Oracle Threatintel API

The threatintel API from Oracle — 5 operation(s) for threatintel.

Documentation

📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/access-governance-cp/20220518/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/adm/20220421/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/advisor/20200606/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/ai-data-platform/20240831/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/analytics/20190331/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/announcements/0.0.1/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/api-gateway/20190501/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/apm-config/20210201/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/apm-control-plane/20200630/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/apm-synthetic-monitoring/20200630/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/apm-trace-explorer/20200630/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/audit/20190901/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/autoscaling/20181001/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/bastion/20210331/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/batch/20251031/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/bigdata/20190531/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/blockchain/20191010/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/budgets/20190111/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/certificates/20210224/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/certificatesmgmt/20210224/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/cloud-guard/20200131/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/clusterplacementgroups/20230801/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/compute-cloud-at-customer/20221208/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/container-instances/20210415/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/container-registry/20180419/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/containerengine/20180222/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/cost-anomaly/20190111/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/dashboard/20210731/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/data-catalog/20190325/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/data-flow/20200129/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/data-integration/20200430/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/data-safe/20181201/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/data-science/20190101/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/database-management/20201101/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/database-migration/20230518/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/database-multicloud-integrations/20240501/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/database/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/database-tools/20201005/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/database-tools-runtime/20230222/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/datacc/20251101/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/datalabeling-dp/20211001/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/datalabeling/20211001/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/delegate-access-control/20230801/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/devops/20210630/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/digital-assistant/20190506/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/disaster-recovery/20220125/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/dms/20211101/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/dns/20180115/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/document-understanding/20221109/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/edsfu/20220528/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/emaildelivery/20170907/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/emaildeliverysubmission/20220926/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/events/20181201/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/filestorage/20171215/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/fleet-management/20250228/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/functions/20181201/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/functionsdocgenpbf/1.0/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/fusion-applications/20211201/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/generative-ai-agents-client/20240531/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/generative-ai-agents/20240531/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/generative-ai-inference/20231130/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/generative-ai-nl2sql/20260325/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/generative-ai/20231130/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/generic/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/globally-distributed-database/20250101/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/goldengate/20200407/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/healthchecks/20180501/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/iaas/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/identity-domains/v1/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/identity-dp/v1/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/identity/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/incidentmanagement/20181231/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/instanceagent/20180530/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/integration/20190131/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/iot/20250531/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/itas/v1/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/jms-java-download/20230601/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/jms/20210610/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/jms-utils/20250521/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/kafka/20240901/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/key/release/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/language/20221001/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/licensemanager/20220430/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/limits-increase/20251101/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/limits/20181025/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/loadbalancer/20170115/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/logan-api-spec/20200601/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/logging-dataplane/20200831/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/logging-management/20200531/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/logging-search/20190909/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/lustre/20250228/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/managed-access/20220126/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/management-agent/20200202/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/managementdashboard/20200901/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/marketplace/20181001/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/mngdmac/20250320/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/monitoring/20180401/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/multicloud-omhub-cp/20180828/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/mysql/20190415/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/NetMonitor/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/network-firewall/20211001/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/network-firewall/20230501/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/networkloadbalancer/20200501/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/nosql-database/20190828/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/notification/20181201/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/objectstorage/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/OCB/20220509/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/occ/20230515/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/occds/20240430/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/occm/20231107/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/ocicache/20220315/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/ocm/20220919/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/opa/20210621/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/opensearch/20180828/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/operations-insights/20200630/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/operatoraccesscontrol/20200630/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/oracle-api-access-control/20241130/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/organizations/20230401/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/organizations/20200801/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/osmh/20220901/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/postgresql/20220915/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/psasvc/20240301/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/publisher/20241201/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/queue/20210201/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/recovery-service/20210216/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/registry/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/resource-analytics/20241031/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/resource-discovery-monitoring-control-api/20210330/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/resource-scheduler/20240430/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/resourcemanager/20180917/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/rover/20201210/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/s3objectstorage/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/scanning/20210215/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/search/20180409/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/secretmgmt/20180608/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/secretretrieval/20190301/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/secure-desktops/20220618/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/security-attribute/20240815/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/self/20260129/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/service-catalog/20210527/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/serviceconnectors/20200909/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/smp/20210914/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/speech/20220101/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/stack-monitoring/20210330/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/streaming/20180418/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/threat-intel/20220901/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/usage/20200107/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/usage-proxy/20190111/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/vision/20220125/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/visual-builder/20210601/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/visual-builder-studio/20180828/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/vmware/20200501/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/vmware/20230701/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/waa/20211230/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/waas/20181116/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/waf/20210930/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/wlms/20241101/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/workrequests/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/zero-trust-packet-routing/20240301/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/zero-trust-packet-routing-tools/20240301/

