Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Activate and configure the VirusTotal integration

Before you can use the VirusTotal integration, you must download it from the ServiceNow Store.

Before you begin

Role required: admin

Threat Intelligence must be installed and activated before you can use VirusTotal. The VirusTotal integration has been upgraded to version 3 APIs.

Procedure

  1. Download the integration from the ServiceNow Store.

  2. When the installation is complete, access VirusTotal and obtain the API Key under your VirusTotal profile.

  3. In your instance, navigate to Security Operations > Integration Configuration.

    The available security integrations appear as a series of cards.

  4. In the VirusTotal card, click Configure.

FieldDescription
NameName of the integration. For example, VirusTotal.
API KeyEnter (or paste) the API Key you acquired from the VirusTotal site.
Enable VT Private Scanning

Select this check box to analyze files with VirusTotal in a privacy preserving fashion. The files uploaded via this offering won't be shared with anyone beyond your organization, and will remain in VirusTotal only for a brief period of time.The resulting analyses will be ephemeral too and only visible to your VirusTotal group.

Important: To use the VT Private Scanning, your VirusTotal license should be entitled to this feature.

Send URL as SHA-256 HashSelect this check box to send the URLs as hashes for threat lookup and protect the users' privacy on the integration.Note: If disabled, the URL is sent as Base64 encoding to the VirusTotal API.
  1. Click Submit.
Image omitted: virus-total-config.png
VirusTotal Configuration page

Result

After it is configured, VirusTotal can be selected for performing lookups on observables in Threat Intelligence and on observables in security incidents.

Related topics

Perform lookups on observables