Oracle Cloud Infrastructure (OCI)
Oracle Cloud, finally on the same radar as the rest.
Oracle Cloud is the second great blind spot. Teams running Autonomous Database, OCI compute, and Oracle workloads rarely have a cost-and-security tool that even speaks OCI, so the estate drifts unmonitored.
Nuvozy covers OCI broadly, Compute, Block/Object/File storage, ADB & DB Systems, VCN, IAM/policies, Vault/KMS, Cloud Guard, GoldenGate, Container Instances, Data Flow, Network Firewall, and VSS, with field names validated against the real Oracle SDK and a security-first detector mix.
Underserved
Almost no cost or CSPM platform covers OCI, so this is often a team's first real visibility into their Oracle estate.
Security-first
IAM policy posture, Vault/KMS, Cloud Guard, and Network Firewall gaps, all in one read-only pass.
SDK-validated
Detector field names validated against the real Oracle Python SDK, not just the docs.
What we scan on Oracle Cloud
A representative sample of the Oracle Cloud checks, grouped by service domain. Cost waste and security risk are surfaced in the same read-only pass. The complete, searchable list is further down this page.
Compute & storage
Compute, Block/Object/File storage, Container Instances.Idle & oversized compute
Instances running with little real utilization.
Orphaned block volumes & backups
Storage left behind by deleted resources.
Object & file storage hygiene
Exposure and lifecycle gaps across buckets and file systems.
Container Instances & Data Flow waste
Serverless and analytics resources nobody uses.
Database
Autonomous Database, DB Systems, GoldenGate.Autonomous Database idle/oversized
ADB scaled or licensed beyond actual use.
DB Systems utilization
Database nodes running well below capacity.
GoldenGate deployment hygiene
Replication deployments on outdated or unused configs.
Network
VCN, load balancers, Network Firewall.Idle load balancers
Balancers with no backends or traffic.
VCN & gateway plumbing
Network resources provisioned and abandoned.
Network Firewall posture
Perimeter rules and exposure gaps.
Security & identity
IAM/policies, Vault/KMS, Cloud Guard, VSS.IAM policy posture
Over-broad policies beyond least privilege.
Vault & KMS hygiene
Key management and rotation gaps.
Cloud Guard not enabled
Native detective controls left off.
Vulnerability Scanning (VSS) gaps
Workloads without scan coverage.
Every check we run on Oracle Cloud
All 183 checks, generated directly from the scanner so this list matches what actually runs. Search for a service to see whether your stack is covered.
No Oracle Cloud check matches that. It may be covered on another cloud, or it may be something we do not scan yet. Ask us about it .
- Commitment
GoldenGate deployment using license-included
A GoldenGate deployment uses the license-included model, which bundles the software licence into the hourly rate. Organizations that already own GoldenGate licences can switch to bring-your-own-licence (BYOL) and pay a lower infrastructure-only rate. Informational.
- Compute
Instance on a legacy shape
Compute instance running on a previous-generation shape (e.g. VM.Standard1/Standard2/E2) that has a cheaper, faster current successor (E4/E5/A1). Migrating modernizes performance and usually cuts cost.
- Compute
Underused dedicated VM host
Dedicated VM host with no or very few instances placed on it. You pay for the whole host regardless of placement, so an empty/near-empty host is wasted spend. Consolidate workloads or release it.
- Database
Autonomous Database auto-scaling disabled
Autonomous Database with compute auto-scaling turned off, so it cannot scale OCPUs to demand. Usually a missed cost-efficiency opportunity.
- Database
DB system license model review
Oracle DB systems using LICENSE_INCLUDED, which is worth reviewing against owned Oracle licenses (BYOL) for potential savings. Informational.
- Database
Prod DB system without HA
Production-looking Oracle DB systems running a single node with no RAC / Data Guard association. Informational resilience review.
- Database
Prod MySQL without HA
Production-looking MySQL HeatWave DB systems with is_highly_available disabled. Informational resilience review.
- Database
Underutilized Exadata infrastructure
A Cloud Exadata infrastructure is available but hosts few databases relative to its provisioned compute/storage. Exadata is billed on the rack regardless of utilization, so a sparsely used estate is costly. Informational.
- Governance
Alarm with no notification destination
An enabled Monitoring alarm has no destination configured, so when it fires no one is notified.
- Governance
Analytics instance oversized for non-production
An Analytics Cloud instance has a high capacity value (OCPU/OLPU) while its name/tags indicate a non-production instance. Analytics capacity bills continuously, so a large non-prod instance is usually over-provisioned. Informational.
- Governance
Attached volume without backups
Block volumes attached to an instance with no volume backup present. An attached, unprotected volume has no recovery point if data is lost.
