---
title: "VirusTotal Enrichment | ThreatConnect"
slug: "virustotal-enrichment"
description: "This article describes how to enable the VirusTotal enrichment service in ThreatConnect, view data retrieved from VirusTotal on the Enrichment tab of an Indicator’s Details screen, and import Indicators from VirusTotal into ThreatConnect."
tags: ["Enriching Data", "Viewing Data"]
updated: 2025-03-11T19:30:53Z
published: 2025-03-11T19:30:53Z
---

> ## Documentation Index
> Fetch the complete documentation index at: https://knowledge.threatconnect.com/llms.txt
> Use this file to discover all available pages before exploring further.

# VirusTotal Enrichment

## Overview

The VirusTotal™ built-in enrichment in ThreatConnect® lets you use the extensive scanning and analysis capabilities of VirusTotal directly within ThreatConnect, providing you with contextual information about a given file, domain, IP address, or URL and enabling you to make faster and more well-informed decisions about potential threats to your organization.

This article describes how to enable the VirusTotal enrichment service in ThreatConnect, view data retrieved from VirusTotal on the **Enrichment**tab of an Indicator’s **Details**screen, and import Indicators from VirusTotal into ThreatConnect.

## Before You Start

### User Roles

- To enable and configure the VirusTotal enrichment, your user account must have a [System role](https://knowledge.threatconnect.com/docs/threatconnect-system-roles-and-permissions) of Administrator.
- To view VirusTotal data on the **Enrichment** tab of an Indicator’s **Details** screen, your user account can have any [Organization role](https://knowledge.threatconnect.com/docs/organization-roles).
- To retrieve data manually on the **VirusTotal** card on the **Enrichment** tab of an Indicator’s **Details** screen, your user account can have any Organization role.
- To import VirusTotal data into an Organization, your user account must have an Organization role of Standard User, Sharing User, Organization Administrator, or App Developer.
- To import VirusTotal data into a Community or Source, your user account must have a [Community role](https://knowledge.threatconnect.com/docs/community-roles) of Contributor, Editor, or Director for that Community or Source.

### Prerequisites

- A VirusTotal API key. To obtain a VirusTotal API key, create a free VirusTotal API user account at [virustotal.com/gui/join-us](https://virustotal.com/gui/join-us).

## Enabling the VirusTotal Enrichment

Before you can retrieve data from VirusTotal, you must enable and configure the VirusTotal enrichment in ThreatConnect. Follow these steps to enable and configure the VirusTotal enrichment on your ThreatConnect instance:

1. Hover over **Settings![Settings icon](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Settings%20icon.png)**on the top navigation bar and select **System Settings**.
2. Select the **Indicators**tab on the **System Settings**screen, and then click **Enrichment Tools**in the sidebar.
3. Click **Edit![Pencil icon_Black](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Pencil%20icon_Black.png)**in the **Options**column for **VirusTotal**and fill out the fields on the **Edit Vendor**window (Figure 1) as follows:  
![Figure 1_VirusTotal Enrichment_7.8.1](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%201_VirusTotal%20Enrichment_7.8.1.png)
  - **Enable Vendor**: Select this checkbox to enable VirusTotal.
  - **Enable Automatic Retrieval**: Select this checkbox to enable automatic data retrieval for VirusTotal. If automatic data retrieval is enabled, VirusTotal data will automatically populate when a user opens an Address, File, Host, or URL Indicator's **Enrichment** tab for the first time. This checkbox is selected by default.
  - **API Key**: Enter the API key that will be used to retrieve data from VirusTotal.NoteFor VirusTotal, the type of API key entered (Premium or Public) determines the type and amount of information displayed on the **VirusTotal Detailed View**drawer that users can access from the **Enrichment**tab. See the [“VirusTotal Detailed View”](/docs/virustotal-enrichment#virustotal-detailed-view) section for details on which content requires a Premium API key.
  - **VALIDATE**: After entering the VirusTotal API key, click this****button to validate it. If the API key is accepted, the **VALIDATE**button’s label will change to **VALID**.
  - **Lookup/Retrieve**: Select one or more Indicator types to retrieve data from VirusTotal for. Available Indicator types include Address, File, Host, and URL.
4. Click **SAVE**on the **Edit Vendor**window to save the configuration for the VirusTotal enrichment.

When VirusTotal is enabled, a value of **true**will be displayed in the **Enabled**column for its entry on the **Enrichment Tools**screen.

