Configure and Enable VirusTotal Integration

  • リリースバージョン: Australia
  • 更新日 2026年03月12日
  • 所要時間:2分
  • Before you can use the VirusTotal integration, you must download it from the ServiceNow Store.

    始める前に

    Role required: sn_sec_tisc.admin

    The Threat Intelligence Security Center plugin is required in order to activate VirusTotal integration.

    手順

    1. Using your instance, access Threat Intelligence Security Center.
    2. Download the integration from the ServiceNow Store.
    3. When the installation is complete, access VirusTotal and obtain the API Key under your VirusTotal profile.
    4. Navigate to Workspaces > Threat Intelligence Security Center.
    5. Select Integrations > Enrichment Integrations > All Integrations.
    6. Alternatively, you can navigate to Integrations > Enrichment Integrations > All Integrations > Threat Lookup
    7. Click Configure New Enrichment to configure VirusTotal integration.
    8. Fill in the fields on the Configure New Enrichment form.
      表 : 1. Enrichment Integration
      Field Description
      Name Enter a name for the new enrichment integration. For example, VirusTotal.
      Vendor Name Name of the vendor. The details of the selected vendor is populated by default. For example, VirusTotal.
      Integration Type Type of integration that you selected. For example, Threat Lookup.
      Description Enter the description for the new enrichment integration.
    9. Drill down to Integration Configuration section.
    10. Enter (or paste) the API Key you acquired from the VirusTotal site.
    11. Click Save.
      The integration details are validated, and by default the VirusTotal integration's status is disabled.
    12. Click Enable to enable the VirusTotal integration.

    タスクの結果

    After it is configured, VirusTotal can be selected for performing lookups on observables in Threat Intelligence Security Center.