Skip to content
Virus Total API Maltego Transform Set For Canari
Branch: master
Clone or download
Latest commit db083e6 Jan 14, 2019
Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
src/ripVT Ready for push Jan 11, 2019
LICENSE Create LICENSE Jan 11, 2019
MANIFEST.in Initial commit Apr 8, 2015
README.md Update README.md Jan 14, 2019
entity.png Entities Jan 14, 2019
pivot.png Splash Jan 11, 2019
setup.py Ready for push Jan 11, 2019

README.md

ripVT

Maltego Canari transforms for Virus Total private API. Provided AS-IS, no warranties, no guarantees.

No jokes in this repo. It's as serious as you are.

Visual Guide Visual Guide 2

Installation

  1. Requires Canari, specifically this branch/version
  2. Install Malformity
sudo python setup.py install
canari create-profile ripVT
  1. Import generated ripVT.mtz
  2. Import entities stored at:
src/ripVT/resources/external/entities.mtz
  1. Copy src/ripVT/resources/etc/ripVT.conf to ~/.canari/
  2. Pivot

Pivots

Multiple unique entities enable forward & reverse searches. Unique graphically-distinguished icons.

Search (Phrase Entity) ->

  • Generic Search
  • Behavioral
  • Engines
  • ITW

Generic

  • Hash -> Download to Repository

Hash -> VT File Report ->

  • Behavioral (Copied Files, Deleted, Downloaded, Moved, Mutex, Network, Opened, Read, Replaced, Written)
  • Imphash
  • Cert / Certs
  • Compile Time
  • Detections
  • Exports / Imports
  • File Names
  • In-The-Wild (ITW) Locations
  • Parents (Dropped / Created By)
  • PE Resources
  • PE Sections
  • SSDEEP
  • Similar-To

Domain -> VT Domain Report ->

  • Undetected/Detected Communicating Samples
  • Undetected/Detected Domain-Embedding Samples
  • Undetected/Detected Domain-Downloaded Samples
  • PCAP
  • Domain Resolutions
  • Siblings
  • Subdomains
  • Detected URLs

IP Address -> VT IP Report

  • Undetected/Detected Communicating Samples
  • Undetected/Detected Domain-Embedding Samples
  • Undetected/Detected Domain-Downloaded Samples
  • PCAP
  • Domain Resolutions
  • Siblings
  • Subdomains
  • Detected URLs

Detections ->

  • Search Detection Name (Engine Included)
  • Search Detection Name (No Engine

Cuckoo -> (Report ID)

  • Report -> Network
You can’t perform that action at this time.