Enable threat source in Admin settings, the hashes, url, and IP address artifacts will be sent for VirusTotal scan.
With the VirusToal App installed, it will create a function to perform scan. You may compose an artifact menu or auto rule per your own workflow.
------------------------------
Leo Kuo
------------------------------
Original Message:
Sent: Wed August 18, 2021 09:20 AM
From: Pierre Dufresne
Subject: Diffrence between VirusTotal threat source and VirusTotal app
Hi,
I am still learning about SOAR and I was wondering what is the difference between the VirusTotal threat source from the "Administrator Settings" and the VirusTotal app that can be installed from the app Exchange?
Thanks
------------------------------
Pierre Dufresne
------------------------------