query
(required): Search query. Examples: a SHA-256 hash, evil.com, 8.8.8.8, type:peexe size:90kb+ tag:signed positives:5+
How to use it
query is exposed by the MCP Virustotal MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the query tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.
Install MCP Virustotal
claude mcp add --transport stdio --env VIRUSTOTAL_API_KEY=your-key virustotal -- npx -y @burtthecoder/mcp-virustotalOther tools in MCP Virustotal (9)
(optional): Continuation cursor for pagination
(required): Domain name to analyze
(required): MD5, SHA-1 or SHA-256 hash of the file
(required): Collection ID (e.g. threat-actor--<uuid>, malware-family--<id>)
(required): IP address to analyze
(optional, default: 10): Maximum number of related objects to retrieve (1-40)
(required): Type of relationship to query
(optional): Array of specific relationships to include in the report
(required): The URL to analyze