Introducing Autocomplete for VirusTotal Intelligence queries
#1
Information 
Quote:
[Image: Logo_VT_Horizontal.png]

TL;DR: We implemented an Autocomplete feature for VirusTotal Intelligence queries

VirusTotal Intelligence is one of the most powerful, flexible and intuitive tools for security researchers around the world. It was designed with the idea of providing (almost) unlimited possibilities to VirusTotal users when searching across the VirusTotal dataset at Google speed ©. Most of the time our users simply search for some observable (hash, domain, IP address or URL) to get everything we know about it, however there are more than 50 modifiers that can be used (and combined) in any query to get what we are exactly looking for.

This is a very real need. Let’s say we search for a given string we know is related to some malware family, returning a few thousand results. How to further specify where we want this string to be found inside the sample? Should it be in the content of the malware, in its metadata, maybe in a signature? You get the idea, and this is not limited to string searches. You can check malware with a certain number of positive verdicts, seen during a particular time window, signed with a given key, triggering a specific crowdsourced YARA rule, etc. Our 2019 VirusTotal for investigators workshop (you can find the video here) dives into some interesting search modifier use cases. Here you can find a full list of Intelligence modifiers you can use in your queries, understanding and using them in your queries provides analysts with an incredibly powerful resource.

However, learning them by heart is not easy. At VirusTotal we spend most of our time dealing with them and still we hesitate from time to time. That’s why we implemented an Autocomplete feature that will offer you different possibilities on what modifier to use depending on what you are typing.
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Hasleo software (formerly called EasyUE...
Hasleo WinToUSB V10....jasonX — 16:10
AxCrypt 3.0.0.94
AxCrypt 3.0.0.94: ...harlan4096 — 11:41
NVIDIA GeForce Game Ready 596.49 driver
Highlights  Gam...harlan4096 — 11:40
AMD launches six new Ryzen PRO 9000 CPUs...
AMD Ryzen PRO 9000...harlan4096 — 11:39
AMD HDMI 2.1 DSC patches could bring 4K ...
AMDGPU HDMI 2.1 pa...harlan4096 — 11:37

[-]
Birthdays
Today's Birthdays
avatar (38)owysykan
avatar (49)beautgok
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (39)axuben
avatar (40)ihijudu
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
avatar (49)contjrat
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>