## Data Overview

The **Overview**section of the **VirusTotal**card (Figure 2) on the [**Enrichment** tab](https://knowledge.threatconnect.com/docs/the-enrichment-tab#viewing-enrichment-data) of an Address, File, Host, or URL Indicator’s **Details** screen provides a summary of data retrieved from VirusTotal for the Indicator and the date and time the data were last retrieved.

![Figure 2_VirusTotal Enrichment_7.3.0](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%202_VirusTotal%20Enrichment_7.8.1.png)

Depending on the type of Indicator you are viewing, the **Overview**section displays the following information:

- **Address Indicator**
  - **Score**: The Address’s VirusTotal Score (i.e., the total number of VirusTotal partners who consider the Address harmful out of the total number of partners who reviewed the Address).
  - **Tags**: The Tags applied to the Address in VirusTotal.
  - **Domain Name**: The domain name corresponding to the Address.
  - **Country**: The country where the Address is placed.
  - **ASN**: The autonomous system (AS) number to which the Address belongs.
  - **First Seen/Referenced**: The date and time when the Address was first seen or referenced.
  - **Last Seen/Referenced**: The date and time when the Address was last seen or referenced.
- **File Indicator**
  - **Score**: The File’s VirusTotal Score (i.e., the total number of VirusTotal partners who consider the File harmful out of the total number of partners who reviewed the File).
  - **MD5**: The File’s MD5 file hash.
  - **SHA-1**: The File’s SHA1 file hash.
  - **SHA-256**: The File’s SHA256 file hash.
  - **Imphash**: The File’s import hash.
  - **File Type**: The File’s type.
  - **File Size**: The File’s size in kilobytes (KB).
  - **Tags**: The Tags applied to the File in VirusTotal.
  - **First Seen/Referenced**: The date and time when the File was first seen or referenced.
  - **Last Seen/Referenced**: The date and time when the File was last seen or referenced.
- **Host Indicator**
  - **Score**: The Host’s VirusTotal Score (i.e., the total number of VirusTotal partners who consider the Host harmful out of the total number of partners who reviewed the Host).
  - **Last DNS Record**: The Host’s DNS record on its last VirusTotal scan.
  - **Registrar**: The company that registered the Host.
  - **Tags**: The Tags applied to the Host in VirusTotal.
  - **First Seen/Referenced**: The date and time when the Host was first seen or referenced.
  - **Last Seen/Referenced**: The date and time when the Host was last seen or referenced.
- **URL Indicator**
  - **Score**: The URL’s VirusTotal Score (i.e., the total number of VirusTotal partners who consider the URL harmful out of the total number of partners who reviewed the URL).
  - **Final URL**: The final URL to which the original URL redirects.
  - **Serving IP**: The IP address from which the URL is being served.
  - **Status**: The HTTP status code corresponding to the URL.
  - **Tags**: The Tags applied to the URL in VirusTotal.
  - **First Seen/Referenced**: The date and time when the URL was first seen or referenced.
  - **Last Seen/Referenced**: The date and time when the URL was last seen or referenced.

HintWhen [constructing a TQL query](https://knowledge.threatconnect.com/docs/constructing-query-expressions), you can use the **vtMaliciousCount**parameter to query for Indicators based on their VirusTotal Score.

## VirusTotal Detailed View

Click **Open Detailed View**on the **VirusTotal**card to open the **VirusTotal Detailed View**drawer (Figure 3). This drawer displays cards with additional data retrieved from VirusTotal. The cards are collapsed by default and vary based on the type of Indicator you are viewing. Figure 3 shows the **VirusTotal Detailed View**drawer with all available cards expanded.

![Figure 4_VirusTotal Enrichment_7.3.0](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%203_VirusTotal%20Enrichment_7.8.1.png)

Depending on the type of Indicator you are viewing, as well as whether you are using a VirusTotal Public or Premium API key, the **VirusTotal Detailed View**drawer displays the following cards:

- **Address Indicator**
  - **Passive DNS Replication**: The domains to which the Address resolves.
  - **Last HTTPS Certificate**: The certificate details observed when attempting a standard HTTPS connection to the Address.
  - **URLs**: (Requires a VirusTotal Premium API key) The URLs to which the Address resolves.
- **File Indicator**
  - **Contacted Domains**: The domains contacted by the File.
  - **Contacted IPs**: The IP addresses contacted by the File.
  - **Contacted URLs**: The URLs contacted by the File.
- **Host Indicator**
  - **Categories**: The categories provided by URL sandboxing engines to which the URL or domain content belongs.
  - **Passive DNS Replication**: The IP addresses to which the Host resolves.
  - **URLs**: (Requires a VirusTotal Premium API key) The URLs to which the Host resolves.
- **URL Indicator**
  - **Categories**: The categories provided by URL sandboxing engines to which the URL or domain content belongs.
  - **Contacted Domains**: (Requires a VirusTotal Premium API key) The domains from which the URL loads some type of resource.
  - **Contacted IPs**: (Requires a VirusTotal Premium API key) The IP addresses from which the URL loads some type of resource.

