> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# VirusTotal

## Overview

This guide walks through how to create a VirusTotal connection and the access it requires to be used in Blink's Automated Case Management, primarily for **Enrichment** workflows (threat intelligence lookups for domains, IPs, file hashes, URLs, and email addresses).

<Note>
  Unlike Microsoft or CrowdStrike, VirusTotal does not use granular API scopes or permission toggles. Access is controlled by a single API key, and what that key can do is determined by your VirusTotal account tier. See [Required Access](#required-access) below.
</Note>

***

## Creating a Connection

<Card title="VirusTotal Connection Guide" icon="arrow-up-right-from-square" href="https://docs.blinkops.com/docs/integrations/virustotal">
  Follow this guide to create a VirusTotal connection
</Card>

<Warning>
  Your VirusTotal API key carries all of your account's privileges. Keep it secure and do not share it.
</Warning>

***

<AccordionGroup>
  <Accordion title="Which stage of Alert Processing need this connection?" icon="table">
    | Source | Requires this connection? | Notes |
    | - | - | - |
    | Ingestion | ✗ No | Not applicable |
    | Enrichment | ✓ Yes | Threat intel lookups (domain, IP, file hash, URL, email) |
    | Response | ✗ No | Not applicable |
  </Accordion>
</AccordionGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.