• Last Updated
    Apr 1, 2025
  • Version
    1.0.3
  • Compatibility
    ThreatQ versions >= 4.49.0
  • VirusTotal Collections CDF

    ThreatQuotient

    Overview

    The VirusTotal Collections feed allows a user to ingest all IoCs (IP Address, Domains, URLs, and Hashes) and related attributes from one or multiple VirusTotal collections.

    The integration provides the following endpoint:

    • VirusTotal Collections - GET https://www.virustotal.com/api/v3/collections/ {collection_id}

    Based on the response of the collection, the integration will then execute four additional GET requests:

    • IP Address - GET https://www.virustotal.com/api/v3/collections/{collection_id}/ip_addresses
    • Domains - GET https://www.virustotal.com/api/v3/collections/{collection_id}/domains
    • URLs - GET https://www.virustotal.com/api/v3/collections/{collection_id}/urls
    • Files - GET https://www.virustotal.com/api/v3/collections/{collection_id}/files

    Copyright © 2025, ThreatQuotient, Inc. All Rights Reserved. Privacy Policy