# Install virustotal-cli with Homebrew, apt, winget

Command-line interface for VirusTotal. Version 1.3.1 via Homebrew; verified 2026-07-26. Also installable with debian: sudo apt install vt.

## Install

```sh
sudo av install brew:virustotal-cli
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install virustotal-cli
```

  Evidence: local Homebrew formula metadata

### Linux

- Debian apt (92%):

```sh
sudo apt install vt
```

  Evidence: Debian stable package indexes: vt from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz

### Windows

- winget (92%):

```sh
winget install --id VirusTotal.vt-cli -e
```

  Evidence: Windows Package Manager source index: VirusTotal.vt-cli from https://cdn.winget.microsoft.com/cache/source.msix

## Package facts

- **Package key:** brew:virustotal-cli
- **Package manager:** Homebrew
- **Version:** 1.3.1
- **Source summary:** Command-line interface for VirusTotal
- **Homepage:** <https://virustotal.github.io/vt-cli/>
- **Repository:** <https://github.com/VirusTotal/vt-cli>
- **Last updated:** 2026-07-26T00:30:33+02:00
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- vt (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 1.3.1
## Project history and usage

VirusTotal CLI, shipped upstream as vt-cli and invoked as `vt`, is VirusTotal's command-line interface for interacting with VirusTotal from terminals and scripts. It wraps common VirusTotal API workflows such as file, URL, domain, IP, analysis, download, search, hunting, and collection commands.

### Project history

The public vt-cli repository was created in May 2018, and GitHub releases list version 0.2.0 on May 29, 2018. The project is maintained under the VirusTotal GitHub organization, uses an Apache-2.0 license, and publishes command documentation through GitHub Pages.

vt-cli belongs to the API v3 era of VirusTotal tooling: instead of being only a web interface for manual submissions, VirusTotal documents APIs and client libraries for automation. The CLI packages that automation into a single binary with global options for API key, output format, silent mode, and verbosity.

### Adoption history

The CLI is mainly adopted by malware analysts, incident responders, threat hunters, and DevOps/security engineers who already use VirusTotal's web service. It has a narrower audience than VirusTotal itself, but it is valuable wherever terminal workflows and repeatable scripts are preferred over browser-driven lookups.

VirusTotal's own API documentation describes programmatic access for uploading and scanning files or URLs, retrieving reports, and building scripts without the website interface. vt-cli makes those same workflows accessible to shell users and package-manager users who want a maintained official client.

### How it is used

Typical usage begins with configuring an API key, either through `vt init`, a config file, or a command-line option. Users then run commands such as `vt file`, `vt url`, `vt domain`, `vt ip`, `vt analysis`, `vt scan`, or `vt hunting`, often with JSON, YAML, or CSV output for downstream processing.

Package users tend to install vt-cli for quick hash lookups, file and URL submissions, triage scripts, and security automation. Its command surface mirrors VirusTotal object types, so it fits naturally into pipelines that already collect hashes, suspicious URLs, domains, IP addresses, or YARA/LiveHunt context.

### Why package nerds care

virustotal-cli is package-nerd useful because it turns a web threat-intelligence service into a composable Unix-style command. It is not a scanner engine itself; its power comes from letting local scripts and incident-response notebooks ask VirusTotal for reputation and analysis data at the exact point where artifacts are being handled.

### Timeline

- 2018-05-15: The public VirusTotal/vt-cli repository was created.
- 2018-05-29: GitHub releases list vt-cli 0.2.0.
- 2026-05-19: GitHub releases list vt-cli 1.3.1.

### Related projects

- VirusTotal's API v3 is the service interface behind the CLI. The broader VirusTotal ecosystem includes the web UI, API scripts and client libraries, LiveHunt/YARA workflows, and VirusTotal Enterprise features.

### Sources

- VirusTotal API scripts and client libraries documentation: https://docs.virustotal.com/docs/api-scripts-and-client-libraries
- VirusTotal API v3 overview: https://docs.virustotal.com/reference/overview
- VirusTotal files API documentation: https://docs.virustotal.com/reference/files
- VirusTotal vt-cli GitHub repository: https://github.com/VirusTotal/vt-cli
- VirusTotal vt-cli command documentation: https://virustotal.github.io/vt-cli/doc/vt.html
- VirusTotal vt-cli releases: https://github.com/VirusTotal/vt-cli/releases


## Security Notes

No matching local secret-handling manifest was found for virustotal-cli. Nucleus package metadata is still published here so future coverage has a stable package URL.



## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: ~/.vt.toml

## Credential files

- Unix: ~/.vt.toml
## Other Package-Manager Records

- Debian apt - vt - 0.57721+ds-3+b1: installed executable or alias match | Debian stable package indexes: vt from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | toolset for short variant discovery in genetic sequence data | https://genome.sph.umich.edu/wiki/Vt
- Debian apt - vt-examples - 0.57721+ds-3: installed executable or alias match | Debian stable package indexes: vt-examples from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | toolset for short variant discovery in genetic sequence data (examples) | https://genome.sph.umich.edu/wiki/Vt
- Ubuntu apt - vt - 0.57721+ds-3build2: installed executable or alias match | Ubuntu 24.04 LTS package indexes: vt from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz | toolset for short variant discovery in genetic sequence data | https://genome.sph.umich.edu/wiki/Vt
- Ubuntu apt - vt-examples - 0.57721+ds-3build2: installed executable or alias match | Ubuntu 24.04 LTS package indexes: vt-examples from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz | toolset for short variant discovery in genetic sequence data (examples) | https://genome.sph.umich.edu/wiki/Vt
- winget - VirusTotal.vt-cli: installed executable or alias match | Windows Package Manager source index: VirusTotal.vt-cli from https://cdn.winget.microsoft.com/cache/source.msix


## Combined YAML source

View the package source record on GitHub. [combined/virustotal-cli.yml](https://github.com/mxcl/pkgdb/blob/main/combined/virustotal-cli.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