- Governance
Audit log retention below baseline
The tenancy's audit-log retention is configured below 90 days, the common compliance baseline for investigating incidents.
- Governance
Autonomous Database on an old version
Autonomous Database whose major Oracle Database version is older than 19c, missing security patches and long-term support.
- Governance
Autonomous Database without a recent backup
An available Autonomous Database has no successful backup in the last 8 days. Automatic backups should run continuously; a stale newest backup means point-in-time recovery is degraded.
- Governance
Big Data Service cluster without Cloud SQL
A multi-node Big Data Service cluster has is_cloud_sql_configured false, so the Cloud SQL query layer is not provisioned. For a cluster of this size that is usually a configuration gap or an underused capability worth reviewing. Informational.
- Governance
Boot volume without backup policy
Boot volumes attached to an instance with no volume-backup policy assigned, leaving the OS/boot disk without an automated recovery point.
- Governance
Bucket storage tier mismatched to access pattern
A bucket's default storage tier looks misaligned with the access pattern implied by its name/tags - cold/archive data sitting in Standard, or hot/serving data in Archive (where every read pays a restore fee). Informational.
- Governance
Bucket without cross-region replication
A Standard or Infrequent-Access bucket has no replication policy, so its objects exist in a single region and would be lost in a regional outage. Business-critical buckets should replicate to a second region for DR.
- Governance
Budget without a forecast alert
A budget has alert rules but none of them is a forecast-based alert, so overspend is only flagged after it has already occurred rather than when it is projected.
- Governance
Budget without an alert rule
A budget exists but has no alert rule, so it tracks spend silently and never notifies anyone when a threshold is crossed.
- Governance
Compartment without enabled Events rules
A compartment has no enabled Events service rule, so resource-lifecycle and operational events trigger no automation or alerting.
- Governance
Compartment without enabled alarms
A compartment has no enabled Monitoring alarm, so there is no proactive alerting on metric thresholds for the resources it holds.
- Governance
Compartment without quotas
A compartment has no compartment quotas, so there is no guardrail capping the number or size of resources that can be provisioned in it.
- Governance
Compartment without tag defaults
A compartment has no tag defaults, so new resources are not automatically tagged for cost allocation, ownership, or environment tracking.
- Governance
Container instance without restart policy
A running Container Instance has its container restart policy set to NEVER, so if a container exits or crashes it is not restarted and the workload silently goes down. Informational.
- Governance
DB home on an old patch set
A database home runs an Oracle Database software version below the 19c long-term-support baseline, so the databases it hosts are missing patch set updates and security fixes. Informational.
- Governance
DB system likely over-provisioned on storage
An Oracle DB system provisions a large amount of data storage while its name/tags indicate a non-production system. Provisioned storage bills regardless of how much is used, so a large non-prod allocation is a likely oversized-storage candidate. Informational.
- Governance
DB system on old major version
Oracle DB systems below 19c or MySQL DB systems below 8.x, which are on old / out-of-support major versions and should be upgraded.
- Governance
DRG attachment not in an attached state
A dynamic routing gateway (DRG) attachment is not in the ATTACHED lifecycle state, so it provides no active connectivity. A stale attachment clutters the routing topology and can mask a broken interconnect. Informational.
- Governance
Disabled Events rule
An Events service rule exists but is disabled, so the automation or alerting it was created for is silently inactive.
- Governance
Disabled KMS keys
KMS keys in the DISABLED state. They cannot encrypt or decrypt but are still retained in the vault. Re-enable if needed or schedule deletion.
- Governance
Disabled monitoring alarm
A Monitoring alarm exists but is disabled, so it never evaluates its metric condition and never alerts.
- Governance
Empty DNS zone
A DNS zone holds only its mandatory SOA/NS infrastructure records and no content records, suggesting it is unused and can be removed.
- Governance
Empty Functions application
Functions applications that contain zero functions. Empty applications are usually leftovers from teardown and should be removed.
- Governance
Empty IAM group
An IAM group has zero members yet may still be referenced by policies. Empty groups clutter the access model and can mask intent: a policy granting the group access is effectively dead until someone is added.
- Governance
Empty log group
A log group contains no enabled logs. It collects nothing and only adds clutter to the logging configuration.
- Governance
Empty or stale compartment
A compartment older than 30 days has no compute instances or block volumes in any scanned region. It may be an abandoned shell worth cleaning up. Informational.
- Governance
Empty volume group
A volume group that contains no volumes. Empty groups are leftover scaffolding from removed workloads and should be deleted.
- Governance
Failed container instance
A Container Instance is in the FAILED lifecycle state. It is not running workloads but may still hold its reserved shape, and a failed instance usually signals a broken deployment that needs attention or cleanup.
- Governance
Failed or stale email sender
An Email Delivery approved sender is in a FAILED or NEEDS_ATTENTION state, so it cannot reliably send mail and should be fixed or removed.
