VirusTotal (v2.7.24)

Analyze suspicious hashes, URLs, domains and IP addresses

Author
VirusTotal
Support
partner
URL
https://www.virustotal.com
Categories
Data Enrichment & Threat Intelligence

Indicator fields (3)

Integrations (5)

README

Note: Support for this pack moved to the partner on Oct 1, 2021. Please contact the partner directly via the support link on the right.

What. VirusTotal is the richest and most actionable crowdsourced threat intelligence platform on the planet. It equips security teams with comprehensive context and cutting edge functionality to proactively protect their networks from cybersecurity threats.

Why. Security teams are often confronted with an unknown file/URL/domain/IP address and asked to make sense of an attack. Without further context, it is virtually impossible to determine attribution, build effective defenses against other strains of the attack, or understand the impact of a given threat in your organization. Through API and web based interaction with VirusTotal, security analysts can rapidly build a picture of an incident and then use those insights to neutralize other attacks.

Outcome. Faster, more confident, more accurate and more cost-effective security operations.

Where. On-premise, in the cloud, in your hosting, in your corporate network, everywhere.

What we solve for leaders.

Security team challenges Solving with VirusTotal + XSOAR
Alert fatigue + quality & speed of IR handling. PANW survey data shows that SOC analysts are only able to handle 14% of alerts generated by security tools. Eradicate analyst burnout through automation. Automate false positive discarding and alert prioritization, optimize SOC resources. Malicious+Benign info.
Lack of context & missed threats. Reliance on reactive threat feeds. Only information about internal systems and users, no in-the-wild contextual details. Improved and early detection. Track threats going forward with YARA. Crowdsourced threat reputation for files/hashes, domains, IPs and URLs coming from over 90 security vendors.
Finding and maintaining security talent. There is a shortage of qualified security candidates; recruiting + retaining these is an endemic challenge Juniors operating as advanced threat hunters. Automate repetitive tasks with playbooks, elevate SOC Level 1 effectiveness. Faster, more confident and more accurate decisions. Greater productivity.
Budget constraints. Cybersecurity isn’t top of mind at many organizations when budget line items are getting funded. Difficult to prove ROI. Condense & lower costs + Increase toolset ROI. One-stop-shop for everything threat intelligence related (domains, IPs, URLs, files). Take your SIEM, IDS, EDR, Firewall, etc. to the next level.

Use cases.

Example questions we answer.

Technical capabilities

Popular tasks

Additional information