Threat intelligence · Google

Google VirusTotal

Aggregates verdicts from dozens of antivirus engines and blocklist services on submitted files and URLs, now operated by Google.

VirusTotal takes a file, URL, domain, or IP address a user submits and runs it against dozens of third-party antivirus engines and blocklist services simultaneously, then presents a consolidated verdict showing which vendors flagged it and why. Acquired by Google and operated within Google's security business, it also correlates submissions with metadata, behavioral sandbox reports, and relationship graphs between files, domains, and IPs. A significant, easily overlooked consideration: anything submitted through VirusTotal's standard scanning is shared with the wider security community and antivirus vendors, so it is not a private malware-analysis sandbox. Access ranges from a free Public API with strict rate limits, through Premium and Enterprise API tiers aimed at higher-volume, private, or intelligence-enriched use, all of which are quote-only rather than listed.

At a glance

Vendor Google
Pricing model Free tier + paid plans
Free tier Yes
Deployment Cloud
Open source No
Best for Analysts wanting a fast, multi-engine second opinion on a suspicious file or URL, with the caveat that public submissions are shared with the community.

Pricing

A free Public API with rate limits is open to anyone; Premium, Enterprise, and Intelligence tiers add higher quotas, private submissions, and enrichment but require a sales quote.

Pricing has not been verified yet — see the vendor's site.

Features

  • Multi-engine antivirus and blocklist scanning of files, URLs, domains, and IPs
  • Consolidated vendor-by-vendor verdict reports
  • Relationship graphing between files, domains, and IPs
  • Behavioral sandbox execution reports
  • Free Public API with rate limits
  • Premium/Enterprise API for higher-volume and private use

Profile last reviewed September 21, 2026

Alternatives

Google VirusTotal in the index now

Terms to know

Related guides