Specifications

OpenAPI Specification

oracle-threatintel-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: Use the Threat Intelligence API to search for information about known threat indicators, including suspicious IP addresses, domain names, and other digital fingerprints. Threat Intelligence is a managed database of curated threat intelligence that comes from first party Oracle security insights, open source feeds, and vendor-procured data. For more information, see the [Threat Intelligence documentation](/iaas/Content/threat-intel/home.htm).
  title: Threat Intelligence Threatintel API
  version: '20220901'
  x-provenance:
    method: harvested
    first_party: true
    publisher: Oracle
    source: https://docs.oracle.com/en-us/iaas/api/specs/17d2201ee8fa40c5d12f2d532a9d279886d09cc2e7bcc6f6f8e8056519be9c01.yaml
    harvested: '2026-08-04'
    note: Published by Oracle as the contract for the Threat Intelligence API OCI service and stored verbatim; API Evangelist added only this provenance block.
  x-evidence:
  - url: https://docs.oracle.com/en-us/iaas/api/specs/index.json
    what: Oracle's own index of every OCI service specification
  - url: https://docs.oracle.com/en-us/iaas/api/specs/17d2201ee8fa40c5d12f2d532a9d279886d09cc2e7bcc6f6f8e8056519be9c01.yaml
    what: the harvested document for Threat Intelligence API
servers:
- url: http://127.0.0.1/20220901
- url: https://127.0.0.1/20220901
tags:
- name: threatintel
paths:
  /indicatorCounts:
    get:
      description: Get the current count of each threat indicator type. Indicator counts can be sorted in ascending or descending order.
      operationId: ListIndicatorCounts
      parameters:
      - $ref: '#/components/parameters/CompartmentIdQueryParam'
      - $ref: '#/components/parameters/RequestIdHeader'
      - $ref: '#/components/parameters/SortOrderQueryParam'
      responses:
        200:
          description: Successfully retrieved the number of indicators of each type.
          headers:
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact

                Oracle about a particular request, please provide the request ID.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IndicatorCountCollection'
        400:
          $ref: '#/components/responses/400'
        401:
          $ref: '#/components/responses/401'
        404:
          $ref: '#/components/responses/404'
        429:
          $ref: '#/components/responses/429'
        500:
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/default'
      summary: Get the current count of each threat indicator type. Indicator counts can be sorted in ascending or descending order.
      tags:
      - threatintel
      x-related-resource: '#/definitions/IndicatorCountCollection'
  /indicators:
    get:
      description: 'Get a list of threat indicator summaries based on the search criteria.

        '
      operationId: ListIndicators
      parameters:
      - $ref: '#/components/parameters/CompartmentIdQueryParam'
      - $ref: '#/components/parameters/ThreatTypeNameQueryParam'
      - $ref: '#/components/parameters/IndicatorTypeQueryParam'
      - $ref: '#/components/parameters/IndicatorValueQueryParam'
      - $ref: '#/components/parameters/ConfidenceGreaterThanOrEqualToQueryParam'
      - $ref: '#/components/parameters/TimeUpdatedGreaterThanOrEqualToQueryParam'
      - $ref: '#/components/parameters/TimeUpdatedLessThanQueryParam'
      - $ref: '#/components/parameters/TimeLastSeenGreaterThanOrEqualToQueryParam'
      - $ref: '#/components/parameters/TimeLastSeenLessThanQueryParam'
      - $ref: '#/components/parameters/TimeCreatedGreaterThanOrEqualToQueryParam'
      - $ref: '#/components/parameters/TimeCreatedLessThanQueryParam'
      - $ref: '#/components/parameters/PaginationLimitQueryParam'
      - $ref: '#/components/parameters/PaginationTokenQueryParam'
      - $ref: '#/components/parameters/SortOrderQueryParam'
      - $ref: '#/components/parameters/IndicatorSortByQueryParam'
      - $ref: '#/components/parameters/RequestIdHeader'
      responses:
        200:
          description: Successfully returns a page of IndicatorSummary objects.
          headers:
            opc-next-page:
              description: 'For pagination of a list of items. When paging through a list, if this header appears in the response,

                then a partial list might have been returned. Include this value as the `page` parameter for the

                subsequent GET request to get the next batch of items.

