---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Activate and configure the VirusTotal integration

# Activate and configure the VirusTotal integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Before you can use the VirusTotal integration, you must download it from the ServiceNow Store.

## Before you begin

Role required: admin

Threat Intelligence must be installed and activated
before you can use VirusTotal. The VirusTotal integration has been
upgraded to version 3 APIs.

## Procedure

1. [Download the integration from the ServiceNow Store](https://servicenow-prod.fluidtopics.net/qGeljAXHdNqRLZ7BfdM03w "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.").
2. When the installation is complete, access VirusTotal and obtain the API Key under your VirusTotal profile.
3. In your instance, navigate to Security OperationsIntegration Configuration.  
   The available security integrations appear as a series of cards. {#activate-configure-virustotal__Nav-To}
{#activate-configure-virustotal__Nav-To}
4. In the VirusTotal card, click Configure.  
   {#activate-configure-virustotal__table_hbs_ccm_vzb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the integration. For example, VirusTotal. |
   | API Key | Enter (or paste) the API Key you acquired from the VirusTotal site. |
   | Enable VT Private Scanning | Select this check box to analyze files with VirusTotal in a privacy preserving fashion. The files uploaded via this offering won't be shared with anyone beyond your organization, and will remain in VirusTotal only for a brief period of time. The resulting analyses will be ephemeral too and only visible to your VirusTotal group. Important: To use the VT Private Scanning, your VirusTotal license should be entitled to this feature. |
   | Send URL as SHA-256 Hash | Select this check box to send the URLs as hashes for threat lookup and protect the users' privacy on the integration. Note: If disabled, the URL is sent as Base64 encoding to the VirusTotal API. |
   [Table 1. VirusTotal Configuration]

   {#activate-configure-virustotal__table_hbs_ccm_vzb}
5. Click Submit.  
{#activate-configure-virustotal__steps_gfz_1yn_vw}

## Result

After it is configured, VirusTotal can be selected for performing lookups on observables in Threat Intelligence and on observables in security incidents.
**Related tasks**   

* [Perform lookups on observables](https://servicenow-prod.fluidtopics.net/lpoUE~l5Cuui5Nt5XCnFsA "You can perform threat intelligence lookups on one or more observables to determine whether they’re associated with known security threats. The scanning implementations that run depend on the ones you’ve activated.")

*[\>]: and then


