# VirusTotal

**Canonical:** https://apis.io/providers/virustotal/  
**Website:** https://www.virustotal.com  
**APIs profiled:** 35

VirusTotal — the Google-owned (since 2012) threat intelligence platform that aggregates anti-malware engines and URL scanners to analyse files, URLs, IP addresses, and domains. The v3 API surfaces seven major areas: Access Control, IoC Feeds, IoC Investigation, Private Scanning, Threat Graphs, Threat Landscape & Vulnerability Intelligence, and YARA Hunting (Livehunt, Retrohunt, IoC Stream). Now also branded "Google Threat Intelligence" (GTI) for Enterprise customers, integrating Mandiant intelligence, Digital Threat Monitoring (DTM), and Attack Surface Management (ASM).

## Kin Score — 49.7 / 100 (developing)

Scored 2026-08-25 under rubric 0.14.0. Trend: flat (+0.0 from 49.7).

| Facet | Score |
|---|---|
| Discoverability | 57.4 |
| Contract Quality | 68.9 |
| Governance | 28.8 |
| Contract Governance | 28.8 |
| Operational Transparency | 34.2 |
| Developer Ergonomics | 54.8 |
| Commercial Clarity | 39.5 |
| Access Clarity | 39.5 |

## Agent readiness — 30.6 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | verified |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (35)

- **Google Threat Intelligence - Attack Surface Management (ASM)** — Enterprise add-on (formerly Mandiant Advantage ASM). Discovers and monitors an organisation's external attack surface, scoring exposures and prioritising remediation.
- **Google Threat Intelligence - Digital Threat Monitoring (DTM)** — Enterprise add-on (formerly Mandiant Advantage DTM). Monitors the open, deep, and dark web for credential leaks, brand abuse, and adversary chatter referencing the customer.
- **VirusTotal Access Control - Group Management API** — Access Control - Group Management
- **VirusTotal Access Control - Quota Management API** — Access Control - Quota Management
- **VirusTotal Access Control - Service Account Management API** — Access Control - Service Account Management
- **VirusTotal Access Control - User Management API** — Access Control - User Management
- **VirusTotal IoC Feeds - Domain intelligence feed API** — IoC Feeds - Domain intelligence feed
- **VirusTotal IoC Feeds - File intelligence feed API** — IoC Feeds - File intelligence feed
- **VirusTotal IoC Feeds - IP intelligence feed API** — IoC Feeds - IP intelligence feed
- **VirusTotal IoC Feeds - Sandbox analyses feed API** — IoC Feeds - Sandbox analyses feed
- **VirusTotal IoC Feeds - URL intelligence feed API** — IoC Feeds - URL intelligence feed
- **VirusTotal IoC Investigation - Analyses, Submissions & Operations API** — IoC Investigation - Analyses, Submissions & Operations
- **VirusTotal IoC Investigation - Attack Tactics API** — IoC Investigation - Attack Tactics
- **VirusTotal IoC Investigation - Attack Techniques API** — IoC Investigation - Attack Techniques
- **VirusTotal IoC Investigation - Comments API** — IoC Investigation - Comments
- **VirusTotal IoC Investigation - Domains & Resolutions API** — IoC Investigation - Domains & Resolutions
- **VirusTotal IoC Investigation - Files API** — IoC Investigation - Files
- **VirusTotal IoC Investigation - Files Behaviours API** — IoC Investigation - Files Behaviours
- **VirusTotal IoC Investigation - IP addresses API** — IoC Investigation - IP addresses
- **VirusTotal IoC Investigation - Popular Threat Categories API** — IoC Investigation - Popular Threat Categories
- **VirusTotal IoC Investigation - Search & Metadata API** — IoC Investigation - Search & Metadata
- **VirusTotal IoC Investigation - URLs API** — IoC Investigation - URLs
- **VirusTotal IoC Investigation - Zipping files API** — IoC Investigation - Zipping files
- **VirusTotal Private Scanning - Analyses API** — Private Scanning - Analyses
- **VirusTotal Private Scanning - Files API** — Private Scanning - Files
- **VirusTotal Private Scanning - Files Behaviours API** — Private Scanning - Files Behaviours
- **VirusTotal Private Scanning - URLs API** — Private Scanning - URLs
- **VirusTotal Private Scanning - Zipping files API** — Private Scanning - Zipping files
- **VirusTotal Threat Graphs API** — Threat Graphs
- **VirusTotal Threat Graphs Permissions & ACL API** — Threat Graphs Permissions & ACL
- **VirusTotal Threat Landscape & Vulnerability Intelligence & Reports & Analysis API** — Threat Landscape & Vulnerability Intelligence & Reports & Analysis
- **VirusTotal YARA Hunting - IoC Stream API** — YARA Hunting - IoC Stream
- **VirusTotal YARA Hunting - Livehunt API** — YARA Hunting - Livehunt
- **VirusTotal YARA Hunting - Retrohunt API** — YARA Hunting - Retrohunt
- **VirusTotal YARA Hunting - Rules API** — YARA Hunting - Rules

## Agentic access (1)

- **Virustotal Agentic Access** — 206 operations · 56 acting · 11 human-in-the-loop

## Security (2)

- **Virustotal Authentication** — apiKey · 1 scheme
- **Virustotal Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC

## Plans (1)

- **Virustotal Plans Pricing**

## Tags

Anti Malware, Threat Intelligence, Security, File Analysis, URL Analysis, YARA, IOC, Sandbox, MITRE ATT&CK, Google Cloud

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/virustotal/). Scores are computed from the provider's own public artifacts under a published rubric.
