Investigating threats using VirusTotal
VirusTotal is a Threat Intelligence Platform (TIP) that allows security analysts to analyze suspicious files, hashes, domains, IPs, and URLs to detect and investigate malware and other cyber threats. Moreover, VirusTotal is known for its robust automation capabilities, which allow for the automatic sharing of this intelligence with the broader security community. See Figure 14.1:
Figure 14.1 – The VirusTotal platform main web page
The VirusTotal scans submitted artifacts, such as hashes, domains, URLs, and IPs, against more than 88 security solution signatures and intelligence databases. As a SOC analyst, you should use the VirusTotal platform to investigate the following:
- Suspicious files
- Suspicious domains and URLs
- Suspicious outbound IPs
Investigating suspicious files
VirusTotal allows cyber security analysts to analyze suspicious files either by uploading the file or searching...