For AI agents: visit https://virustotal.readme.io/llms.txt for an index of all pages formatted in Markdown and endpoints in OpenAPI. Append .md to any documentation page URL to get its markdown version.
Jump to Content
VirusTotal
HomeGuidesAPI Reference
VirusTotal
API Reference
HomeGuidesAPI Reference

Introduction

  • VirusTotal API v3 Overview
  • Public vs Premium API
  • Technology Integrations
  • Getting started
  • Authentication
  • API responses
    • Errors
    • Key concepts
    • Objects
    • Collections
    • Relationships
  • Legend
  • API v2 to v3 Migration Guide

IOC REPUTATION & ENRICHMENT

  • IP addresses
    • Get an IP address reportget
    • Request an IP address (re)scanpost
    • Get comments on an IP addressget
    • Add a comment to an IP addresspost
    • Get objects related to an IP addressget
    • Get object descriptors related to an IP addressget
    • Get votes on an IP addressget
    • Add a vote to an IP addresspost
  • Domains & Resolutions
    • Get a domain reportget
    • Request an domain (re)scanpost
    • Get comments on a domainget
    • Add a comment to a domainpost
    • Get objects related to a domainget
    • Get object descriptors related to a domainget
    • Get a DNS resolution objectget
    • Get votes on a domainget
    • Add a vote to a domainpost
  • Files
    • Upload a filepost
    • Get a URL for uploading large filesget
    • Get a file reportget
    • Request a file rescan (re-analyze)post
    • Get a file’s download URLget
    • Download a fileget
    • Get comments on a fileget
    • Add a comment to a filepost
    • Get objects related to a fileget
    • Get object descriptors related to a fileget
    • Get a crowdsourced Sigma rule objectget
    • Get a crowdsourced YARA rulesetget
    • Get votes on a fileget
    • Add a vote on a filepost
  • File Behaviours
    • Get a summary of all behavior reports for a fileget
    • Get a summary of all MITRE ATT&CK techniques observed in a fileget
    • Get all behavior reports for a fileget
    • Get a file behavior report from a sandboxget
    • Get objects related to a behaviour reportget
    • Get object descriptors related to a behaviour reportget
    • Get a detailed HTML behaviour reportget
    • Get the EVTX file generated during a file’s behavior analysisget
    • Get the PCAP file generated during a file’s behavior analysisget
    • Get the memdump file generated during a file’s behavior analysisget
  • URLs
    • Scan URLpost
    • Get a URL reportget
    • Request a URL rescan (re-analyze)post
    • Get comments on a URLget
    • Add a comment on a URLpost
    • Get objects related to a URLget
    • Get object descriptors related to a URLget
    • Get votes on a URLget
    • Add a vote on a URLpost
  • Comments
    • Get latest commentsget
    • Get a comment objectget
    • Delete a commentdel
    • Get objects related to a commentget
    • Get object descriptors related to a commentget
    • Add a vote to a commentpost
  • Analyses, Submissions & Operations
    • Get a URL / file analysisget
    • Get objects related to an analysisget
    • Get object descriptors related to an analysisget
    • Get a submission objectget
    • Get an operation objectget
  • Attack Tactics
    • Get an attack tactic objectget
    • Get objects related to an attack tacticget
    • Get object descriptors related to an attack tacticget
  • Attack Techniques
    • Get an attack technique objectget
    • Get objects related to an attack techniqueget
    • Get object descriptors related to an attack techniqueget
  • Popular Threat Categories
    • Get a list of popular threat categoriesget
  • Code Insights
    • Analyse code blocks with Code Insightspost
  • Saved Searches
    • List Saved Searchesget
    • Get a Saved Searchget
    • Create a Saved Searchpost
    • Share a Saved Searchpost
    • Update a Saved Searchpatch
    • Delete a Saved Searchdel
    • Revoke access to a Saved Searchdel
    • Get object descriptors related to a Saved Searchget
    • Get objects related to a Saved Searchget

VT Enterprise

  • Search & Metadata
    • Search for files, URLs, domains, IPs and commentsget
    • Advanced corpus searchget
    • Get file content search snippetsget
    • Get VirusTotal metadataget
  • Collections
    • Create a new collectionpost
    • Get a collectionget
    • Update a collectionpatch
    • Delete a collectiondel
    • Get comments on a collectionget
    • Add a comment to a collectionpost
    • Get objects related to a collectionget
    • Get object descriptors related to a collectionget
    • Add new items to a collectionpost
    • Delete items from a collectiondel
    • šŸ”’ List collectionsget
    • šŸ”’ Export IOCs from a collectionget
    • šŸ”’ Export IOCs from a given collection's relationshipget
    • šŸ”’ Export aggregations from a collectionget
    • šŸ”’ Search IoCs inside a collectionget
  • Zipping files
    • Create a password-protected ZIP with VirusTotal filespost
    • Check a ZIP file’s statusget
    • Get a ZIP file’s download URLget
    • Download a ZIP fileget

