{"uid":"cap_WAL710RvcHiQEallLLqfH","slug":"virustotal-attack-technique-lookup-via-locus-x402-13c7426e","name":"VirusTotal Attack Technique Lookup via Locus x402","description":"Threat intelligence platform — scan files by hash, URLs, domains, and IPs against 70+ antivirus engines and security tools.","url":"https://virustotal.x402.paywithlocus.com/virustotal/attack-technique","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"id":{"type":"string"}}},"responseSchema":{"type":"json","example":{"data":{},"payment":{"scheme":"exact","settledUsdc":"0.001000","authorizedMaxUsdc":"0.001000"},"request":{"id":"00000000-0000-4000-8000-000000000000","statusUrl":"/requests/00000000-0000-4000-8000-000000000000"},"success":true}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.055","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.055/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.055","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.055","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_6k01Am5Q1IHQCOqUSpbsv","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.055","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Retrieve MITRE ATT&CK technique intelligence from VirusTotal by providing a technique ID (e.g. T1059), paid via x402 micropayment.","exampleAgentPrompt":"Can you pull the VirusTotal threat intelligence for MITRE ATT&CK technique T1059 — I want to understand what attack behaviors and tools are associated with it.","exampleUseCases":[{"title":"Threat modeling for a SOC playbook","prompt":"I'm building a detection playbook for command and script interpreter attacks — can you look up MITRE ATT&CK technique T1059 on VirusTotal and give me what threat actors and tools are linked to it?"},{"title":"Investigating a suspicious alert","prompt":"We got an alert flagged with MITRE technique T1566, which is phishing. Can you pull the VirusTotal intelligence on that technique so I can understand what variants and behaviors to look for?"},{"title":"Red team exercise preparation","prompt":"I'm prepping a red team exercise around credential dumping. Can you grab the VirusTotal data for ATT&CK technique T1003 so I can see what tools adversaries typically use for it?"}],"resultDescription":"A JSON object containing VirusTotal intelligence data about the specified MITRE ATT&CK technique, including associated threat actors, tools, malware families, and behavioral metadata, along with payment settlement details and a request tracking ID.","failureModes":["Invalid or non-existent MITRE technique ID returns empty or error data","Payment failure if USDC balance is insufficient for the $0.055 micropayment","Rate limiting or upstream VirusTotal API unavailability causing request failure","Malformed technique ID format (e.g. missing 'T' prefix) may return no results","Network timeout from the Locus x402 proxy layer"],"whenToPreferThis":"Use this endpoint when you need structured threat intelligence specifically tied to a MITRE ATT&CK technique ID and want to leverage VirusTotal's database of 70+ security engines without managing a direct VirusTotal API key. Ideal for agents doing automated threat research, SOC enrichment, or red team planning where per-query micropayment via x402 is acceptable. Prefer this over direct VirusTotal API integration when you need pay-per-use access without subscription management.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T06:48:44.700Z","isFirstParty":false}