
Threat Intelligence Service
Oracle Threat Intelligence Service aggregates threat intelligence data across many different sources and manages this data to provide actionable guidance for threat detection and prevention in Oracle Cloud Guard and other Oracle Cloud Infrastructure services. Threat Intelligence Service manages disparate feeds and creates a single confidence score for each indicator to reduce false positives while providing transparency into the source to support incident investigation.
Using threat intelligence data purposefully and reliably can be a burden on already overworked security operations teams. It requires sourcing, validation, management, storage, and manual integration—which can be money and time intensive. Threat Intelligence Service is a fully integrated approach to gaining threat intelligence, at no additional cost.
Oracle Threat Intelligence Service features
Native integrations eliminate configuration complexity and redundancy
Threat intelligence data goes to work with Cloud Guard and Threat Detector.
Managed curation helps filter signal from noise
Aggregated threat intelligence data from open-source feeds, threat intelligence partners, and Oracle expertise, with prescriptive overall confidence assessments based on source, frequency, quality of sightings, and recency help analysts prioritize alerts and sort valid signals from noise.
Oracle security expertise built-in to make you safer
Access to Oracle security insights from Oracle security researchers and our own unique telemetry.
Access to Oracle’s threat intelligence database
Easily search for the most relevant threats in Oracle’s threat intelligence database.
Oracle Threat Intelligence Service provides:
-
Integrated threat intelligence
Out-of-the-box integrations with Oracle Cloud Guard and Oracle Cloud Guard Threat Detector mean simple, integrated threat intelligence is used for both proactive defense and detection, reducing configuration complexity and redundancy.
-
Prescriptive confidence assessments
Prescriptive overall confidence assessments based on source, frequency, quality of sightings, and recency help analysts prioritize alerts and sort valid signals from noise.
-
Trusted threat warnings
Threat intelligence-backed detections for threat warnings provide transparency and helps customers trust the warnings they get from Oracle.
-
Unique threat intelligence
Access to Oracle intelligence from observed telemetry and our threat research teams provides unique threat intelligence from our unique POV spanning SaaS/PaaS/IaaS.
Threat Intelligence Service resources
Oracle Cloud Free Tier
Build, test, and deploy applications on Oracle Cloud—for free. Sign up once—access two free offers.
Oracle Threat Intelligence Service
Get the latest information about Oracle Threat Intelligence Service.
See most frequently asked questions and answers about Oracle Threat Intelligence Service.
Join a community of your peers
Cloud Customer Connect is Oracle's premier online cloud community. With more than 200,000 members, it promotes peer-to-peer collaboration on best practices, product updates, and feedback.
Develop your cloud security skills
Oracle University provides you the training and certification to ensure your organization’s success—all delivered in your choice of formats.
Threat Intelligence Service related products
-
Oracle Cloud Guard
Oracle Cloud Guard helps organizations gain a better view of their cloud risk posture
-
Threat Detector
Learn more about the newly launched threat detection service
-
Compliance
Learn how Oracle Cloud Infrastructure is addressing global compliance concerns
-
OCI regions
See Oracle Cloud Infrastructure data center regions
General questions
What is threat intelligence?
Threat intelligence is information about an adversary, including their tactics and motives. In the context of information security, threat intelligence commonly refers to indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs). In this framework, an IOC is typically forensic evidence that can be observed in telemetry, such as outbound traffic to a suspicious domain, the presence of malware on a host, or unusual activity in an administrative account. TTPs generally refer to tactics actors may use, such as brute force, supply chain compromise, or Secure Shell (SSH) hijacking.
MITRE ATT@CK is a common framework for understanding TTPs. Read more about MITRE ATT&CK.
What is threat intelligence data?
Threat intelligence data generally refers to static indicators that can be used in machine systems for detection and prevention use cases—for example, IP addresses and domains associated with unusual network traffic activity, suspicious geographic logins, and the presence of known malicious code.
There are many different sources of threat intelligence data, including open source feeds, vendor data, government-published threat intelligence, and private sector information sharing organizations such as IT-ISAC.
What does Oracle Threat Intelligence Service do?
Oracle Threat Intelligence Service provides access to threat intelligence including, but not limited to, indicators of compromise, threat reputation data, geolocation data, known bad actors, and confidence levels. Sources include first-party Oracle-sourced data, third-party data from our partners, open source threat feeds, and Oracle security research insights. The data evolves as new threats arise and is updated daily. Threat Intelligence Service is intended to support security incident investigation and provide contextual detail about identified threats.
The service supports out-of-the-box integrations with Oracle Cloud Guard and Oracle Cloud Guard Threat Detector and provides access to Threat Intelligence Service's searchable database of indicators of compromise.
How does Oracle Threat Intelligence Service improve my security?
Once you enable Oracle Cloud Guard and Oracle Cloud Guard Threat Detector in your tenancy, Threat Intelligence Service goes to work for you. Cloud Guard and Cloud Guard Threat Detector are fully integrated on the back end with Threat Intelligence Service. Cloud Guard will monitor your audit telemetry and generate a Problem if any suspicious IP activity is detected in API invocations based on high confidence suspicious IP addresses provided by Threat Intelligence Service.
Cloud Guard Threat Detector uses threat intelligence data in its machine learning and event correlation models to identify suspicious activity and adjust confidence scoring, providing more-reliable security alerts.
How much does Oracle Threat Intelligence Service cost?
Threat Intelligence Service is a free service in OCI. It is not available for Free Tier customers. Services that are integrated with Threat Intelligence Service may come at an additional cost.
What services are integrated with Oracle Threat Intelligence Service?
Cloud Guard and Cloud Guard Threat Detector are the first services integrated with Oracle Threat Intelligence Service.
Are there any restrictions on consumption for Oracle Threat Intelligence Service?
Direct search queries via the Console and API to the Threat Intelligence Service database are subject to rate limiting to protect performance and prevent abuse.
What sources are included with Oracle Threat Intelligence Service?
Threat Intelligence Service aggregates threat intelligence data from common open source feeds, technology partners such as CrowdStrike, and our own internal security expertise and observations.