NoteIf the **VirusTotal Detailed View**drawer does not display a card available for an Indicator type (e.g., the drawer does not display the **Contacted URLs**card for a File Indicator), then no data for that card were returned from VirusTotal. Similarly, some cards require a VirusTotal Premium API key and will not be displayed if your System Administrator entered a VirusTotal Public API key when [configuring the VirusTotal enrichment](/docs/virustotal-enrichment#enabling-the-virustotal-enrichment).

## Importing Indicators From VirusTotal Into ThreatConnect

You may import Indicators displayed on the **Contacted Domains**, **Contacted IPs**, **Contacted URLs**, **Passive DNS Replication**, and **URLs** cards into ThreatConnect and associate them to a new or existing Group. You may also import Indicators displayed on these****cards into ThreatConnect and associate them directly to the enriched Indicator (i.e., the Indicator whose **Details**screen you are viewing) via a custom association.

Follow these steps to import Indicators from VirusTotal into ThreatConnect:

1. Expand one of the following cards on the **VirusTotal Detailed View**drawer (Figure 3) to view Indicators retrieved from VirusTotal that are related to the enriched Indicator:
  - **Contacted Domains**: (Available for File and URL Indicators only) Indicators on this card will be imported as Host Indicators.
  - **Contacted IPs**: (Available for File and URL Indicators only) Indicators on this card will be imported as Address Indicators.
  - **Contacted URLs**: (Available for File Indicators only) Indicators on this card will be imported as URL Indicators.
  - **Passive DNS Replication**: (Available for Address and Host Indicators only) If the enriched Indicator is an Address, Indicators on this card will be imported as Host Indicators. If the enriched Indicator is a Host, Indicators on this card will be imported as Address Indicators.
  - **URLs**: (Available for Address and Host Indicators only) Indicators on this card will be imported as URL Indicators.
2. Select the checkbox for each Indicator to import into ThreatConnect, or select the checkbox in the table’s header to import all Indicators displayed on the current page in the table.ImportantIf a selected Indicator already exists in the ThreatConnect owner into which you are importing data, that copy of the Indicator will be updated based on the information entered and options configured during the****import.
3. Expand the **Import**dropdown at the top left of the card and select one of the following import options (Figure 4):![Figure 5_VirusTotal Enrichment_7.3.0](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%204_VirusTotal%20Enrichment_7.8.1.png)
  - [**To New Group**](/docs/virustotal-enrichment#importing-indicators-into-a-new-group): Select this option to import the selected Indicators and associate them to a new Group created during the import.
  - [**To Existing Group**](/docs/virustotal-enrichment#importing-indicators-into-an-existing-group): Select this option to import the selected Indicators and associate them to an existing Group.
  - [**As an Indicator**](/docs/virustotal-enrichment#importing-indicators-as-indicators): Select this option to import the selected Indicators and associate them directly to the enriched Indicator via a custom association.

NoteIf associating the Indicators selected for import to a new or existing Group, the Group will also be associated to the enriched Indicator, thus creating a second-level (i.e., indirect) association between the Indicators imported from VirusTotal and the enriched Indicator.

### Importing Indicators Into a New Group

Follow these steps to import Indicators from VirusTotal and associate them to a new Group created during the import:

1. Follow Steps 1–3 in the [“Importing Indicators From VirusTotal Into ThreatConnect”](/docs/virustotal-enrichment#importing-indicators-from-virustotal-into-threatconnect) section and select **To New Group**from the **Import**dropdown.
2. Proceed through the steps on the **Create**screen to create the Group and configure the Indicators selected for import. There are three steps in this process: [**Details**](/docs/virustotal-enrichment#step-1-enter-details-about-the-group) (required), [**Associations**](/docs/virustotal-enrichment#step-2-enter-details-about-associated-indicators-optional) (optional), and [**Attachments**](/docs/virustotal-enrichment#step-3-upload-file-attachments-to-the-group-optional) (optional).

