Before you can use the VirusTotal integration, you must download it from the ServiceNow Store.
始める前に
Role required: sn_sec_tisc.admin
The Threat Intelligence Security Center plugin is required in order to activate VirusTotal integration.
手順
-
Using your instance, access Threat Intelligence Security Center.
-
Download the integration from the ServiceNow Store.
-
When the installation is complete, access VirusTotal and obtain the API Key under your VirusTotal profile.
-
Navigate to .
-
Select .
-
Alternatively, you can navigate to
-
Click Configure New Enrichment to configure VirusTotal integration.
-
Fill in the fields on the Configure New Enrichment form.
表 : 1. Enrichment Integration
| Field |
Description |
| Name |
Enter a name for the new enrichment integration. For example, VirusTotal. |
| Vendor Name |
Name of the vendor. The details of the selected vendor is populated by default. For example, VirusTotal. |
| Integration Type |
Type of integration that you selected. For example, Threat Lookup. |
| Description |
Enter the description for the new enrichment integration. |
-
Drill down to Integration Configuration section.
-
Enter (or paste) the API Key you acquired from the VirusTotal site.
-
Click Save.
The integration details are validated, and by default the VirusTotal integration's status is disabled.
-
Click Enable to enable the VirusTotal integration.
タスクの結果
After it is configured, VirusTotal can be selected for performing lookups on observables in Threat Intelligence Security Center.