Scan multiple URLs in VirusTotal

Supported in:

The VirusTotal Scan URL action iterates over the selected scope entities, and initiates a request to VirusTotal for each entity whose type is URL. When finished, the action enriches the URL entities with a VirusTotal report and also posts the result on the Case Wall.
An is_risky value is exposed so that you can add further conditions to the playbook for high-risk URLs.

Need more help? Get answers from Community members and Google SecOps professionals.