VirusTotal

VirusTotal Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index


Attribute Value
Publisher Microsoft Corporation
Support Tier Microsoft
Support Link https://support.microsoft.com/
Categories Security - Automation (SOAR)
Version 3.0.2
Author Microsoft - support@microsoft.com
First Published 2022-07-31
Last Updated 2026-09-07
Solution Folder VirusTotal
Marketplace Azure Marketplace · Rating: ★☆☆☆☆ 1.0/5 (1 ratings) · Popularity: 🟢 High (82%)

The VirusTotal solution for Microsoft Sentinel contains Playbooks that can help enrich incident information with threat information and intelligence for IPs, file hashes and URLs from VirusTotal. Enriched information can help drive focused investigations in Security Operations. NOTE: This solution includes a few playbooks that use the legacy HTTP data collector API to ingest data. Since that API is about to be deprecated, we recommend using the logingestionapi playbooks instead.

Contents

Data Connectors

This solution does not include data connectors.

This solution may contain other components such as analytics rules, workbooks, hunting queries, or playbooks.

Tables Used

This solution queries 4 table(s) from its content items:

Table Used By Content
VTDomainReport_CL Playbooks (writes)
VTFileReport_CL Playbooks (writes)
VTIPReport_CL Playbooks (writes)
VTURLReport_CL Playbooks (writes)

Content Items

This solution includes 17 content item(s):

Content Type Count
Playbooks 17

Playbooks

Name Description Tables Used
FileHash Enrichment - Virus Total Report - Alert Triggered using Log Ingestion API This playbook will take each File Hash entity and query VirusTotal for file report (https://develope... -
FileHash Enrichment - Virus Total Report - Incident Triggered using Log Ingestion API This playbook will take each File Hash entity and query VirusTotal for file report (https://develope... -
IP Enrichment - Virus Total Report - Incident Triggered using Log Ingestion API This playbook will take each IP entity and query VirusTotal for IP Address Report (https://developer... -
IP Enrichment - Virus Total Report - Alert Triggered using Log Ingestion API This playbook will take each IP entity and query VirusTotal for IP Address Report (https://developer... -
IP Enrichment - Virus Total Report - Entity Trigger This playbook will query VirusTotal Report for the selected IP Address (https://developers.virustota... -
URL Enrichment - Virus Total Domain Report - Alert Triggered using Log Ingestion API This playbook will take each URL entity and query VirusTotal for Domain info (https://developers.vir... -
URL Enrichment - Virus Total Domain Report - Incident Triggered using Log Ingestion API This playbook will take each URL entity and query VirusTotal for Domain Report (https://developers.v... -
URL Enrichment - Virus Total Report - Alert Triggered using Log Ingestion API This playbook will take each URL entity and query VirusTotal for info (https://developers.virustotal... -
URL Enrichment - Virus Total Report - Incident Triggered using Log Ingestion API This playbook will take each URL entity and query VirusTotal for info (https://developers.virustotal... -
[Deprecated] FileHash Enrichment - Virus Total Report - Alert Triggered This playbook will take each File Hash entity and query VirusTotal for file report (https://develope... VTFileReport_CL (write)
[Deprecated] FileHash Enrichment - Virus Total Report - Incident Triggered This playbook will take each File Hash entity and query VirusTotal for file report (https://develope... VTFileReport_CL (write)
[Deprecated] IP Enrichment - Virus Total Report - Incident Triggered This playbook will take each IP entity and query VirusTotal for IP Address Report (https://developer... VTIPReport_CL (write)
[Deprecated] IP Enrichment - Virus Total Report - Alert Triggered This playbook will take each IP entity and query VirusTotal for IP Address Report (https://developer... VTIPReport_CL (write)
[Deprecated] URL Enrichment - Virus Total Domain Report - Alert Triggered This playbook will take each URL entity and query VirusTotal for Domain info (https://developers.vir... VTDomainReport_CL (write)
[Deprecated] URL Enrichment - Virus Total Domain Report - Incident Triggered This playbook will take each URL entity and query VirusTotal for Domain Report (https://developers.v... VTDomainReport_CL (write)
[Deprecated] URL Enrichment - Virus Total Report - Alert Triggered This playbook will take each URL entity and query VirusTotal for info (https://developers.virustotal... VTURLReport_CL (write)
[Deprecated] URL Enrichment - Virus Total Report - Incident Triggered This playbook will take each URL entity and query VirusTotal for info (https://developers.virustotal... VTURLReport_CL (write)

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.2 04-09-2026 Added playbooks for using the log ingestion API to send data.
3.0.1 02-06-2025 Updated Playbook instructions for clarity
3.0.0 11-01-2024 Updated solution to 3.0.0 to fix IP Enrichment - Virus Total report playbook

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index