VT Hunting

  • YARA Rules
    • List Crowdsourced YARA Rulesget
    • Get a Crowdsourced YARA ruleget
    • Get objects related to a Crowdsourced YARA ruleget
    • Get objects descriptors related to a Crowdsourced YARA ruleget
  • IoC Stream
    • Get objects from the IoC Streamget
    • Delete notifications from the IoC Streamdel
    • Get an IoC Stream notificationget
    • Delete an IoC Stream notificationdel
  • šŸ”’ Livehunt
    • Get Livehunt rulesetsget
    • Create a new Livehunt rulesetpost
    • Remove all Livehunt rulesetsdel
    • Get a Livehunt rulesetget
    • Update a Livehunt rulesetpatch
    • Check if a user or group is a Livehunt ruleset editorget
    • Revoke Livehunt ruleset edit permission from a user or groupdel
    • Delete a Livehunt rulesetdel
    • Get objects related to a Livehunt rulesetget
    • Get object descriptors related to a Livehunt rulesetget
    • Grant Livehunt ruleset edit permissions for a user or grouppost
    • Transfer Livehunt ruleset to another userpost
    • Get Livehunt notificationsget
    • Delete Livehunt notificationsdel
    • Get a Livehunt notification objectget
    • Delete a Livehunt notificationdel
    • Retrieve file objects for Livehunt notificationsget
  • šŸ”’ Retrohunt
    • Get a list of Retrohunt jobsget
    • Create a new Retrohunt jobpost
    • Get a Retrohunt job objectget
    • Delete a Retrohunt jobdel
    • Abort a Retrohunt jobpost
    • Retrieve matches for a Retrohunt jobget

VT GRAPH

  • VT Graphs
    • Search graphsget
    • Create a graphpost
    • Get a graph objectget
    • Update a graph objectpatch
    • Delete a graphdel
    • Get comments on a graphget
    • Add a comment to a graphpost
    • Get objects related to a graphget
    • Get object descriptors related to a graphget
  • VT Graphs Permissions & ACL
    • Get users and groups that can view a graphget
    • Grant users and groups permission to see a graphpost
    • Check if a user or group can view a graphget
    • Revoke view permission from a user or groupdel
    • Get users and groups that can edit a graphget
    • Grant users and groups permission to edit a graphpost
    • Check if a user or group can edit a graphget
    • Revoke edit graph permissions from a user or groupdel

VT Private Scanning

  • šŸ”’ Files
    • Upload a filepost
    • List private filesget
    • Get a URL for uploading large filesget
    • Rescan a private filepost
    • Get a private file reportget
    • Delete a private file reportdel
    • Get objects related to a private fileget
    • Get object descriptors related to a fileget
  • šŸ”’ Analyses
    • List private analysesget
    • Get a private analysisget
    • Get objects related to a private analysisget
    • Get object descriptors related to a private analysisget
  • šŸ”’ File Behaviours
    • Get a behaviour report from a private fileget
    • Get the behaviour reports from a private fileget
    • Get objects related to a private file's behaviour reportget
    • Get object descriptors related to a private file's behaviour reportget
    • Get a summary of all behavior reports for a fileget
    • Get a summary of all MITRE ATT&CK techniques observed in a fileget
    • Get a detailed HTML behaviour reportget
    • Get the EVTX file generated during a private file’s behavior analysisget
    • Get the PCAP file generated during a private file’s behavior analysisget
    • Get the memdump file generated during a private file’s behavior analysisget
  • šŸ”’ URLs
    • Private Scan URLpost
    • Get a URL analysis reportget
    • Get objects related to a private URLget
    • Get object descriptors related to a private URLget
  • Zipping private files
    • Create a password-protected ZIP with VirusTotal private filespost
    • Check a ZIP file’s statusget
    • Get a ZIP file’s download URLget
    • Download a ZIP fileget

