VirusTotal
Threat IntelligenceCheck what many engines say about a file, URL or domain.
Who uses it?
SOC analysts, incident responders and malware analysts.
Best for
Quick reputation checks on files, URLs and domains
Similar tools
CrowdStrike, Wireshark
What is it?
VirusTotal is an online service that analyses files, URLs, domains and IP addresses using many security engines and data sources.
What problem does it solve?
Analysts need a fast, second opinion on whether something is known to be malicious.
How does it work?
You submit or look up a file hash, URL, domain or IP address. Multiple engines and data sources return their verdicts and context. Analysts use the results as one input in their assessment.
Simple example
Look up the hash of a suspicious attachment to see whether it is already known.
When would a SOC analyst use it?
During triage, to quickly check an indicator. Note that files uploaded to public services may become visible to others, so sensitive files should not be uploaded.
How does it work?
- 1You submit or look up a file hash, URL, domain or IP address.
- 2Multiple engines and data sources return their verdicts and context.
- 3Analysts use the results as one input in their assessment.
Simple example
Look up the hash of a suspicious attachment to see whether it is already known.
When would a SOC analyst use it?
During triage, to quickly check an indicator. Note that files uploaded to public services may become visible to others, so sensitive files should not be uploaded.
Who uses it?
SOC analysts, incident responders and malware analysts.
Pros
- A fast second opinion
- No setup for basic lookups
- Covers many kinds of indicator
Cons
- Uploaded files can be seen by others
- A clean result is not proof of safety
- Not a replacement for investigation