Supported Indicator Types
Configuration
Set your VirusTotal API key in the.env file:
VirusTotal offers free API keys with a rate limit of 4 requests/minute. Premium keys have higher limits. Calseta respects rate limits and caches results to minimize API calls.
Extracted Fields
These fields are extracted from VirusTotal responses and surfaced to agents in theextracted object:
IP Addresses
Domains
File Hashes
Malice Rules
Default verdict thresholds:
These thresholds are configurable via the enrichment provider’s
malice_rules field.
Cache TTLs
Rate Limits
VirusTotal enforces strict rate limits:
Calseta’s caching significantly reduces API calls — the same indicator across multiple alerts is only enriched once within the cache TTL.

