Configure Threat Intelligence (Virus Total API) permissions.
Controls access to the configuration page for external threat intelligence API keys (Virus Total) on → → → . This configuration enables the enrichment of indicators within the tenant using Virus Total.
Permission | Description | Role Example |
|---|---|---|
None | The user cannot access or view the Threat Intelligence configuration page. | SOC Tier-1 Analyst: Uses TI data but doesn't configure. |
View | Users can see if a VirusTotal API key is configured but cannot add, edit, or test the key. | SOC Tier-2 and 3 Analysts: May need to review TI configurations. |
View/Edit | Full access to add, edit, test, and save VirusTotal API key configurations. |
|