#### Step 1: Enter Details About the Group

The **Details**step of the **Create**screen (Figure 5) is a required step where you enter basic information about the Group you are creating.

![Figure 6_VirusTotal Enrichment_7.3.0](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%205_VirusTotal%20Enrichment_7.8.1.png)

1. Provide the following details for the Group:
  - **Type**: By default, **Event**is selected. However, you can select another [Group type](https://knowledge.threatconnect.com/docs/the-threatconnect-data-model) from the dropdown. If you select a new Group type from the **Type**dropdown, the [fields on the **Details**step](https://knowledge.threatconnect.com/docs/creating-groups#additional-details-step-fields) will change based on the new Group type.
  - **Owner**: Select the [owner](https://knowledge.threatconnect.com/docs/ownership-in-threatconnect) in which to create the Group.
  - **Summary**: Enter a name for the Group.
  - **Description**: (Optional) Enter a [Description](https://knowledge.threatconnect.com/docs/the-description-attribute) for the Group.****To apply the Description to the Indicators that will be associated to the Group, select **Apply Description To Associations**.
  - **Tags**: (Optional) Enter one or more [Tags](https://knowledge.threatconnect.com/docs/applying-tags) to apply to the Group. (By default, the **Tags**field includes a **VirusTotal Enrichment**Tag.) To****apply the Tags to the Indicators that will be associated to the Group, select **Apply Tags To Associations**.ImportantIf you select **Apply Tags to Associations**, it is recommended that you remove the **VirusTotal Enrichment** Tag from the **Tags**field so that the Tag is not applied to the enriched Indicator (that is, the Indicator whose **Enrichment** tab you are importing VirusTotal data from), as this Indicator will be added as an association to the new Group. Alternatively, if you want to apply the **VirusTotal Enrichment** Tag to all associations except for the enriched Indicator, select **Apply Tags to Associations**, leave the **VirusTotal Enrichment**Tag in the **Tags**field, and then, after completing the import, navigate to the enriched Indicator’s **Details** screen and [remove the Tag from the Indicator manually](https://knowledge.threatconnect.com/docs/applying-tags#removing-a-tag-from-an-object).
2. Click **Next** to proceed to the optional [**Associations**step](/docs/virustotal-enrichment#step-2-enter-details-about-associated-indicators-optional).NoteThe **Save**button is available only on the **Associations**and **Attachments**steps.

#### Step 2: Enter Details About Associated Indicators (Optional)

The **Associations**step of the **Create**screen (Figure 6) is an optional step where you configure the Indicators from VirusTotal that are being created and [associated](https://knowledge.threatconnect.com/docs/associations) to the new Group.

![Graphical user interface Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%206_VirusTotal%20Enrichment_7.8.1.png)

Follow these steps to fill out the fields on the **Associations**step:

1. (Optional)****On the **Associations**card, review the table of Indicators that will be created and associated to the Group. This table includes all selected Indicators and the enriched Indicator. To remove an Indicator from the table, click **Delete![Trash icon_Black](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Trash%20icon_Black.png)**in the **Actions**column.NoteThe table on the **Associations**card will include a **Private**column if your System Administrator turned on private Indicators for your ThreatConnect instance. To mark an Indicator as [private](https://knowledge.threatconnect.com/docs/private-indicators), select the corresponding checkbox in the **Private** column.NoteA checkmark in the **Known**column indicates that the corresponding Indicator exists in the owner in which you are creating the Group and Indicators.
2. (Optional) On the **Association Details**card, provide the following details for *all*Indicators that will be created and associated to the Group:ImportantAll information added in this section will be applied to the enriched Indicator (that is, the Indicator whose **Enrichment** tab you are importing VirusTotal data from), because the enriched Indicator is always added as an association to the new Group, along with the Indicators selected on the card on the **VirusTotal Detailed View**drawer (Figure 4). If the enriched Indicator has a default Description, a Threat Rating, or a Confidence Rating and you enter a value for one of these fields, then that value will replace the existing value for the enriched Indicator. Tags entered in this section will be applied in addition to the enriched Indicator’s existing Tags.
  - **Description**: Enter a default [Description](https://knowledge.threatconnect.com/docs/the-description-attribute) for the Indicators. If you entered a Description for the Group on the [**Details** step](/docs/virustotal-enrichment#step-1-enter-details-about-the-group) and selected **Apply Description to Associations**, the text box will contain that Description.
  - **Tags**: Enter one or more [Tags](https://knowledge.threatconnect.com/v1/docs/applying-tags) to apply to the Indicators. If you entered Tags for the Group on the [**Details** step](/docs/virustotal-enrichment#step-1-enter-details-about-the-group) and selected **Apply Tags to Associations**, the text box will contain those Tags.
  - **Threat Rating**: Set the [Threat Rating](https://knowledge.threatconnect.com/v1/docs/setting-indicator-threat-and-confidence-ratings) for the Indicators.
  - **Confidence Rating**: Set the [Confidence Rating](https://knowledge.threatconnect.com/v1/docs/setting-indicator-threat-and-confidence-ratings) for the Indicators.
3. Click **Next**to proceed to the optional [**Attachments**step](/docs/virustotal-enrichment#step-3-upload-file-attachments-to-the-group-optional), or click **Save**to create the Group and Indicators.

