Skip to main content
To enable VirusTotal:
  1. Open the file xcc.yml in the Expert Editor and add the following with your key:
    xcc.yml
  2. Click Publish, then restart the XCC. The virusTotal setting is a general xcc.yml setting and requires the XCC restart to take effect.

Information about the integration

xorlab sends only the SHA256 hash of an attachment to VirusTotal, not the entire attachment. URLs are submitted as-is without prior hashing. By adding your VirusTotal key you agree that this information will be sent to VirusTotal. Please visit VirusTotal website for their Terms and Services and their Privacy Policy as by submitting data those will apply. xorlab only uses the VirusTotal API for items that are manually opened in xorlab, e.g., when opening a message in the detail view. No VirusTotal API requests are performed when an email is not viewed. The following VirusTotal API endpoints are used: