Activate and configure the VirusTotal integration

  • Versão de lançamento: Australia
  • Atualizado 12 de mar. de 2026
  • 1 min. de leitura
  • Before you can use the VirusTotal integration, you must download it from the ServiceNow Store.

    Antes de Iniciar

    Role required: admin

    Threat Intelligence must be installed and activated before you can use VirusTotal. The VirusTotal integration has been upgraded to version 3 APIs.

    Procedimento

    1. Download the integration from the ServiceNow Store.
    2. When the installation is complete, access VirusTotal and obtain the API Key under your VirusTotal profile.
    3. In your instance, navigate to Security Operations > Integration Configuration.
      The available security integrations appear as a series of cards.
    4. In the VirusTotal card, click Configure.
      Tabela 1. VirusTotal Configuration
      Field Description
      Name Name of the integration. For example, VirusTotal.
      API Key Enter (or paste) the API Key you acquired from the VirusTotal site.
      Enable VT Private Scanning Select this check box to analyze files with VirusTotal in a privacy preserving fashion. The files uploaded via this offering won't be shared with anyone beyond your organization, and will remain in VirusTotal only for a brief period of time.

      The resulting analyses will be ephemeral too and only visible to your VirusTotal group.

      Importante:
      To use the VT Private Scanning, your VirusTotal license should be entitled to this feature.
      Send URL as SHA-256 Hash Select this check box to send the URLs as hashes for threat lookup and protect the users' privacy on the integration.
      Nota:
      If disabled, the URL is sent as Base64 encoding to the VirusTotal API.
    5. Click Submit.
      VirusTotal Configuration page

    Resultado

    After it is configured, VirusTotal can be selected for performing lookups on observables in Threat Intelligence and on observables in security incidents.