Scan multiple URLs in VirusTotal

Supported in:
Google secops SOAR

The VirusTotal Scan URL action iterates over the selected scope entities, and initiates a request to VirusTotal for each entity whose type is URL. When finished, the action enriches the URL entities with a VirusTotal report and also posts the result on the case wall. An is_risky value is exposed so that you can add further conditions to the playbook for high-risk URLs. For details on how to use the Scan Hash action to scan file hashes with VirusTotal, mark entities as suspicious, and show insights, see the Scan Hash action for VirusTotal.

Need more help? Get answers from Community members and Google SecOps professionals.

Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.

Last updated 2025年11月24日 UTC.