logo

Advanced Threat Hunting: Automating Large-Scale Operations with LLMs

ID: 8fca2b46-66f8-5f48-9f78-dc0dab3cb4ca

STIX ID: report--8fca2b46-66f8-5f48-9f78-dc0dab3cb4ca

Feed Name: VirusTotal Blog

Date Published: 2025-09-30

Date Updated: 2026-05-01

Author: Joseliyo Sánchez

...
...

This report recaps a LABScon workshop on automating large-scale threat hunting with the VirusTotal API and Gemini in Google Colab, featuring a “meta Colab” preloaded with reference documentation and vt-py code snippets. It walks through practical examples—such as hunting malicious LNK files over a time range, flattening and visualizing attributes, building Sankey diagrams of relationships, and mapping submission geographies—along with additional query ideas for campaigns, threat actors, and malware. The focus is on methodology, tooling, and scalable analysis workflows rather than specific incidents or IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.