#### Step 3: Upload File Attachments to the Group (Optional)

If you click **Next**on the **Associations**step, you will proceed to the optional **Attachments**step of the **Create**screen (Figure 7). Here, you can upload and attach related files to the Group.![Graphical user interface, text, application, email, website Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%207_VirusTotal%20Enrichment_7.8.1.png)

Follow these steps to proceed through the **Attachments**step:

1. Upload one or more files for which Document Groups will be created and associated to the Group being created.
2. After a file is uploaded, the filename will be displayed below the upload area, along with the **Add to Malware Vault** checkbox. Leave this checkbox cleared unless you are [uploading a malware file](https://knowledge.threatconnect.com/docs/uploading-malware).
3. Click **Save** to create the Group and Indicators.

After you complete the import process, the Group’s **Details**screen will open. You can view the Indicators that were imported and associated to the Group on the [**Indicator Associations**card](https://knowledge.threatconnect.com/docs/the-associations-tab#indicator-associations) of the Group’s [**Associations** tab](https://knowledge.threatconnect.com/docs/the-associations-tab).

### Importing Indicators Into an Existing Group

Follow these steps to import Indicators from VirusTotal and associate them to an existing Group:

1. Follow Steps 1–3 in the [“Importing Indicators From VirusTotal Into ThreatConnect”](/docs/virustotal-enrichment#importing-indicators-from-virustotal-into-threatconnect) section and select **To Existing Group**from the **Import**dropdown.
2. Proceed through the steps on the **Import to Existing Group**screen to select an existing Group and configure the Indicators selected for import. There are two steps in this process: [**Select Group**](/docs/virustotal-enrichment#step-1-select-an-existing-group) (required) and [**Associations**](/docs/virustotal-enrichment#step-2-enter-details-about-associated-indicators-optional1) (optional).

#### Step 1: Select an Existing Group

The **Select Group**step of the **Import to Existing Group**screen (Figure 8) is a required step where you select an existing Group to associate to the imported Indicators.![Graphical user interface, application Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%208_VirusTotal%20Enrichment_7.8.1.png)

Follow these steps to select a Group to associate to the imported Indicators:

1. Select a Group to which the selected Indicators, as well as the enriched Indicator, will be associated. To search for a Group, enter its name in the search bar above the table containing all Groups.
2. Click **Next** to proceed to the optional [**Associations**step](/docs/virustotal-enrichment#step-2-enter-details-about-associated-indicators-optional1).NoteThe **Save**button is available only on the **Associations**step.

#### Step 2: Enter Details About Associated Indicators (Optional)

The **Associations** step of the **Import to Existing Group** screen (Figure 9) is an optional step where you configure the Indicators from VirusTotal that are being created and [associated](https://knowledge.threatconnect.com/docs/associations) to the existing Group.

![Graphical user interface Description automatically generated](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%209_VirusTotal%20Enrichment_7.8.1.png)

Follow these steps to fill out the fields on the **Associations**step:

