---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure Threat Lookup

# Configure Threat Lookup {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Scan selected observables for malware using Threat Intelligence to determine if they are malicious. Use this lookup to assess security threats from IP addresses, URLs, file hashes, and other observable types.

## Before you begin

Role required: sn_sec_tisc.admin  
Note:  
The Enrichment Integrations module appears only if at least one integration supporting any capability is installed in the application.  
The Threat Intelligence Security Center supports Threat Lookup only for the following integrations:

* VirusTotal
* CrowdStrike Intelligence

{#configure-threat-lookup__ul_ybk_5h5_4zb}For more information, see [Threat Lookup](https://servicenow-prod.fluidtopics.net/_rITe~FbPtAFkY0_yCvhQw "Scan selected observables for malware using VirusTotal and CrowdStrike Falcon Intelligence. This workflow checks observables against both threat intelligence sources and returns detailed security analysis results.").

## About this task

The Threat Lookup section contains only the integrations with the integration type as threat lookup.

This section displays cards for each of the configured integration implementations that you can activate and use.

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security Center.
2. Select the Integrations icon, and select the Threat Lookup section.  
3. Select the Configure new enrichment action.  
   A pop-up displays the available integrations.
4. Select an integration from the list of available integrations, and select Select.  
   The Create Enrichment Integration page opens with pre-filled details for the selected integration.

5. On the Create Integration form, fill in the fields.

   | Field | Description |
   | Name | Enter a name for the new enrichment integration. For example, <kbd class="ph userinput">VirusTotal-1</kbd>. |
   | Vendor Name | Name of the vendor. This field is automatically set to the selected vendor. For example, <kbd class="ph userinput">VirusTotal</kbd>. |
   | Integration Type | Type of integration. This field is automatically set to Threat Lookup. |
   | Description | Enter a unique description for the new enrichment integration. |
   |-|-|

   {#configure-threat-lookup__choicetable_vcr_4zw_mzb}  
6. In the Integration Configuration section, configure the integration details based on your requirements.  
   The Integration Configuration section includes configuration details like API key, API Client ID or secret, username, and password. These configuration details vary for different apps.
7. Select the Save action to store and create the new enrichment integration configuration.  
   The system validates the provided details and sets the enrichment integration status to inactive by default.
8. Select Save as Draft action to only store the updates made to the enrichment configuration and not create it.  
   If you aren't sure about the configuration details, you can use the Save as Draft option. After you get the configuration details, you can fill the remaining information in the draft version and create it.
9. To enable the enrichment integration, select Enable.  
   The system enables the enrichment integration. You can also enable, disable, or delete a particular enrichment integration by using the Actions menu of the required integration tile on the Catalog page or the Enrichment Integrations page.
{#configure-threat-lookup__steps_dw4_5gz_1jc}
* **[View Threat Lookup Reputation Calculators](https://servicenow-prod.fluidtopics.net/cgC3~QNkee~YzrwAxVvUEA)**   
  You can view the Threat Lookup Finding Calculator to calculate the observable findings for your integration.

**Related tasks**   

* [View Threat Lookup Reputation Calculators](https://servicenow-prod.fluidtopics.net/cgC3~QNkee~YzrwAxVvUEA "You can view the Threat Lookup Finding Calculator to calculate the observable findings for your integration.")

*[\>]: and then


