Virustotal

Virustotal MCP integration

Submits suspicious links and files for scanning, polls reports to completion, pivots across related indicators, and records verdicts and comments.

16actions available

Three actions you can hand over today

Every action runs live through MCP. Nothing to build, nothing to maintain.

  • Scan URL

    Lyro submits a suspicious link a customer shared for a fresh security scan. The agent handling the ticket learns whether the URL is malicious before anyone clicks it.

  • Get file report

    Lyro looks up the existing analysis for a file by its hash instead of re-uploading it. A known-bad attachment is identified in seconds, without the wait a fresh scan costs.

  • Search virustotal

    Lyro searches the VirusTotal database for a domain, hash, or address raised in a conversation. The team gets the reputation history behind a report rather than a single yes-or-no verdict.

See all 16 actions

How businesses use Virustotal + Lyro

Each card is one request a support team gets, and the Virustotal actions Lyro runs to close it.

  • Scan something a customer sent in

    Lyro submits the URL or uploads the file for analysis, then polls the resulting analysis report until its status reads completed rather than acting on a partial verdict.

    Scan URLUpload FileGet Analysis Report
  • Check the reputation of a domain or address

    Lyro pulls the analysis report for a domain, an IP with its ASN and country, or a URL identifier, and reads the detection stats behind each one.

    Get Domain ReportGet IP Address ReportGet URL Report
  • Pivot from one indicator to everything around it

    Lyro follows a domain's related entities and the files and URLs connected to an IP address, and runs a database query when the starting point is a partial match.

    Get Domain RelationshipsGet IP Address RelationshipsSearch VirusTotal
  • Record a verdict the team can see

    Lyro votes a resource harmless or malicious, leaves a comment with the context behind that call, and reads back what the wider community has already voted.

    Add VoteAdd VirusTotal CommentGet Votes

How it works

Get started in 3 steps

Connect once, then just ask. There is no workflow builder to learn and nothing to maintain — Lyro reads the Virustotal actions it has and picks the ones a request needs.

  1. 01

    Connect Virustotal

    Authorize the Virustotal account your team already uses — one consent screen, no API keys, no mapping tables. Lyro can only do what you granted that account, and you can disconnect it at any time.

  2. 02

    Tell your agent what you need

    Describe the job the way you would hand it to a teammate. Lyro maps it to the Virustotal actions that close it and chains as many as the request needs.

  3. 03

    Watch it work

    The agent runs the actions inside the conversation the customer is already in, so nobody copies data between tabs and your team can take over at any point.

    Get started free
Virustotal · Lyro

Everything else about Virustotal

Setup, permissions, and the limits of what Lyro can do inside Virustotal.

  • No. Scan URL returns a preliminary analysis ID while engines are still running, and recently uploaded files return partial results too. Lyro polls Get URL Report, Get File Report, or Get Analysis Report with short delays and only treats a report as final once its status reads completed.

Every action available in Virustotal

All 16 actions your agent can call on Virustotal, straight from the live MCP connection.

  • Add virustotal comment

    Add a comment to a VirusTotal resource (file, URL, domain, or IP address).

  • Add vote

    Add a vote (harmless/malicious) to a VirusTotal resource.

  • Get analysis report

    Retrieve the analysis report of a file or URL submission.

  • Get comments

    Retrieve the latest comments on a VirusTotal resource.

  • Get domain relationships

    Retrieve relationship objects for a given domain.

  • Get domain report

    Retrieve the analysis report of a domain.

  • Get file report

    Retrieve the analysis report of a file.

  • Get IP address relationships

    Retrieve objects related to a specific IP address by relationship type.

  • Get IP address report

    Retrieve the analysis report of an IP address.

  • Get virustotal metadata

    Retrieve VirusTotal metadata.

  • Get URL report

    Retrieve the analysis report of a URL.

  • Get votes

    Retrieve votes on files, URLs, domains, or IP addresses.

  • Rescan file

    Re-analyze a previously submitted file.

  • Scan URL

    Submit a URL for scanning.

  • Search virustotal

    Search for objects in the VirusTotal database.

  • Upload file

    Upload a file for scanning.

Ready to connect Virustotal?

Authorize the account and your agent has all 16 actions from the first conversation.

Support agent working at a laptop next to the Lyro mascot