Overview
This guide walks through how to create a VirusTotal connection and the access it requires to be used in Blink’s Automated Case Management, primarily for Enrichment workflows (threat intelligence lookups for domains, IPs, file hashes, URLs, and email addresses).Unlike Microsoft or CrowdStrike, VirusTotal does not use granular API scopes or permission toggles. Access is controlled by a single API key, and what that key can do is determined by your VirusTotal account tier. See Required Access below.
Creating a Connection
VirusTotal Connection Guide
Follow this guide to create a VirusTotal connection
Which stage of Alert Processing need this connection?
Which stage of Alert Processing need this connection?