                '
              schema:
                type: string
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact

                Oracle about a particular request, please provide the request ID.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IndicatorSummaryCollection'
        400:
          $ref: '#/components/responses/400'
        401:
          $ref: '#/components/responses/401'
        404:
          $ref: '#/components/responses/404'
        429:
          $ref: '#/components/responses/429'
        500:
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/default'
      summary: Get a list of threat indicator summaries based on the search criteria.
      tags:
      - threatintel
  /indicators/actions/summarize:
    post:
      description: Get indicator summaries based on advanced search criteria.
      operationId: SummarizeIndicators
      parameters:
      - $ref: '#/components/parameters/CompartmentIdQueryParam'
      - $ref: '#/components/parameters/RequestIdHeader'
      - $ref: '#/components/parameters/PaginationLimitQueryParam'
      - $ref: '#/components/parameters/PaginationTokenQueryParam'
      responses:
        200:
          description: The indicator with the given id was successfully retrieved.
          headers:
            opc-next-page:
              description: 'For pagination of a list of items. When paging through a list, if this header appears in the response,

                then a partial list might have been returned. Include this value as the `page` parameter for the

                subsequent GET request to get the next batch of items.

                '
              schema:
                type: string
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact

                Oracle about a particular request, please provide the request ID.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IndicatorSummaryCollection'
        400:
          $ref: '#/components/responses/400'
        401:
          $ref: '#/components/responses/401'
        404:
          $ref: '#/components/responses/404'
        429:
          $ref: '#/components/responses/429'
        500:
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/default'
      summary: Get indicator summaries based on advanced search criteria.
      tags:
      - threatintel
      x-example: "POST /20220901/indicators/actions/summarize?compartmentId=<compartment_OCID>&limit=1 \nHost: api-threatintel.us-ashburn-1.oci.oraclecloud.com\n<authorization and other headers>\n{\n    \"indicatorType\": \"IP_ADDRESS\",\n    \"confidenceGreaterThanOrEqualTo\": 25,\n    \"threatActor\": \"solarspider\",\n    \"malware\": \"jsoutprox\"\n}\n"
      x-related-resource: '#/definitions/Indicator'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SummarizeIndicatorsDetails'
        description: Query Parameters to search for indicators.
        required: true
  /indicators/{indicatorId}:
    get:
      description: Get detailed information about a threat indicator with a given identifier.
      operationId: GetIndicator
      parameters:
      - $ref: '#/components/parameters/IndicatorIdentifierPathParam'
      - $ref: '#/components/parameters/CompartmentIdQueryParam'
      - $ref: '#/components/parameters/RequestIdHeader'
      responses:
        200:
          description: The indicator with the given id was successfully retrieved.
          headers:
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact

                Oracle about a particular request, please provide the request ID.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Indicator'
        400:
          $ref: '#/components/responses/400'
        401:
          $ref: '#/components/responses/401'
        404:
          $ref: '#/components/responses/404'
        429:
          $ref: '#/components/responses/429'
        500:
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/default'
      summary: Get detailed information about a threat indicator with a given identifier
      tags:
      - threatintel
  /threatTypes:
    get:
      description: 'Gets a list of threat types that are available to use as parameters when querying indicators.

        The list is sorted by threat type name according to the sort order query param.

        '
      operationId: ListThreatTypes
      parameters:
      - $ref: '#/components/parameters/CompartmentIdQueryParam'
      - $ref: '#/components/parameters/PaginationLimitQueryParam'
      - $ref: '#/components/parameters/PaginationTokenQueryParam'
      - $ref: '#/components/parameters/SortOrderQueryParam'
      - $ref: '#/components/parameters/RequestIdHeader'
      responses:
        200:
          description: Successfully retrieved a list of threat types.
          headers:
            opc-next-page:
              description: 'For pagination of a list of items. When paging through a list, if this header appears in the response,

                then a partial list might have been returned. Include this value as the `page` parameter for the

                subsequent GET request to get the next batch of items.

