Virustotal MCP integration
Submits suspicious links and files for scanning, polls reports to completion, pivots across related indicators, and records verdicts and comments.
16actions available
Three actions you can hand over today
Every action runs live through MCP. Nothing to build, nothing to maintain.
Scan URL
Lyro submits a suspicious link a customer shared for a fresh security scan. The agent handling the ticket learns whether the URL is malicious before anyone clicks it.
Get file report
Lyro looks up the existing analysis for a file by its hash instead of re-uploading it. A known-bad attachment is identified in seconds, without the wait a fresh scan costs.
Search virustotal
Lyro searches the VirusTotal database for a domain, hash, or address raised in a conversation. The team gets the reputation history behind a report rather than a single yes-or-no verdict.
How businesses use Virustotal + Lyro
Each card is one request a support team gets, and the Virustotal actions Lyro runs to close it.
Scan something a customer sent in
Lyro submits the URL or uploads the file for analysis, then polls the resulting analysis report until its status reads completed rather than acting on a partial verdict.
Scan URLUpload FileGet Analysis ReportCheck the reputation of a domain or address
Lyro pulls the analysis report for a domain, an IP with its ASN and country, or a URL identifier, and reads the detection stats behind each one.
Get Domain ReportGet IP Address ReportGet URL ReportPivot from one indicator to everything around it
Lyro follows a domain's related entities and the files and URLs connected to an IP address, and runs a database query when the starting point is a partial match.
Get Domain RelationshipsGet IP Address RelationshipsSearch VirusTotalRecord a verdict the team can see
Lyro votes a resource harmless or malicious, leaves a comment with the context behind that call, and reads back what the wider community has already voted.
Add VoteAdd VirusTotal CommentGet Votes
How it works
Get started in 3 steps
Connect once, then just ask. There is no workflow builder to learn and nothing to maintain — Lyro reads the Virustotal actions it has and picks the ones a request needs.
- 01
Connect Virustotal
Authorize the Virustotal account your team already uses — one consent screen, no API keys, no mapping tables. Lyro can only do what you granted that account, and you can disconnect it at any time.
- 02
Tell your agent what you need
Describe the job the way you would hand it to a teammate. Lyro maps it to the Virustotal actions that close it and chains as many as the request needs.
- 03
Watch it work
The agent runs the actions inside the conversation the customer is already in, so nobody copies data between tabs and your team can take over at any point.
Get started free
Everything else about Virustotal
Setup, permissions, and the limits of what Lyro can do inside Virustotal.
No. Scan URL returns a preliminary analysis ID while engines are still running, and recently uploaded files return partial results too. Lyro polls Get URL Report, Get File Report, or Get Analysis Report with short delays and only treats a report as final once its status reads completed.
Every action available in Virustotal
All 16 actions your agent can call on Virustotal, straight from the live MCP connection.
Add virustotal comment
Add a comment to a VirusTotal resource (file, URL, domain, or IP address).
Add vote
Add a vote (harmless/malicious) to a VirusTotal resource.
Get analysis report
Retrieve the analysis report of a file or URL submission.
Get comments
Retrieve the latest comments on a VirusTotal resource.
Get domain relationships
Retrieve relationship objects for a given domain.
Get domain report
Retrieve the analysis report of a domain.
Get file report
Retrieve the analysis report of a file.
Get IP address relationships
Retrieve objects related to a specific IP address by relationship type.
Get IP address report
Retrieve the analysis report of an IP address.
Get virustotal metadata
Retrieve VirusTotal metadata.
Get URL report
Retrieve the analysis report of a URL.
Get votes
Retrieve votes on files, URLs, domains, or IP addresses.
Rescan file
Re-analyze a previously submitted file.
Scan URL
Submit a URL for scanning.
Search virustotal
Search for objects in the VirusTotal database.
Upload file
Upload a file for scanning.
The tools Virustotal sits next to
Same connection, same setup. Pick the next one your team already uses.
Apify
Starts Actors and returns their dataset items, reads what earlier runs collected, digs into run logs, and schedules recurring scrapes with webhooks.
Datagma
Resolve a lead to a verified email and mobile, enrich them from one identifier, and catch job changes before outreach goes out stale.
Interzoid
Scores emails and phone numbers, generates fuzzy-matching keys for names, addresses and companies, standardises messy input, and enriches company records.
Neo4J
Provisions, pauses, and resizes Neo4j Aura instances, takes and restores snapshots, and reports project users and IP filters.
Retently
Triggers transactional surveys after a resolved conversation, reads scores and individual responses, and honours opt-outs immediately.
The odds api
Resolves sport keys, lists fixtures and participants, returns bookmaker prices and market coverage for an event, and reports live scores.

Ready to connect Virustotal?
Authorize the account and your agent has all 16 actions from the first conversation.


