Configure and enable VirusTotal Integration
Set up VirusTotal integration with Threat Intelligence Security Center to perform threat lookups on observables.
Before you begin
Role required: sn_sec_tisc.admin
Important: type="note">The Threat Intelligence Security Center and VirusTotal Threat Lookup plugins must be installed and active.
Download the VirusTotal integration from the ServiceNow Store. Verify you have a valid VirusTotal account before use. For more information see, Download the integration from the ServiceNow Store.
This integration requires a valid VirusTotal API key and enables automated security analysis.
Procedure
Navigate to Workspaces > Threat Intelligence Security Center > Integrations > Enrichment Integrations > All Integrations > Threat Lookup.
Note: After installation is complete, access VirusTotal. Obtain the API Key under your VirusTotal profile.
Select Configure New Enrichment to configure VirusTotal integration.
Complete the fields on the Configure New Enrichment form.
Field Description Name Name for the new enrichment integration. For example, VirusTotal. Vendor Name Name of the vendor. The details of the selected vendor is populated by default. For example, VirusTotal. Integration Type Type of integration that you selected. For example, Threat Lookup. Description Description for the new enrichment integration. Navigate to Integration Configuration section.
In the API Key field, enter the API key you acquired from the VirusTotal site.
Select Save to apply the changes.
The system validates the integration details. By default, the VirusTotal integration status is inactive.
Select Enable to enable the VirusTotal integration.
Result
After configuration, you can select VirusTotal to perform lookups on observables in Threat Intelligence Security Center.
Parent Topic:TISC VirusTotal integration