virustotal.md
For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to page URLs; this page is available as Markdown.
VirusTotal
VirusTotal is a Threat Intelligence (TI) integration. TI Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more tooling integrations enhances Dropzone analysis.
The Dropzone AI platform supports VirusTotal, a threat intelligence service that can analyze suspicious files, domains, IPs and URLs. Their privacy policy is available at https://docs.virustotal.com/docs/privacy-policy.
Create an API Key
VirusTotal requires an API key to enable.
To obtain an API Key, do the following:
- Log into VirusTotal
- From your profile in the upper right, select "API Key"
API Key Menu
- In the "API KEY" section at the top of your screen, find the blurred-out section and click the eyeball icon next to it
- The key will be de-blurred
- Record the value shown for use later in the Dropzone UI where it is called "API key"
API Key Menu
Enable VirusTotal
To enable the Data Source integration, do the following:
- Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app
- In the bottom left hand corner, click Settings > Integrations
Integrations Dropdown
- Click "Available"
Click Available
- In the Search bar, search VirusTotal, then click "Configure"
The VirusTotal Data Tile
- Input the API Key
- Select which scan types you wish to enable
- Click "Test & Save" to finish
The VirusTotal Data Source Configuration
If you have any errors engage your Dropzone AI support representative.