VirusTotal
Last updated
Last updated
VirusTotal is a Threat Intelligence (TI) integration. TI Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more tooling integrations enhances Dropzone analysis.
The Dropzone AI platform supports VirusTotal, a threat intelligence service that can analyze suspicious files, domains, IPs and URLs. Their privacy policy is available at https://docs.virustotal.com/docs/privacy-policy.
VirusTotal requires an API key to enable.
To obtain an API Key, do the following:
Log into https://www.virustotal.com
From your profile in the upper right, select API Key
In the "API KEY" section of the top of your screen find the blurred-out section and click the eyeball icon next to it
The key will be de-blurred
Record this string for use later in the Dropzone UI where it is called "API key"
To enable the Data Source integration, do the following:
Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.ai
Click System > Integrations
Click "Data Sources" in the top left corner
In the THREAT INTEL section, find the VirusTotal tile and click "Connect"
Input the API Key
Select which scan types you wish to enable
Click "Test & Save" to finish
If you have any errors engage your Dropzone AI support representative.