Rules](https://virustotal.readme.io/reference/yara-rule.md): YARA rules objects - [YARA Rulesets](https://virustotal.readme.io/reference/yara-rulesets.md): YARA rulesets objects - [Software Publishers](https://virustotal.readme.io/reference/software-publishers.md) - [Monitor Items](https://virustotal.readme.io/reference/monitoritem-description.md): Details about objects stored in the VirusTotal Monitor service. - [Get a list of MonitorItem objects by path or tag](https://virustotal.readme.io/reference/monitor-items-filter.md) - [Upload a file or create a new folder](https://virustotal.readme.io/reference/monitor-items-create.md) - [Get a URL for uploading files larger than 32MB](https://virustotal.readme.io/reference/monitor-items-upload-url.md) - [Get attributes and metadata for a specific MonitorItem](https://virustotal.readme.io/reference/monitor-items-stat.md) - [Delete a VirusTotal Monitor file or folder](https://virustotal.readme.io/reference/monitor-items-delete.md) - [Configure a given VirusTotal Monitor item (file or folder)](https://virustotal.readme.io/reference/monitor-items-config.md) - [Download a file in VirusTotal Monitor](https://virustotal.readme.io/reference/monitor-items-download.md) - [Get a URL for downloading a file in VirusTotal Monitor](https://virustotal.readme.io/reference/monitor-items-download-url.md) - [Get the latest file analyses](https://virustotal.readme.io/reference/monitor-items-analyses.md) - [Get user owning the MonitorItem object](https://virustotal.readme.io/reference/monitor-items-owner.md) - [Retrieve partner's comments on a file](https://virustotal.readme.io/reference/monitor-item-comments.md) - [Retrieve statistics about analyses performed on your software collection](https://virustotal.readme.io/reference/monitor-statistics.md) - [Retrieve historical events about your software collection](https://virustotal.readme.io/reference/events.md) - [Antivirus Partners](https://virustotal.readme.io/reference/antivirus-partners.md) - [Get a list of MonitorHashes detected by an engine](https://virustotal.readme.io/reference/monitorpartner-hashes.md) - [Get a list of analyses for a file](https://virustotal.readme.io/reference/monitorpartner-hashes-analyses.md) - [Get a list of items with a given sha256 hash](https://virustotal.readme.io/reference/monitorpartner-hashes-items.md) - [Create a comment over a hash](https://virustotal.readme.io/reference/monitorpartner-hashes-comments.md): Create a comment and if necessary confirm detection over a hash - [Get comments on a sha256 hash](https://virustotal.readme.io/reference/get-sha256-hash-comments.md) - [Add a comment on a sha256 hash](https://virustotal.readme.io/reference/monitorpartner-comments-patch.md): Create a comment and if necessary confirm detection over a hash - [Remove a comment detection for a hash.](https://virustotal.readme.io/reference/monitorpartner-comments-delete.md): Remove a comment and reset confirmed detection for a hash. - [Download a file with a given sha256 hash](https://virustotal.readme.io/reference/monitorpartner-files-download.md) - [Retrieve a download url for a file with a given sha256 hash](https://virustotal.readme.io/reference/monitorpartner-files-download-url.md) - [Download a daily detection bundle directly](https://virustotal.readme.io/reference/monitorpartner-detectionsbundle-download.md) - [Get a daily detection bundle download URL](https://virustotal.readme.io/reference/monitorpartner-detectionsbundle-download-url.md) - [Get a list of MonitorHashes detected by an engine](https://virustotal.readme.io/reference/monitorpartner-statistics.md) ## Pages - [Title](https://virustotal.readme.io/page/title.md)