Threat Intelligence Service

Watch a demonstration of Oracle Threat Intelligence and Cloud Guard Threat Detector (4:21)

Oracle Threat Intelligence Service aggregates threat intelligence data across many different sources and manages this data to provide actionable guidance for threat detection and prevention in Oracle Cloud Guard and other Oracle Cloud Infrastructure services. Threat Intelligence Service manages disparate feeds and creates a single confidence score for each indicator to reduce false positives while providing transparency into the source to support incident investigation.

Using threat intelligence data purposefully and reliably can be a burden on already overworked security operations teams. It requires sourcing, validation, management, storage, and manual integration—which can be money and time intensive. Threat Intelligence Service is a fully integrated approach to gaining threat intelligence, at no additional cost.

Oracle Threat Intelligence Service features

Native integrations eliminate configuration complexity and redundancy

Threat intelligence data goes to work with Cloud Guard and Threat Detector.

Managed curation helps filter signal from noise

Aggregated threat intelligence data from open-source feeds, threat intelligence partners, and Oracle expertise, with prescriptive overall confidence assessments based on source, frequency, quality of sightings, and recency help analysts prioritize alerts and sort valid signals from noise.

Oracle security expertise built-in to make you safer

Access to Oracle security insights from Oracle security researchers and our own unique telemetry.

Access to Oracle’s threat intelligence database

Easily search for the most relevant threats in Oracle’s threat intelligence database.

Oracle Threat Intelligence Service provides:

  • Integrated threat intelligence

    Out-of-the-box integrations with Oracle Cloud Guard and Oracle Cloud Guard Threat Detector mean simple, integrated threat intelligence is used for both proactive defense and detection, reducing configuration complexity and redundancy.

  • Prescriptive confidence assessments

    Prescriptive overall confidence assessments based on source, frequency, quality of sightings, and recency help analysts prioritize alerts and sort valid signals from noise.

  • Trusted threat warnings

    Threat intelligence-backed detections for threat warnings provide transparency and helps customers trust the warnings they get from Oracle.

  • Unique threat intelligence

    Access to Oracle intelligence from observed telemetry and our threat research teams provides unique threat intelligence from our unique POV spanning SaaS/PaaS/IaaS.

Threat Intelligence Service resources

Oracle Cloud Free Tier

Build, test, and deploy applications on Oracle Cloud—for free. Sign up once—access two free offers.

Oracle Cloud Free Tier

Oracle Threat Intelligence Service

Get the latest information about Oracle Threat Intelligence Service.

See most frequently asked questions and answers about Oracle Threat Intelligence Service.

Documentation

Join a community of your peers

Cloud Customer Connect is Oracle's premier online cloud community. With more than 200,000 members, it promotes peer-to-peer collaboration on best practices, product updates, and feedback.

Community

Develop your cloud security skills

Oracle University provides you the training and certification to ensure your organization’s success—all delivered in your choice of formats.

Cloud Learning

Threat Intelligence Service related products

General questions

What is threat intelligence?

Threat intelligence is information about an adversary, including their tactics and motives. In the context of information security, threat intelligence commonly refers to indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs). In this framework, an IOC is typically forensic evidence that can be observed in telemetry, such as outbound traffic to a suspicious domain, the presence of malware on a host, or unusual activity in an administrative account. TTPs generally refer to tactics actors may use, such as brute force, supply chain compromise, or Secure Shell (SSH) hijacking.

MITRE ATT@CK is a common framework for understanding TTPs. Read more about MITRE ATT&CK.

What is threat intelligence data?

Threat intelligence data generally refers to static indicators that can be used in machine systems for detection and prevention use cases—for example, IP addresses and domains associated with unusual network traffic activity, suspicious geographic logins, and the presence of known malicious code.

There are many different sources of threat intelligence data, including open source feeds, vendor data, government-published threat intelligence, and private sector information sharing organizations such as IT-ISAC.

What does Oracle Threat Intelligence Service do?

Oracle Threat Intelligence Service provides access to threat intelligence including, but not limited to, indicators of compromise, threat reputation data, geolocation data, known bad actors, and confidence levels. Sources include first-party Oracle-sourced data, third-party data from our partners, open source threat feeds, and Oracle security research insights. The data evolves as new threats arise and is updated daily. Threat Intelligence Service is intended to support security incident investigation and provide contextual detail about identified threats.

The service supports out-of-the-box integrations with Oracle Cloud Guard and Oracle Cloud Guard Threat Detector and provides access to Threat Intelligence Service's searchable database of indicators of compromise.

How does Oracle Threat Intelligence Service improve my security?

Once you enable Oracle Cloud Guard and Oracle Cloud Guard Threat Detector in your tenancy, Threat Intelligence Service goes to work for you. Cloud Guard and Cloud Guard Threat Detector are fully integrated on the back end with Threat Intelligence Service. Cloud Guard will monitor your audit telemetry and generate a Problem if any suspicious IP activity is detected in API invocations based on high confidence suspicious IP addresses provided by Threat Intelligence Service.

Cloud Guard Threat Detector uses threat intelligence data in its machine learning and event correlation models to identify suspicious activity and adjust confidence scoring, providing more-reliable security alerts.

How much does Oracle Threat Intelligence Service cost?

Threat Intelligence Service is a free service in OCI. It is not available for Free Tier customers. Services that are integrated with Threat Intelligence Service may come at an additional cost.

What services are integrated with Oracle Threat Intelligence Service?

Cloud Guard and Cloud Guard Threat Detector are the first services integrated with Oracle Threat Intelligence Service.

Are there any restrictions on consumption for Oracle Threat Intelligence Service?

Direct search queries via the Console and API to the Threat Intelligence Service database are subject to rate limiting to protect performance and prevent abuse.

What sources are included with Oracle Threat Intelligence Service?

Threat Intelligence Service aggregates threat intelligence data from common open source feeds, technology partners such as CrowdStrike, and our own internal security expertise and observations.

Get started with Oracle Threat Intelligence Service