Virustotal
for LuumenAI

Check files, URLs, domains, and IPs against VirusTotal without leaving the terminal

Pull VirusTotal reports while you work an incident. Ask about a file hash, a URL, a domain, or an IP and get the engine verdicts, the related infrastructure, and the community notes back in the terminal. When you need a fresh verdict, Luumen can submit a URL or file for scanning as an approved step. Luumen connects with an API key.

The Virustotal toolbox

16 tools: 11 read, 5 write. Reads answer instantly. Writes require approval by default. Everything is logged.

  • ReadGet Analysis ReportRetrieve the analysis report of a file or URL submission.
  • ReadGet commentsRetrieve the latest comments on a VirusTotal resource.
  • ReadGet Domain RelationshipsRetrieve relationship objects for a given domain.
  • ReadGet Domain ReportRetrieve the analysis report of a domain.
  • ReadGet File ReportRetrieve the analysis report of a file.
  • ReadGet IP Address RelationshipsRetrieve objects related to a specific IP address by relationship type.
  • ReadGet IP Address ReportRetrieve the analysis report of an IP address.
  • ReadGet VirusTotal MetadataRetrieve VirusTotal metadata.
  • ReadGet URL ReportRetrieve the analysis report of a URL.
  • ReadGet VotesRetrieve votes on files, URLs, domains, or IP addresses.
  • ReadSearch VirusTotalSearch for objects in the VirusTotal database.
  • WriteAdd VirusTotal CommentAdd a comment to a VirusTotal resource (file, URL, domain, or IP address). Approval by default
  • WriteAdd VoteAdd a vote (harmless/malicious) to a VirusTotal resource. Approval by default
  • WriteRescan FileRe-analyze a previously submitted file. Approval by default
  • WriteScan URLSubmit a URL for scanning. Approval by default
  • WriteUpload FileUpload a file for scanning. Approval by default

One prompt, start to finish

What a governed Virustotal run looks like inside Luumen.

Questions

How does LuumenAI connect to Virustotal?

Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.

Can LuumenAI change things in Virustotal on its own?

Read actions answer immediately. Anything that writes — add virustotal comment, add vote, rescan file, scan url, and more — is shown as a plan and requires approval by default. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.

Who gets access to the integration?

You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.

Is there an audit trail?

Every call to Virustotal — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.

Put Virustotal to work with Luumen

Connect in minutes. Every action scoped, approved, and audited from day one.