---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Hybrid Analysis integration

# Hybrid Analysis integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Hybrid Analysis application is
part of an open online community in which users analyze files and URLs for threats. You share
results and utilize research from the community for more effective incident responses. When
integrated with the ServiceNow AI Platform
Security Operations product, the shared
threat intelligence provides you with additional insight into the severity of specific
observables.  
The Hybrid Analysis integration performs threat lookups on the following observables:

* File hashes
* IP addresses
* URLs
{#hybrid-analysis-lookups__ul_rqq_f4w_qcb}

The flow checks for new observables as they arrive in security incidents. If the observables are of a type recognized by the API integration, the observables are evaluated. Observables determined to be malicious are tagged.
1. [Install and configure Hybrid Analysis](https://servicenow-prod.fluidtopics.net/dQk6AVw_fCumqU1Fz8_02Q)  
   Before you run the integration on your instance, complete the installation and configuration steps so the Hybrid Analysis application properly integrates with ServiceNow AI Platform Security Operations.
2. [Verify expected results for Hybrid Analysis](https://servicenow-prod.fluidtopics.net/09ribGQo2QCjVFHOWeBZRw)  
   Observables are generated automatically by a security incident and scanned by the application. Locate the lookup results on the security incident to verify the threat lookup has run successfully. Also view raw data and run threat lookups on child observables.
3. [(Optional) Manually attach an observable for Hybrid Analysis](https://servicenow-prod.fluidtopics.net/xSEAUPxIhiQ6Ny2yuVGTEg)  
   You can manually attach observables when you want to perform threat lookups on observables that are not attached to a security incident on the initial event trigger. Also, you might perform this task when you want more information about a related observable.

