VirusTotal Integration

Overview

VirusTotal integration provides automated threat detection for monitored platforms. The system periodically scans platform URLs using the VirusTotal API, analyzes results from multiple antivirus vendors, and automatically generates alerts when threats are detected.

Configuration Setup

API Configuration

Required Settings:

  • API Key - VirusTotal authentication key

  • Scan Frequency - Automated scanning interval (configurable)

  • Available Scan Frequencies: - 1 to 7 days

Configuration Steps:

  1. Navigate to Config > Integration and click VirusTotal’s configure button (https://oju.example.com/config/integrations)

  2. Enter valid VirusTotal API key

  3. Select desired scan frequency

  4. Activate integration

virustotal config
Figure 1. VirusTotal configuration

Scanning Operations

Automated Scanning Process

Scan Execution:

  • Periodic scanning based on configured frequency

  • All active platforms included in scan cycle

  • Sequential processing with rate limiting

  • Comprehensive vendor analysis collection

Scan Workflow:

  1. Retrieve list of active platforms

  2. Submit URLs to VirusTotal API

  3. Collect multi-vendor analysis results

  4. Process threat detection responses

  5. Generate alerts for detected threats

Antivirus Vendor Management

Local Vendor Database

Vendor Information Storage:

  • Name - Antivirus vendor name (case-sensitive)

  • Contact - Primary contact information

  • Comments - Additional notes and details

vendor list
Figure 2. Vendors list

Critical Requirement:

  • Vendor names must match VirusTotal exactly (case-sensitive)

  • Missing vendors result in limited alert information

  • Regular database updates recommended

  • Accurate vendor contact information essential

Database Management:

  1. Navigate to Vendor

  2. Add new vendor with exact name matching VirusTotal

  3. Include complete contact information

  4. Verify case-sensitive name accuracy

  5. Save vendor information for alert enrichment

vendor add
Figure 3. Adding vendor

VirusTotal integration enhances Oju security monitoring by providing automated threat detection, comprehensive vendor analysis, and coordinated incident response for security threats across monitored platforms.