Skip to main content
VirusTotal provides reputation data for IP addresses, domains, and file hashes by aggregating results from 70+ antivirus engines and security services.

Supported Indicator Types

Configuration

Set your VirusTotal API key in the .env file:
VirusTotal offers free API keys with a rate limit of 4 requests/minute. Premium keys have higher limits. Calseta respects rate limits and caches results to minimize API calls.

Extracted Fields

These fields are extracted from VirusTotal responses and surfaced to agents in the extracted object:

IP Addresses

Domains

File Hashes

Malice Rules

Default verdict thresholds: These thresholds are configurable via the enrichment provider’s malice_rules field.

Cache TTLs

Rate Limits

VirusTotal enforces strict rate limits: Calseta’s caching significantly reduces API calls — the same indicator across multiple alerts is only enriched once within the cache TTL.