Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

VirusTotal integration

The VirusTotal integration enables you to request the analysis of suspicious IP addresses, files, file hashes, and URL addresses to aid in your investigation to determine if they are malicious.

Explore Threat Intelligence integrationsSet up - VirusTotal integration setup - Activate and configure the VirusTotal integration
Use - Perform lookups on observables - Threat Lookup - VirusTotal workflowDevelop - ServiceNow Security Operations integration development guidelines - Tips for writing integrations - Developer training - Developer documentation - Find components installed with an application
Troubleshoot and get help - Integration troubleshooting - Ask or answer questions in the Security Operations community - Search the Known Error Portal for known error articles - Contact Customer Service and Support