VT FeedS

  • šŸ”’ File intelligence feed
    • Get a per-minute file feed batchget
    • Get a hourly file feed batchget
    • Download a file published in the file feedget
  • šŸ”’ Sandbox analyses feed
    • Get a per-minute file behaviour feed batchget
    • Get an hourly file behaviour feed batchget
    • Get the EVTX file generated during a file’s behavior analysisget
    • Get the memdump file generated during a file’s behavior analysisget
    • Get the PCAP file generated during a file’s behavior analysisget
    • Get a file behaviour's detailed HTML reportget
  • šŸ”’ Domain intelligence feed
    • Get a minutely domain feed batchget
    • Get an hourly domain feed batchget
  • šŸ”’ IP intelligence feed
    • Get a minutely IP address feed batchget
    • Get an hourly IP address feed batchget
  • šŸ”’ URL intelligence feed
    • Get a minutely URL feed batchget
    • Get an hourly URL feed batchget

VT ENTERPRISE ADMINISTRATION

  • User management
    • Get a user objectget
    • Update a user objectpatch
    • Delete a userdel
    • Get objects related to a userget
    • Get object descriptors related to a userget
  • Group management
    • Get a group objectget
    • Update a group objectpatch
    • Get administrators for a groupget
    • Manage Rolespatch
    • Check if a user is a group adminget
    • Get group usersget
    • Check if a user is a group memberget
    • Remove a user from a groupdel
    • Add users to a grouppost
    • Get objects related to a groupget
    • Get object descriptors related to a groupget
  • Quota management
    • Get a user’s API usageget
    • Get a group’s API usageget
    • Get a group's usage per featureget
  • Service Account Management
    • Create a new Service Accountpost
    • Get Service Accounts of a groupget
    • Get a Service Account objectget
  • Audit Log
    • Get Activity Logsget

VT Augment

  • Overview
  • Rendering
    • Get a widget rendering URLget
    • Retrieve the widget's HTML contentget
  • Theming