                '
              schema:
                type: string
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact

                Oracle about a particular request, please provide the request ID.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ThreatTypesCollection'
        400:
          $ref: '#/components/responses/400'
        401:
          $ref: '#/components/responses/401'
        404:
          $ref: '#/components/responses/404'
        429:
          $ref: '#/components/responses/429'
        500:
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/default'
      summary: List available threat types
      tags:
      - threatintel
      x-related-resource: '#/definitions/ThreatTypesCollection'
components:
  schemas:
    IndicatorCountCollection:
      description: A list of indicator counts by indicator type.
      properties:
        items:
          description: The list of aggregated indicator counts.
          items:
            $ref: '#/components/schemas/IndicatorCountSummary'
          type: array
      required:
      - items
      type: object
    ThreatType:
      description: A threat type along with attribution data that associates it to a threat indicator.
      properties:
        attribution:
          description: The list of supporting attribution information.
          items:
            $ref: '#/components/schemas/DataAttribution'
          type: array
        id:
          description: The OCID of the threat type.
          type: string
        name:
          description: The name of the threat type.
          type: string
      required:
      - id
      - name
      - attribution
      type: object
    IndicatorCountDimensions:
      description: The indicator dimension that was counted, such as the indicator type.
      properties:
        compartmentId:
          description: The compartment OCID that contains the indicator type.
          type: string
        type:
          description: The indicator type that was counted.
          enum:
          - DOMAIN_NAME
          - FILE_NAME
          - MD5_HASH
          - SHA1_HASH
          - SHA256_HASH
          - IP_ADDRESS
          - URL
          type: string
          x-obmcs-top-level-enum: '#/definitions/IndicatorType'
      type: object
    GeodataDetails:
      description: Geodata information for a given IP address
      properties:
        adminDiv:
          description: State/Province/subdivision within the country
          type: string
        city:
          description: City of origin
          type: string
        countryCode:
          description: Two-letter abbreviation for country of origin
          type: string
        geoId:
          description: Unique Identifier (optional)
          type: string
        label:
          description: Information on source providing the information
          type: string
        latitude:
          description: Latitude
          type: string
        longitude:
          description: Longitude
          type: string
        origin:
          description: ASN entry
          type: string
        routedPrefix:
          description: Encompassing assigned prefix for the IP
          type: string
      required:
      - origin
      - countryCode
      - adminDiv
      - city
      - latitude
      - longitude
      - label
      type: object
    Error:
      description: Error Information.
      properties:
        code:
          description: A short error code that defines the error, meant for programmatic parsing.
          type: string
        message:
          description: A human-readable error string.
          type: string
      required:
      - code
      - message
    IndicatorSourceSummary:
      description: Information about the source of threat indicator data.
      properties:
        name:
          description: The name of the source.
          type: string
      required:
      - name
      type: object
    ThreatTypeSummary:
      description: The name of a threat type and its ID.
      properties:
        id:
          description: The OCID of the threat type
          type: string
        name:
          description: The name of the threat type
          type: string
      required:
      - id
      - name
      type: object
    IndicatorCountSummary:
      description: A group of indicators with the same dimensions, such as the same indicator type.
      properties:
        count:
          description: The count of indicators in the group.
          type: integer
        dimensions:
          $ref: '#/components/schemas/IndicatorCountDimensions'
      required:
      - dimensions
      - count
      type: object
    SummarizeIndicatorsDetails:
      description: Query parameters to filter indicators
      properties:
        confidenceGreaterThanOrEqualTo:
          description: The minimum level of confidence to return
          maximum: 100
          minimum: 0
          type: integer
        indicatorSeenBy:
          description: Filter to include indicators that have been seen by the provided source.
          type: string
        indicatorType:
          description: The type of indicator this is
          enum:
          - DOMAIN_NAME
          - FILE_NAME
