We are excited to announce the launch of Saved Searches in Google Threat Intelligence (GTI) and VirusTotal (VT), a powerful new feature designed to streamline your threat hunting workflows and foster seamless collaboration across your security team.
From Campaign to Feature: Better Search Efficiency
For the last month, weβve highlighted the critical importance of mastering search in our ongoing #monthofgoogletisearch campaign. We saw how security teams rely on complex, highly-tuned queries to identify threats, track adversaries, and perform deep-dive investigations.
This campaign emphasized a key challenge: once you craft the perfect query - a cornerstone of your investigation - it should be easy to reuse and share. Saved Searches is the direct answer to this need, turning successful, repeatable threat-hunting logic into a shared institutional asset.
Collaboration, Simplified: Save and Share Your Queries
With this initial launch of Saved Searches, weβre delivering two foundational capabilities that will immediately improve your teamβs efficiency:
Save Searches: Instantly save any complex or frequently used query directly within GTI. This ensures your best investigative logic is always accessible, eliminating the need to rebuild queries from scratch or store them externally.
Share with Users: Critical insights are often time-sensitive. You can now easily share your saved searches with any other user in your organization with access to GTI. Whether youβre escalating a finding or establishing a standard workflow, sharing the exact query ensures consistency and accelerates joint analysis.
This means that a newly onboarded analyst can instantly access the expertise of senior members, and teams can maintain a unified approach to monitoring high-priority threats. Itβs collaboration built right into your investigation tool.
Get Started Today with Campaign Searches
The Saved Searches feature is live now in Google Threat Intelligence and VirusTotal.
To help you hit the ground running, we have made the most impactful searches used throughout the #monthofgoogletisearch campaign public and available to all intelligence users! You can find these expert-crafted queries in your Saved Searches section today - a perfect starting point for your investigations.
Start by exploring these campaign searches and then easily save and share your own complex search queries. Look for the option to Save and Share your searches to transform your investigative logic into a shared asset.
This is just the first phase of enhancing search capabilities within GTI. We are committed to building on this foundation to provide even more robust tools that make your threat intelligence actionable and collaborative.
You can get more info by exploring our documentation page:
This November, weβre celebrating the power of VirusTotal Enterprise search!
All VirusTotal customers will enjoy uncapped searches through the GUI β no quota consumption for the entire month so long as it is manual searches via the web interface.
Whether youβre investigating malware campaigns, analyzing infrastructure, or tracking threat actor activity, this is your chance to search freely and explore advanced use cases using VirusTotal Intelligence.
Experiment with powerful VT search modifiers to uncover patterns, hunt for related samples, and pivot across hashes, domains, IP addresses, or URLs β without worrying about your quota.
Whatβs happening
No quota consumption for all GUI searches during November (API interaction will continue to consume).
Every day, weβll share interesting and creative search queries on our LinkedIn and X channels using the hashtag #MonthOfVTSearch.
We invite you to try these searches, interact with us, and share your own search tips and findings with the community.
Learn and level up
Make the most of this month to sharpen your threat-hunting skills:
This search helps identify document files that, when executed in a sandbox environment, show behavior consistent with potential malicious activity involving .ru infrastructure. It specifically looks for:
Documents (type:document) that were uploaded to VT.
During execution, they show process behavior containing:
HTTP traffic (behavior_processes:*http*)
The string DavSetCookie (often observed in HTTP request headers or custom cookie operations)
And references to .ru domains
And additionally, they show network or embedded indicators related to .ru domains via:
Behavior-based network connections (behavior_network:*.ru*), or
Embedded domains or URLs within the file (embedded_domain:*.ru*, embedded_url:*.ru*)
Join the community
Letβs make November a month of discovery and collaboration!
Tag your posts with #MonthOfVTSearch, share your favorite searches, and show the world how you use VirusTotal to explore and understand the threat landscape.