Skip to main content

Workflow Template: Slack Mention to Analyze Suspicious URLs and IPs with VirusTotal

Receive a suspicious list of URLs and/or IPs from Slack, scan using VirusTotal, and report back to the Slack thread the results.

The "Slack Mention to Analyze Suspicious URLs and IPs with VirusTotal" workflow template is designed to enhance security operations by automating the analysis of potentially harmful URLs and IPs shared in Slack. When a Slack message includes the keyword "analyze," the workflow extracts any URLs or IPs, scans them using VirusTotal, and reports the findings back to the original Slack thread. This process helps organizations quickly assess threats and maintain a secure communication environment.

Trigger

Slack

Use Cases

Security Bots

Workflow Breakdown

  1. Respond to a mention event from Slack with the keyword "analyze"

  2. Filter for IPs and URLs from the event

  3. Scan IPs if provided in the event and send the results

  4. Scan URLs if provided in the event and send the results

  5. Send message at the end of the workflow

Vendors

Slack, Utils, VirusTotal

Workflow Output

Updates via Slack

Tips

  • Results will be provided to the originator and original Slack thread.

Did this answer your question?