          - MD5_HASH
          - SHA1_HASH
          - SHA256_HASH
          - IP_ADDRESS
          - URL
          type: string
          x-obmcs-top-level-enum: '#/definitions/IndicatorType'
        indicatorValue:
          description: The value for the type of indicator this is
          type: string
        malware:
          description: Filter to include indicators associated with the provided malware.
          type: string
        sortBy:
          description: The field to sort by. Only one field to sort by may be provided
          enum:
          - CONFIDENCE
          - TIMECREATED
          - TIMEUPDATED
          - TIMELASTSEEN
          type: string
        sortOrder:
          description: The sort order to use, either 'ASC' or 'DESC'.
          enum:
          - ASC
          - DESC
          type: string
          x-obmcs-top-level-enum: '#/definitions/SortOrder'
        threatActor:
          description: Filter to included indicators associated with the provided threat actor.
          type: string
        threatTypes:
          description: The threat type of entites to be returned.
          items:
            type: string
          type: array
        timeCreatedGreaterThanOrEqualTo:
          description: The oldest creation time of entities to be returned.
          format: date-time
          type: string
        timeCreatedLessThan:
          description: The newest creation time of entities to be returned.
          format: date-time
          type: string
        timeLastSeenGreaterThanOrEqualTo:
          description: The oldest last seen time of entities to be returned.
          format: date-time
          type: string
        timeLastSeenLessThan:
          description: The newest last seen time of entities to be returned.
          format: date-time
          type: string
        timeUpdatedGreaterThanOrEqualTo:
          description: The oldest update time of entities to be returned.
          format: date-time
          type: string
        timeUpdatedLessThan:
          description: The newest update time of entities to be returned.
          format: date-time
          type: string
      type: object
      x-example: "{ \n  \"items\": [\n    {\n      \"attributes\": [\n        {\n          \"name\": \"MaliciousConfidence\",\n          \"value\": \"low\"\n        },\n        {\n          \"name\": \"CSD\",\n          \"value\": \"csa-220906\"\n        },\n        {\n          \"name\": \"ThreatActor\",\n          \"value\": \"solarspider\"\n        },\n        {\n          \"name\": \"Malware\",\n          \"value\": \"jsoutprox\"\n        }\n      ],\n\"compartmentId\": \"ocid1.compartment.oc1..uniqueID\",\n\"confidence\": 55,\n\"geodata\": {\n  \"adminDiv\": \"on\",\n  \"city\": \"toronto\",\n  \"countryCode\": \"ca\",\n  \"geoId\": \"\",\n  \"label\": \"globaltelehost corp.\",\n  \"latitude\": \"43.66\",\n  \"longitude\": \"-79.36\",\n  \"origin\": \"62563\",\n  \"routedPrefix\": \"\"\n},\n\"id\": \"ocid1.threatentity.oc1..uniqueID\",\n\"lifecycleState\": \"ACTIVE\",\n\"threatTypes\": [\n  \"Criminal\",\n  \"RAT\"\n],\n\"timeCreated\": \"2022-08-30T19:15:09.237Z\",\n\"timeLastSeen\": \"2022-08-30T19:07:13.000Z\",\n\"timeUpdated\": \"2022-09-06T07:11:23.503Z\",\n\"type\": \"IP_ADDRESS\",\n\"value\": \"192.168.10.10\"\n    }\n  ]\n} \n"
    DataVisibility:
      description: The visibility level of attribution data, including its [Traffic Light Protocol (TLP)](https://www.cisa.gov/tlp) color.
      properties:
        name:
          description: The name of the visibility level.
          type: string
        tlpName:
          description: The Traffic Light Protocol (TLP) color of the visibility level.
          enum:
          - TLP_INTERNAL_AUDIT
          - TLP_WHITE
          - TLP_GREEN
          - TLP_AMBER
          - TLP_RED
          type: string
      required:
      - name
      - tlpName
      type: object
    ThreatTypesCollection:
      description: List of threat types that can be associated with threat indicators.
      properties:
        items:
          description: The list of threat types that can be used to search for threat indicators.
          items:
            $ref: '#/components/schemas/ThreatTypeSummary'
          type: array
      required:
      - items
      type: object
    IndicatorAttributeSummary:
      description: An attribute name and list of values.
      properties:
        name:
          description: The name of the attribute.
          type: string
        value:
          description: The value of the attribute.
          type: string
      required:
      - name
      - value
    EntityReference:
      description: A reference to a resource or other entity.
      discriminator:
        propertyName: type
      properties:
        type:
          description: The type of the referenced entity.
          enum:
          - INDICATOR
          type: string
      required:
      - type
    IndicatorSummary:
      description: Summary of a data signature observed on a network or host that indicates a potential security threat.
      properties:
        attributes:
          description: 'A map of attributes with additional information about the indicator.

