Description
The [VirusTotal](https://www.virustotal.com/gui/) solution for Microsoft Sentinel contains Playbooks that can help enrich incident information with threat information and intelligence for IPs, file hashes and URLs from VirusTotal. Enriched information can help drive focused investigations in Security Operations. **NOTE: This solution includes a few playbooks that use the legacy HTTP data collector API to ingest data. Since that API is about to be deprecated, we recommend using the logingestionapi playbooks instead.**
- Version
- 3.0.2
- Declared author / publisher
- Microsoft - support@microsoft.com
- Support tier
- Microsoft
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
629d1d3↗- Source identifier
azure-sentinel-solution-virustotal
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC