Skip to main content
Connect Google Threat Intelligence (formerly VirusTotal) so Myrmex can look up indicators of compromise — files, hashes, URLs, domains, and IPs — against 70+ antivirus engines and blocklists. Myrmex queries the API in real time through a Collector.
Myrmex looks up indicators on demand and reads results in real time — nothing is stored on the Myrmex side.

What Myrmex Can Do

IOC lookups

Check files, URLs, domains, and IPs on demand in Threat Intelligence.

Multi-engine verdicts

See detections across 70+ AV scanners and URL/domain blocklists.

Enrich investigations

Let Orion use Google Threat Intelligence to enrich indicators during recon.

Reputation context

Add reputation and relationship context to your alerts and cases.

Before You Start

  • A VirusTotal / Google Threat Intelligence account. Enterprise features require a subscription; the community key is rate-limited.
  • A Collector that can reach virustotal.com over outbound HTTPS.

Step 1 — Create the Credential in Google Threat Intelligence

1

Sign in

Sign in to your VirusTotal / Google Threat Intelligence account.
2

Open your API key

From your profile menu, open the API key page.
3

Copy the key

Copy the API key — it’s sent in the x-apikey header. Paste it into Myrmex.

Step 2 — Add the Integration in Myrmex

From the Directory, choose Add Integration → Google Threat Intelligence, then fill in:

Connect

Click Connect to validate the API key. The integration then appears under Environment → Integrations, and you can look up indicators — live — in Threat Intelligence.