            Each attribute has a name (string), value (string), and attribution (supporting data).

            '
          items:
            $ref: '#/components/schemas/IndicatorAttributeSummary'
          type: array
        compartmentId:
          description: The OCID of the compartment that contains this indicator.
          type: string
        confidence:
          description: An integer from 0 to 100 that represents how certain we are that the indicator is malicious and a potential threat if it is detected communicating with your cloud resources. This confidence value is aggregated from the confidence in the threat types, attributes, and relationships to create an overall value for the indicator.
          maximum: 100
          minimum: 0
          type: integer
        geodata:
          $ref: '#/components/schemas/GeodataDetails'
        id:
          description: The OCID of the indicator.
          type: string
        lifecycleState:
          description: The state of the indicator. It will always be `ACTIVE`.
          enum:
          - ACTIVE
          - DELETED
          type: string
          x-obmcs-top-level-enum: '#/definitions/LifecycleState'
        threatTypes:
          description: Characteristics of the threat indicator based on previous observations or behavior. May include related tactics, techniques, and procedures.
          items:
            type: string
          type: array
        timeCreated:
          description: The date and time that the indicator was first detected. An RFC3339 formatted string.
          format: date-time
          type: string
        timeLastSeen:
          description: The date and time that this indicator was last seen. The value is the same as `timeCreated` for a new indicator. An RFC3339 formatted string.
          format: date-time
          type: string
        timeUpdated:
          description: The date and time that this indicator was last updated by the system.  Updates can include new reports or regular updates in confidence. The value is the same as `timeCreated` for a new indicator. An RFC3339 formatted string.
          format: date-time
          type: string
        type:
          description: The type of indicator.
          enum:
          - DOMAIN_NAME
          - FILE_NAME
          - MD5_HASH
          - SHA1_HASH
          - SHA256_HASH
          - IP_ADDRESS
          - URL
          type: string
          x-obmcs-top-level-enum: '#/definitions/IndicatorType'
        value:
          description: The indicator data value.
          type: string
      required:
      - id
      - type
      - value
      - threatTypes
      - attributes
      - geodata
      - timeCreated
      - timeUpdated
      - timeLastSeen
      type: object
    IndicatorAttribute:
      description: An attribute name and list of values with attribution.
      properties:
        attribution:
          description: The array of attribution data that support this attribute.
          items:
            $ref: '#/components/schemas/DataAttribution'
          type: array
        name:
          description: The name of the attribute.
          type: string
        value:
          description: The value of the attribute.
          type: string
      required:
      - name
      - value
      - attribution
    DataAttribution:
      description: The confidence, source information, and visibility for a particular sighting or observation of some data associated with a threat indicator. This associated data can be the indicator's threat type, attribute, or relationship.
      properties:
        confidence:
          description: An integer from 0 to 100 that provides a measure of our certainty in the maliciousness of data attributed to an indicator. For example, if the source of the data being attributed is the Tor Project, our confidence that the associated indicator is a tor exit node would be 100.
          maximum: 100
          minimum: 0
          type: integer
        source:
          $ref: '#/components/schemas/IndicatorSourceSummary'
        timeFirstSeen:
          description: The date and time the attribution data was first seen for this entity. If the data source does not provide this information, it is set to the last time it was seen. An RFC3339 formatted string.
          format: date-time
          type: string
        timeLastSeen:
          description: The last date and time the attribution data was seen for this entity. An RFC3339 formatted string.
          format: date-time
          type: string
        visibility:
          $ref: '#/components/schemas/DataVisibility'
      required:
      - confidence
      - source
      - visibility
      - timeLastSeen
      type: object
    Indicator:
      description: A data signature observed on a network or host that indicates a potential security threat. Indicators can be plain text or computed (hashed) values.
      properties:
        attributes:
          description: 'A map of attributes with additional information about the indicator.

            Each attribute has a name (string), value (string), and attribution (supporting data).

            '
          items:
            $ref: '#/components/schemas/IndicatorAttribute'
          type: array
        compartmentId:
          description: The OCID of the compartment that contains this indicator.
          type: string
        confidence:
          description: An integer from 0 to 100 that represents how certain we are that the indicator is malicious and a potential threat if it is detected communicating with your cloud resources. This confidence value is aggregated from the confidence in the threat types, attributes, and relationships to create an overall value for the indicator.
          maximum: 100
          minimum: 0
          type: integer
        geodata:
          $ref: '#/components/schemas/GeodataDetails'
        id:
          description: The OCID of the indicator.
          type: string
        lifecycleState:
          description: The state of the indicator. It will always be `ACTIVE`.
          enum:
          - ACTIVE
          - DELETED
          type: string
          x-obmcs-top-level-enum: '#/definitions/LifecycleState'
        relationships:
          description: 'A map of relationships between the indicator and other entities.