API Objects

  • Activity Log
  • Analyses
    • šŸ”€ item
  • Attack Tactics
    • šŸ”€ attack_techniques
  • Attack Techniques
    • šŸ”€ attack_tactics
    • šŸ”€ parent_technique
    • šŸ”€ revoking_technique
    • šŸ”€ subtechniques
    • šŸ”€šŸ”’ threat_actors
  • Collections
    • šŸ”€ autogenerated_graphs
    • šŸ”€ comments
    • šŸ”€ domains
    • šŸ”€ files
    • šŸ”€ ip_addresses
    • šŸ”€ owner
    • šŸ”€ references
    • šŸ”€šŸ”’ related_collections
    • šŸ”€šŸ”’ related_references
    • šŸ”€šŸ”’ threat_actors
    • šŸ”€ urls
  • Comments
    • šŸ”€ author
  • Domains
    • šŸ”€šŸ”’ caa_records
    • šŸ”€šŸ”’ cname_records
    • šŸ”€ collections
    • šŸ”€ comments
    • šŸ”€ communicating_files
    • šŸ”€šŸ”’ downloaded_files
    • šŸ”€ graphs
    • šŸ”€ historical_ssl_certificates
    • šŸ”€ historical_whois
    • šŸ”€ immediate_parent
    • šŸ”€šŸ”’ mx_records
    • šŸ”€šŸ”’ ns_records
    • šŸ”€ parent
    • šŸ”€ referrer_files
    • šŸ”€ related_comments
    • šŸ”€šŸ”’ related_references
    • šŸ”€šŸ”’ related_threat_actors
    • šŸ”€ resolutions
    • šŸ”€ siblings
    • šŸ”€šŸ”’ soa_records
    • šŸ”€ subdomains
    • šŸ”€šŸ”’ urls
    • šŸ”€šŸ§‘ā€šŸ’» user_votes
    • šŸ”€ votes
  • Files
    • androguard
    • asf_info
    • authentihash
    • bundle_info
    • class_info
    • crowdsourced_ids_results
    • crowdsourced_ids_stats
    • crowdsourced_yara_results
    • deb_info
    • detectiteasy
    • dmg_info
    • dot_net_assembly
    • dot_net_guids
    • elf_info
    • šŸ”’ exiftool
    • html_info
    • image_code_injections
    • ipa_info
    • isoimage_info
    • jar_info
    • javascript_info
    • known_distributors
    • lnk_info
    • macho_info
    • magic
    • šŸ”’ malware_config
    • monitor_info
    • nsrl_info
    • šŸ”’ office_info
    • šŸ”’ openxml_info
    • packers
    • password_info
    • pdf_info
    • pe_info
    • popular_threat_classification
    • powershell_info
    • rombios_info
    • šŸ”’ rtf_info
    • sandbox_verdicts
    • sigma_analysis_results
    • sigma_analysis_stats
    • signature_info
    • snort
    • suricata
    • ssdeep
    • swf_info
    • telfhash
    • tlsh
    • traffic_inspection
    • trid
    • vba_info
    • wireshark
    • šŸ”€šŸ”’ analyses
    • šŸ”€ behaviours
    • šŸ”€ bundled_files
    • šŸ”€šŸ”’ carbonblack_children
    • šŸ”€šŸ”’ carbonblack_parents
    • šŸ”€ collections
    • šŸ”€ comments
    • šŸ”€šŸ”’ compressed_parents
    • šŸ”€ contacted_domains
    • šŸ”€ contacted_ips
    • šŸ”€ contacted_urls
    • šŸ”€ dropped_files
    • šŸ”€šŸ”’ email_attachments
    • šŸ”€šŸ”’ email_parents
    • šŸ”€šŸ”’ embedded_domains
    • šŸ”€šŸ”’ embedded_ips
    • šŸ”€šŸ”’ embedded_urls
    • šŸ”€ execution_parents
    • šŸ”€ graphs
    • šŸ”€šŸ”’ itw_domains
    • šŸ”€šŸ”’ itw_ips
    • šŸ”€šŸ”’ itw_urls
    • šŸ”€šŸ”’ overlay_children
    • šŸ”€šŸ”’ overlay_parents
    • šŸ”€šŸ”’ pcap_children
    • šŸ”€šŸ”’ pcap_parents
    • šŸ”€ pe_resource_children
    • šŸ”€ pe_resource_parents
    • šŸ”€šŸ”’ related_references
    • šŸ”€šŸ”’ related_threat_actors
    • šŸ”€šŸ”’ screenshots
    • šŸ”€ sigma_analysis
    • šŸ”€šŸ”’ similar_files
    • šŸ”€šŸ”’ submissions
    • šŸ”€šŸ”’ urls_for_embedded_js
    • šŸ”€šŸ§‘ā€šŸ’» user_votes
    • šŸ”€ votes
    • šŸ”€ memory_pattern_domains
    • šŸ”€ memory_pattern_ips
    • šŸ”€ memory_pattern_urls
  • Files Behaviour
    • dns_lookups
    • files_copied
    • files_dropped
    • http_conversations
    • ip_traffic
    • permissions_checked
    • processes_tree
    • sms_sent
    • tags
    • verdicts
    • šŸ”€ file
    • šŸ”€ attack_techniques
  • Graphs
    • šŸ”€ comments
    • šŸ”€ editors
    • šŸ”€ group
    • šŸ”€ items
    • šŸ”€ owner
    • šŸ”€ viewers
  • Groups
    • šŸ”€šŸ§‘ā€šŸ’» administrators
    • šŸ”€šŸ§‘ā€šŸ’» graphs
    • šŸ”€šŸ§‘ā€šŸ’» users
  • Hunting Notifications
  • Hunting Rulesets
    • šŸ”€ šŸ§‘ā€šŸ’»owner
    • šŸ”€šŸ§‘ā€šŸ’» editors
    • šŸ”€šŸ§‘ā€šŸ’» viewers
    • šŸ”€šŸ§‘ā€šŸ’» hunting_notification_files
  • IoC-Stream Notifications
  • IP addresses
    • šŸ”€ collections
    • šŸ”€ comments
    • šŸ”€ communicating_files
    • šŸ”€šŸ”’ downloaded_files
    • šŸ”€ graphs
    • šŸ”€ historical_ssl_certificates
    • šŸ”€ historical_whois
    • šŸ”€ related_comments
    • šŸ”€šŸ”’ related_references
    • šŸ”€šŸ”’ related_threat_actors
    • šŸ”€ referrer_files
    • šŸ”€ resolutions
    • šŸ”€šŸ”’ urls
    • šŸ”€šŸ§‘ā€šŸ’» user_votes
    • šŸ”€ votes
  • Operations
  • šŸ”’ Private Analyses
    • šŸ”€ item
    • šŸ”€ submitter
  • šŸ”’ Private Files
    • šŸ”€ behaviours
    • šŸ”€ dropped_files
    • šŸ”€ execution_parents
    • šŸ”€ embedded_urls
    • šŸ”€ embedded_domains
    • šŸ”€ embedded_ips
  • šŸ”’ Private Files Behaviours
    • šŸ”€ attack_techniques
    • šŸ”€ file
  • šŸ”’ Private URLs
  • šŸ”’ Private URLs Behaviours
  • Resolutions
  • Retrohunt Jobs
    • šŸ”€šŸ§‘ā€šŸ’» matching_files
    • šŸ”€šŸ§‘ā€šŸ’» owner
  • Screenshots
  • Sigma Analyses
    • šŸ”€ rules
  • Sigma Rules
  • SSL Certificate
  • Submissions
  • URLs
    • šŸ”€šŸ”’ analyses
    • šŸ”€ collections
    • šŸ”€ comments
    • šŸ”€šŸ”’ communicating_files
    • šŸ”€šŸ”’ contacted_domains
    • šŸ”€šŸ”’ contacted_ips
    • šŸ”€šŸ”’ downloaded_files
    • šŸ”€šŸ”’ embedded_js_files
    • šŸ”€ graphs
    • šŸ”€ last_serving_ip_address
    • šŸ”€ network_location
    • šŸ”€šŸ”’ redirecting_urls
    • šŸ”€šŸ”’ redirects_to
    • šŸ”€šŸ”’ referrer_files
    • šŸ”€šŸ”’ referrer_urls
    • šŸ”€ related_comments
    • šŸ”€šŸ”’ related_references
    • šŸ”€šŸ”’ related_threat_actors
    • šŸ”€šŸ”’ submissions
    • šŸ”€šŸ§‘ā€šŸ’» user_votes
    • šŸ”€ votes
    • šŸ”€šŸ”’ urls_related_by_tracker_id
  • Users
    • šŸ”€šŸ§‘ā€šŸ’» api_quota_group
    • šŸ”€ collections
    • šŸ”€ comments
    • šŸ”€ graphs
    • šŸ”€šŸ§‘ā€šŸ’» groups
    • šŸ”€šŸ§‘ā€šŸ’» hunting_rulesets
    • šŸ”€šŸ§‘ā€šŸ’» hunting_notifications
    • šŸ”€šŸ§‘ā€šŸ’» hunting_notification_files
    • šŸ”€šŸ§‘ā€šŸ’» intelligence_quota_group
    • šŸ”€ mentions
    • šŸ”€šŸ§‘ā€šŸ’» retrohunt_jobs
    • šŸ”€ votes
  • Saved Searches
  • Service Accounts
    • šŸ”€šŸ§‘ā€šŸ’» api_quota_group
    • šŸ”€ comments
    • šŸ”€šŸ§‘ā€šŸ’» groups
    • šŸ”€šŸ§‘ā€šŸ’» intelligence_quota_group
    • šŸ”€ mentions
  • Votes
  • Whois
  • YARA Rules
  • YARA Rulesets

