---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure and enable VirusTotal Integration

# Configure and enable VirusTotal Integration {#ariaid-title1}

* Release version: Australia
* 
* Updated April 27, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Set up VirusTotal integration with Threat Intelligence Security Center to perform threat lookups on observables.

## Before you begin

Role required: sn_sec_tisc.admin  
Important:  
type="note"\>The Threat Intelligence Security Center and VirusTotal Threat Lookup plugins must be installed and active.

Download the VirusTotal integration from the ServiceNow Store. Verify you have a valid VirusTotal account before use. For more information see, [Download the integration from the ServiceNow Store](https://servicenow-prod.fluidtopics.net/qGeljAXHdNqRLZ7BfdM03w "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.").

This integration requires a valid VirusTotal API key and enables automated security analysis.

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security CenterIntegrationsEnrichment IntegrationsAll IntegrationsThreat Lookup.  
   Note:  
   After installation is complete, access VirusTotal. Obtain the API Key under your VirusTotal profile.
2. Select Configure New Enrichment to configure VirusTotal integration.
3. Complete the fields on the Configure New Enrichment form.  
   {#tisc-virustotal-integration__table_iqf_n4p_tzb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name for the new enrichment integration. For example, VirusTotal. |
   | Vendor Name | Name of the vendor. The details of the selected vendor is populated by default. For example, VirusTotal. |
   | Integration Type | Type of integration that you selected. For example, Threat Lookup. |
   | Description | Description for the new enrichment integration. |
   [Table 1. Enrichment Integration]

   {#tisc-virustotal-integration__table_iqf_n4p_tzb}
4. Navigate to Integration Configuration section.
5. In the API Key field, enter the API key you acquired from the VirusTotal site.
6. Select Save to apply the changes.  
   The system validates the integration details. By default, the VirusTotal integration status is inactive.
7. Select Enable to enable the VirusTotal integration.
{#tisc-virustotal-integration__steps_j42_fjp_bjc}

## Result

After configuration, you can select VirusTotal to perform lookups on observables in Threat Intelligence Security Center.

*[\>]: and then


