VirusTotal integration with the security investigation tool provides deeper insight into Gmail events
What’s changing
Earlier this year, we announced an integration between VirusTotal and the Alert Center, giving admins the ability to look into security alerts at a deeper level. Beginning today, admins can also use the Security Investigation tool to view VirusTotal reports to gain richer information regarding Gmail event logs and use that information to make more informed decisions on protecting their users and data.
The Standard version of VirusTotal reports includes the following:
- File identification: Identifiers and characteristics allowing you to reference the threat and share it with other analysts (file hashes, file type, size, etc).
- Threat reputation: Maliciousness assessments coming from 70+ security vendors.
- Threat time spread: Key dates that enable you to understand when a given threat was first observed in-the-wild and how long it’s been active.
- Multi-angular detection: Additional threat analysis coming from crowdsourced rule matches and community scoring (for example: YARA, Sigma, and IDS rules).
- Allowlist information: Useful details to power false positive discarding (National Software Reference Library, Software Distributors, Microsoft Clean Metadata Feed, etc.).
- Related indicators of compromise (IOCs): Examples of IOCs include a network infrastructure distributing a malware file, servers acting as a command-and-control for a given threat, first-stage delivery vectors for a file being studied, etc.
- Interactive threat graph: Graphical format that maps out entire threat campaigns by visualizing the relationships between IOCs.
- Security-relevant metadata: Includes software publisher information, identification of malicious macros in documents, Android application permissions, etc.
- In-the-wild details: Geographical and time-spread details for threats, common attacker deception techniques, and more, through VirusTotal submission metadata.
- Suspicious attribute pivoting: Clickable details in VirusTotal reports, allowing you to explore the global VirusTotal dataset for other threats that share the same properties.
Who’s impacted
Why it matters
Additional details
Getting started
- Admins: VirusTotal reports are available to administrators who have access to the security investigation too. Visit the Help Center to learn more about using VirusTotal reports in the security investigation tool.
- End users: There is no end user impact.
Rollout pace
- Rapid Release and Scheduled Release domains: Gradual rollout (up to 15 days for feature visibility) starting on October 28, 2021
Availability
- Available to Google Workspace Enterprise Plus, Education Standard, and Education Plus customers
- Not available to Google Workspace Essentials, Business Starter, Business Standard, Business Plus, Enterprise Essentials, Enterprise Standard, Education Fundamentals, Frontline, and Nonprofits, as well as G Suite Basic and Business customers