Skip to main content
Glama
609,343 tools. Updated 2026-09-25 10:41

"VirusTotal" matching MCP tools:

Matching MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    Official VirusTotal MCP server for AI agents: threat intelligence, file analysis, and recovery through VTAI.
    11
    313 PyPI
    1
    Apache 2.0

Matching MCP Connectors

  • VirusTotal MCP — file / URL / domain / IP reputation (BYO key)

  • VirusTotal reports, file and URL submissions, domain/IP reanalysis, and analysis recovery.

  • Submit an HTTP(S) URL for VirusTotal analysis and receive a request ID to check results. Use for scanning suspicious links without sharing secrets.
    Apache 2.0
    Destructive
  • Submit a local file to VirusTotal for security analysis by specifying its path, optionally verifying an expected SHA256 hash.
    Apache 2.0
    Destructive
  • Query VirusTotal for threat intelligence on a file hash. Get detection results from 70+ antivirus engines, file metadata, and behavioral analysis to validate suspicious files or enrich IOCs.
    MIT
  • Retrieve detailed sandbox behavioral analysis for a file hash to understand malware capabilities, including process activity, network connections, and MITRE ATT&CK techniques. Essential for threat detection and incident response.
    MIT
  • Retrieve existing threat intelligence for an HTTP(S) URL without visiting or submitting it. Get VirusTotal and VTAI analysis results for the given URL.
    Apache 2.0
  • Initiate a fresh VirusTotal reanalysis for an IP address with a unique request ID, then retrieve the outcome later—no automatic retries.
    Apache 2.0
    Destructive
  • Retrieve a VirusTotal file report using an MD5, SHA-1, or SHA-256 hash to check threat intelligence and detection results without uploading or rescanning the file.
    Apache 2.0
  • Query VirusTotal for domain threat intelligence including reputation, WHOIS, DNS, and detection results from 90+ security vendors. Investigate suspicious domains in incident response.
    MIT
  • Retrieve a submission receipt and original analysis ID using either a file's SHA256 hash or a network operation's request ID, without uploading or consuming query quota.
    Apache 2.0
  • Request a new VirusTotal analysis for a domain to refresh its threat intelligence and get updated detection results.
    Apache 2.0
    Destructive
  • Retrieve existing threat intelligence for an IPv4 or IPv6 address to identify known malicious activity, without contacting the host.
    Apache 2.0