VirusTotal MCP Server

VirusTotal MCP Server

PythonVirustotalSecurityApiThreatIntelligenceMalwareAnalysisCybersecurityJavascriptTypescriptGoRubyR

About This Server

A Model Context Protocol (MCP) server for querying the VirusTotal API. This server provides comprehensive security analysis tools with automatic relationship data fetching. It integrates seamlessly with MCP-compatible applications like Claude Desktop.

Server Information

šŸ“‹ Overview:

The webpage is a GitHub repository for mcp-virustotal, a Model Context Protocol (MCP) server designed to query the VirusTotal API. This server enhances security analysis by automatically fetching relationship data, integrating with MCP-compatible applications like Claude Desktop, and offering various tools for URL, file, IP, and domain analysis.


ā­ Key Points:
  • MCP server for VirusTotal API queries.

  • Comprehensive security analysis with automatic relationship data retrieval.

  • Integrates with MCP-compatible apps (e.g., Claude Desktop).

  • Offers URL, file, IP, and domain analysis tools.

  • Supports detailed relationship analysis with pagination.


  • šŸ” Main Findings:
  • Provides comprehensive reports by fetching relevant relationship data automatically.

  • Offers dedicated tools for detailed analysis and querying of relationships with pagination support.

  • Emphasizes clear formatting for analysis results and relationship data.

  • Includes troubleshooting and error handling for invalid API keys, rate limiting, network errors, and invalid input parameters.

  • Recommends installation through Smithery but provides manual installation instructions as well.


  • šŸ“Š Details:
  • Core features include comprehensive reports, URL analysis, file analysis, IP analysis, and domain analysis.

  • Relationship tools available for URLs (17 types), files (41 types), IPs (12 types), and domains (21 types).

  • Requires Node.js (v18+) and a VirusTotal API key.

  • Includes steps for development, error handling, and version history.


šŸŽÆ Conclusion:
The mcp-virustotal repository offers a tool for querying the VirusTotal API and provides comprehensive security analysis reports with relationship data fetching, enhanced error handling, and version-controlled development.

Server Features

Comprehensive Analysis Reports

Each analysis tool automatically fetches relevant relationship data along with the basic report, providing a complete security overview in a single request

URL Analysis

Security reports with automatic fetching of contacted domains, downloaded files, and threat actors

File Analysis

Detailed analysis of file hashes including behaviors, dropped files, and network connections

IP Analysis

Security reports with historical data, resolutions, and related threats

Domain Analysis

DNS information, WHOIS data, SSL certificates, and subdomains

Detailed Relationship Analysis

Dedicated tools for querying specific types of relationships with pagination support

Rich Formatting

Clear categorization and presentation of analysis results and relationship data

Provider Information

GithubBurtthecoder logo

GithubBurtthecoder

cloud Provider

Visit Provider Website

Quick Actions

Visit Website

MCP Configuration

Available Tools

get_url_reportget_file_reportget_ip_reportget_domain_reportget_url_relationshipget_file_relationshipget_ip_relationshipget_domain_relationship