            Each relationship has a name (string), related entity, and attribution (supporting data).

            '
          items:
            $ref: '#/components/schemas/IndicatorRelationship'
          type: array
        threatTypes:
          description: Characteristics of the threat indicator based on previous observations or behavior. May include related tactics, techniques, and procedures.
          items:
            $ref: '#/components/schemas/ThreatType'
          type: array
        timeCreated:
          description: The date and time that the indicator was first detected. An RFC3339 formatted string.
          format: date-time
          type: string
        timeLastSeen:
          description: The date and time that this indicator was last seen. The value is the same as `timeCreated` for a new indicator. An RFC3339 formatted string.
          format: date-time
          type: string
        timeUpdated:
          description: The date and time that this indicator was last updated. The value is the same as `timeCreated` for a new indicator. An RFC3339 formatted string.
          format: date-time
          type: string
        type:
          description: The type of indicator.
          enum:
          - DOMAIN_NAME
          - FILE_NAME
          - MD5_HASH
          - SHA1_HASH
          - SHA256_HASH
          - IP_ADDRESS
          - URL
          type: string
          x-obmcs-top-level-enum: '#/definitions/IndicatorType'
        value:
          description: 'The value for this indicator.

            The value''s format is dependent upon its `type`. Examples:


            DOMAIN_NAME "evil.example.com"


            MD5_HASH "44d88612fea8a8f36de82e1278abb02f"


            IP_ADDRESS "2001:db8::1"

            '
          type: string
      required:
      - id
      - type
      - value
      - threatTypes
      - attributes
      - relationships
      - geodata
      - timeCreated
      - timeUpdated
      - timeLastSeen
      type: object
    IndicatorSummaryCollection:
      description: List of indicator summary objects.
      properties:
        items:
          description: The list of indicator summaries.
          items:
            $ref: '#/components/schemas/IndicatorSummary'
          type: array
      required:
      - items
      type: object
    IndicatorRelationship:
      description: A relationship name and list of releated entities.
      properties:
        attribution:
          description: The array of attribution data that support this relationship.
          items:
            $ref: '#/components/schemas/DataAttribution'
          type: array
        name:
          description: The name of the attribute.
          type: string
        relatedEntity:
          $ref: '#/components/schemas/EntityReference'
      required:
      - name
      - relatedEntity
      - attribution
  parameters:
    PaginationTokenQueryParam:
      description: A token representing the position at which to start retrieving results. This must come from the `opc-next-page` header field of a previous response.
      in: query
      name: page
      x-default-description: When absent, the response will be the first page of the result set.
      schema:
        type: string
        minLength: 1
    ConfidenceGreaterThanOrEqualToQueryParam:
      description: The minimum confidence score of entities to be returned.
      in: query
      name: confidenceGreaterThanOrEqualTo
      required: false
      x-default-description: When absent, the response will not be filtered by confidence.
      schema:
        type: integer
        default: 0
        maximum: 100
        minimum: 0
    TimeUpdatedLessThanQueryParam:
      description: Return indicators updated before the provided time.
      in: query
      name: timeUpdatedLessThan
      required: false
      x-default-description: When absent, the response will not be filtered by update time.
      schema:
        type: string
        format: date-time
    TimeUpdatedGreaterThanOrEqualToQueryParam:
      description: The oldest update time of entities to be returned.
      in: query
      name: timeUpdatedGreaterThanOrEqualTo
      required: false
      x-default-description: When absent, the response will not be filtered by update time.
      schema:
        type: string
        format: date-time
    TimeLastSeenLessThanQueryParam:
      description: Return indicators last seen before the provided time.
      in: query
      name: timeLastSeenLessThan
      required: false
      x-default-description: When absent, the response will not be filtered by last seen time.
      schema:
        type: string
        format: date-time
    TimeLastSeenGreaterThanOrEqualToQueryParam:
      description: The oldest last seen time of entities to be returned.
      in: query
      name: timeLastSeenGreaterThanOrEqualTo
      required: false
      x-default-description: When absent, the response will not be filtered by last seen time.
      schema:
        type: string
        format: date-time
    Compa

# --- truncated at 32 KB (36 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/oracle/refs/heads/main/openapi/oracle-threatintel-api-openapi.yml