Skip to main content

Overview

This guide walks through how to create a VirusTotal connection and the access it requires to be used in Blink’s Automated Case Management, primarily for Enrichment workflows (threat intelligence lookups for domains, IPs, file hashes, URLs, and email addresses).
Unlike Microsoft or CrowdStrike, VirusTotal does not use granular API scopes or permission toggles. Access is controlled by a single API key, and what that key can do is determined by your VirusTotal account tier. See Required Access below.

Creating a Connection

VirusTotal Connection Guide

Follow this guide to create a VirusTotal connection
Your VirusTotal API key carries all of your account’s privileges. Keep it secure and do not share it.