↳ GitHub sourceSolution

VirusTotal

Description

The [VirusTotal](https://www.virustotal.com/gui/) solution for Microsoft Sentinel contains Playbooks that can help enrich incident information with threat information and intelligence for IPs, file hashes and URLs from VirusTotal. Enriched information can help drive focused investigations in Security Operations. **NOTE: This solution includes a few playbooks that use the legacy HTTP data collector API to ingest data. Since that API is about to be deprecated, we recommend using the logingestionapi playbooks instead.**
Version
3.0.2
Declared author / publisher
Microsoft - support@microsoft.com
Support tier
Microsoft

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
azure-sentinel-solution-virustotal
Additional source files 2Solutions/VirusTotal/Data/Solution_VirusTotal.jsonsolution-manifest ↗Solutions/VirusTotal/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.