Developer Tools · Security

VirusTotal logo

VirusTotal

burtthecoder/mcp-virustotal

A Model Context Protocol (MCP) server for querying the VirusTotal API. This server provides comprehensive security analysis tools with automatic relationship data fetching. It integrates seamlessly with MCP-compatible applications like Claude Desktop.

Install

npm install -g @burtthecoder/mcp-virustotal

Client configuration

{
  "mcpServers": {
    "virustotal": {
      "command": "mcp-virustotal",
      "env": {
        "VIRUSTOTAL_API_KEY": "<VIRUSTOTAL_API_KEY>"
      }
    }
  }
}

Environment variables

VIRUSTOTAL_API_KEY
GitHub stars
45
Category
Developer Tools, Security
License
MIT
Updated
Oct 6, 2026

Features

  • Comprehensive Analysis Reports: Each analysis tool automatically fetches relevant relationship data along with the basic report using VirusTotal's?relationships= query, batched to minimize API calls

  • URL Analysis: Cached-report-first lookups with automatic fallback to scanning, plus contacted domains, downloaded files, and threat actors

  • File Analysis: Detailed analysis of file hashes including behaviors, dropped files, and network connections

  • IP Analysis: Security reports with historical data, resolutions, and related threats

  • Domain Analysis: DNS information, WHOIS data, SSL certificates, and subdomains

  • Detailed Relationship Analysis: Dedicated tools for querying specific types of relationships with pagination support

  • Corpus Search: Free-form search across files, URLs, domains, IPs, and comments, including VTI-style modifier syntax (type:peexe positives:5+)

  • Sandbox Behaviour Summary: Cross-sandbox merged view of processes, files, registry, network, MITRE ATT&CK, IDS alerts, and signature matches

  • Threat Collections: Read APT, malware-family, campaign, and intel-report objects referenced from any report's relationships

  • Rich Formatting: Clear categorization and presentation of analysis results and relationship data

Details on this page are taken from the project's README. Open README

Supported clients

Clients mentioned in this server's README:

View all
Claude Desktop logo

Claude Desktop

Desktop · Freemium · Proprietary

Anthropic's official Claude AI desktop application. Supports MCP servers to extend functionality.

WindowsMacOS
VS Code GitHub Copilot logo

VS Code GitHub Copilot

Desktop · Freemium · MIT

VS Code integrates MCP with GitHub Copilot through agent mode, allowing direct interaction with MCP-provided tools in your agentic coding workflow. Configure servers in Claude Desktop, workspace, or user settings, with guided MCP installation and secure handling of secrets in input variables to avoid leaking hardcoded keys.

WindowsMacOSLinuxWeb

Related MCP servers

More servers
Playwright logo

Playwright

microsoft/playwright

72.2k

Playwright is a framework for web automation and testing. It drives Chromium, Firefox, and WebKit with a single API — in your tests, in your scripts, and as a tool for AI agents.

Developer Tools
repomix logo

repomix

yamadashy/repomix

15.2k

Repomix is a tool that packs a codebase into an AI-friendly format, supporting local and remote repository processing and providing code compression, security checks and multiple output formats.

Developer Tools
UI-TARS-desktop logo

UI-TARS-desktop

bytedance/UI-TARS-desktop

12.9k

TARS is ByteDance's multimodal AI agent stack, shipping two projects: Agent TARS (a CLI and Web UI agent built on MCP) and UI-TARS-desktop (a desktop GUI agent).

Developer Tools
blender logo

blender

ahujasid/blender-mcp

10.6k

formerly blender-mcp — the PyPI package is now mcp-for-blender. Existing setups keep working; no config change is required. Read more.

Developer Tools
Playwright Browser Automation logo

Playwright Browser Automation

microsoft/playwright-mcp

9.2k

A Model Context Protocol (MCP) server that provides browser automation capabilities using Playwright. This server enables LLMs to interact with web pages through structured accessibility snapshots, bypassing the need for screenshots or visually-tuned models.

Developer Tools
2344 logo

2344

comet-ml/opik

7k

Opik is the open-source LLM observability and evaluation platform for AI agent tracing, LLM evaluation, prompt management, and production monitoring. Built by Comet. Apache-2.0 licensed, free to self-host the full platform, with 20,000+ GitHub stars.

Developer Tools