1. (Optional)****On the **Associations**card, review the table of Indicators that will be created and associated to the Group. This table includes all selected Indicators and the enriched Indicator. To remove an Indicator from the table, click **Delete![Trash icon_Black](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Trash%20icon_Black.png)**in the **Actions**column.NoteThe table on the **Associations**card will include a **Private**column if your System Administrator turned on private Indicators for your ThreatConnect instance. To mark an Indicator as [private](https://knowledge.threatconnect.com/docs/private-indicators), select the corresponding checkbox in the **Private** column.NoteA checkmark in the **Known**column indicates that the corresponding Indicator exists in the owner in which you are creating the Group and Indicators.
2. (Optional) On the **Association Details**card, provide the following details for *all*Indicators that will be created and associated to the Group:ImportantAll information added in this section will be applied to the enriched Indicator (that is, the Indicator whose **Enrichment** tab you are importing VirusTotal data from), because the enriched Indicator is always added as an association to the new Group, along with the Indicators selected on the card on the **VirusTotal Detailed View**drawer (Figure 4). If the enriched Indicator has a default Description, a Threat Rating, or a Confidence Rating and you enter a value for one of these fields, then that value will replace the existing value for the enriched Indicator. Tags entered in this section will be applied in addition to the enriched Indicator’s existing Tags.
  - **Description**: Enter a default [Description](https://knowledge.threatconnect.com/docs/the-description-attribute) for the Indicators.
  - **Tags**: Enter one or more [Tags](https://knowledge.threatconnect.com/v1/docs/applying-tags) to apply to the Indicators.
  - **Threat Rating**: Set the [Threat Rating](https://knowledge.threatconnect.com/v1/docs/setting-indicator-threat-and-confidence-ratings) for the Indicators.
  - **Confidence Rating**: Set the [Confidence Rating](https://knowledge.threatconnect.com/v1/docs/setting-indicator-threat-and-confidence-ratings) for the Indicators.
3. Click **Save**to create the Indicators and associate them to the existing Group.

After you complete the import process, the Group’s **Details**screen will open. You can view the Indicators that were imported and associated to the Group on the [**Indicator Associations**card](https://knowledge.threatconnect.com/docs/the-associations-tab#indicator-associations) of the Group’s [**Associations** tab](https://knowledge.threatconnect.com/docs/the-associations-tab).

### Importing Indicators as Indicators

Follow these steps to import Indicators from VirusTotal and associate them directly to the enriched Indicator via a custom association:

1. Follow Steps 1–3 in the [“Importing Indicators From VirusTotal Into ThreatConnect”](/docs/virustotal-enrichment#importing-indicators-from-virustotal-into-threatconnect) section and select **As an Indicator**from the **Import**dropdown.
2. On the **Import Indicators**window (Figure 10), review the list of Indicators that will be imported into ThreatConnect and associated directly to the enriched Indicator. To remove an Indicator from this list, click click **Delete![Delete button_Details screen](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Delete%20button_Details%20screen.png)**.

![](https://cdn.document360.io/dfc206c8-1c9f-4725-b74d-a66f83432320/Images/Documentation/Figure%2010_VirusTotal%20Enrichment_7.8.1.png)
3. Click **Import Indicators**to import the Indicators and associate them directly to the enriched Indicator via a custom association.

After you complete the import process, the [**Associations** tab](https://knowledge.threatconnect.com/docs/the-associations-tab) of the enriched Indicator’s **Details**screen will be displayed. You can view the associated Indicators on the [**Indicator Associations**card](https://knowledge.threatconnect.com/docs/the-associations-tab#indicator-associations) of this tab.

## Retrieving Data Manually

When you open an Indicator’s **Enrichment**tab for the first time, data will be retrieved from VirusTotal and displayed on the **VirusTotal**card automatically if your System Administrator enabled automatic data retrieval for VirusTotal. Otherwise, the **VirusTotal**card will display a message stating “Automatic Data Retrieval has been disabled by the System Administrator,” and you will need to click **Retrieve Data** on the card to populate it with data. Once data have been retrieved, they will be cached for a period of time configured by your System Administrator. Each time you revisit that Indicator’s **Enrichment**tab, the cached VirusTotal data will be displayed until this period of time has passed.

To retrieve the latest VirusTotal data for the Indicator manually, click **Retrieve Data** on the **VirusTotal**card.

NoteThe API key your System Administrator entered when configuring VirusTotal on the **System Settings**screen will be used each time data are retrieved from VirusTotal for an Indicator.

## Enriching Indicators Using the ThreatConnect API

You can use the ThreatConnect v3 API to enrich Address, File, Host, and URL Indicators with data from VirusTotal. For instructions on using the ThreatConnect v3 API to enrich Indicators, see [*Indicator Enrichment Overview*](https://threatconnect.readme.io/reference/indicator-enrichment-overview).

---

*ThreatConnect® is a registered trademark of ThreatConnect, Inc. VirusTotal™ is a trademark of Google, Inc.*

20146-03 v.05.C