VT Monitor

  • Software Publishers
    • Monitor Items
    • Get a list of MonitorItem objects by path or tagget
    • Upload a file or create a new folderpost
    • Get a URL for uploading files larger than 32MBget
    • Get attributes and metadata for a specific MonitorItemget
    • Delete a VirusTotal Monitor file or folderdel
    • Configure a given VirusTotal Monitor item (file or folder)patch
    • Download a file in VirusTotal Monitorget
    • Get a URL for downloading a file in VirusTotal Monitorget
    • Get the latest file analysesget
    • Get user owning the MonitorItem objectget
    • Retrieve partner's comments on a fileget
    • Retrieve statistics about analyses performed on your software collectionget
    • Retrieve historical events about your software collectionget
  • Antivirus Partners
    • Get a list of MonitorHashes detected by an engineget
    • Get a list of analyses for a fileget
    • Get a list of items with a given sha256 hashget
    • Create a comment over a hashpost
    • Get comments on a sha256 hashget
    • Add a comment on a sha256 hashpatch
    • Remove a comment detection for a hash.del
    • Download a file with a given sha256 hashget
    • Retrieve a download url for a file with a given sha256 hashget
    • Download a daily detection bundle directlyget
    • Get a daily detection bundle download URLget
    • Get a list of MonitorHashes detected by an engineget

šŸ”’ Retrohunt

🚧

Special privileges required

This endpoint is only available for users with premium privileges.

Updated 8 months ago


Retrieve file objects for Livehunt notifications
Get a list of Retrohunt jobs

Updated 8 months ago


Retrieve file objects for Livehunt notifications
Get a list of Retrohunt jobs