- Governance
File systems without snapshots
File systems with no snapshots have no recovery points; an accidental deletion or corruption is unrecoverable.
- Governance
GoldenGate deployment needs attention
A GoldenGate deployment reports a lifecycle sub-state that indicates a degraded or needs-attention condition (for example RECOVERING or NEEDS_ATTENTION). Replication may be stalled or at risk, so the deployment should be investigated.
- Governance
GoldenGate deployment without auto-scaling
A GoldenGate deployment reserves multiple OCPUs but has auto-scaling disabled, so it pays for its peak core count around the clock instead of scaling down during quiet periods. Informational.
- Governance
IAM user with no group memberships
A local IAM user belongs to no groups, so it has no effective access granted through group policies. Such accounts are usually orphaned and should be deprovisioned to shrink the credential attack surface.
- Governance
Idle Integration / Analytics instance
An Oracle Integration Cloud or Analytics Cloud instance has been left in an INACTIVE/stopped state for an extended period. It may still incur charges and adds attack surface. Clean it up if abandoned. Informational.
- Governance
Idle NoSQL table
A NoSQL table is ACTIVE but has not been created or updated in a long time, suggesting it is abandoned. Provisioned tables reserve throughput, so an unused one is dead weight worth reviewing. Informational.
- Governance
Idle bastion with no recent sessions
A bastion is ACTIVE but has no recent sessions and was created a while ago, so it appears unused. An idle bastion is standing remote-access infrastructure that can be removed to shrink the attack surface. Informational.
- Governance
Idle queue
A Queue has not been updated for a long time and shows no sign of consumers draining it. Abandoned queues are cleanup candidates that clutter the inventory and can hide stale integrations. Cleanup.
- Governance
Idle streaming stream
A Streaming stream has partitions provisioned and has existed for a while but shows no sign of active use. Partitions reserve throughput capacity, so an unused stream is dead weight worth reviewing. Informational.
- Governance
Inactive GoldenGate deployment
A GoldenGate deployment has been stopped (INACTIVE) for a long time. A stopped deployment still reserves its provisioned capacity and clutters the inventory, so it is a cleanup candidate. Cleanup.
- Governance
Inactive container instance
A Container Instance has been stopped (INACTIVE) for a long time. Stopped instances clutter the inventory and can hide abandoned workloads, so they are cleanup candidates. Cleanup.
- Governance
Instance pool with size zero
An instance pool whose target size is 0 runs no instances. It is an idle definition that adds management overhead and is usually safe to delete.
- Governance
Instance with monitoring disabled
Compute instance whose Oracle Cloud Agent monitoring or management plugin is disabled, so it emits no metrics and cannot be patched/managed centrally. A governance and observability gap.
- Governance
Integration instance over-provisioned on message packs
An Oracle Integration Cloud instance provisions several message packs but looks idle or non-production by name/tags. Message packs set the billed throughput ceiling, so an idle instance with many packs is likely over-provisioned. Informational.
- Governance
KMS key has no cross-region replica
A primary KMS key has no replica configured in another region, so the key (and therefore any data encrypted under it) is not available for cross-region disaster recovery or failover.
- Governance
Large email suppression list
The tenancy's Email Delivery suppression list has grown large, indicating sustained bounces/complaints that hurt sender reputation and deliverability.
- Governance
Log retention below the audit floor
An enabled log retains entries for fewer days than a sensible audit floor (30 days), truncating the window available for incident investigation. Short retention can leave a breach undetectable by the time it is noticed.
- Governance
Low tag coverage
A high fraction of compute instances and block volumes carry no freeform tags, undermining cost allocation, ownership, and lifecycle tracking. One summary finding per tenancy.
- Governance
Many local IAM users (no federation)
A large number of local IAM users with no identity-provider federation. Centralizing identities in an IdP (SSO) reduces credential sprawl.
- Governance
MySQL DB system backup retention below safe floor
A MySQL HeatWave DB system has automatic backups enabled but a retention window shorter than a safe floor (7 days) for a production-looking system. A short window narrows the point-in-time recovery range available after an outage or data-corruption event.
- Governance
MySQL automatic backups disabled
MySQL HeatWave DB systems whose backup policy has automatic backups disabled, leaving no point-in-time recovery.
- Governance
No Service Connector Hub configured
The tenancy has no Service Connector Hub. Without a connector, logs and audit events are not aggregated to a central sink (Object Storage, Logging, Streaming, or a SIEM) for retention and monitoring. Informational.
- Governance
No active tag namespace
The tenancy has no active defined-tag namespace (none exist, or all are retired), so defined tags cannot be applied for governed cost allocation.
- Governance
No budget configured
The tenancy has no OCI budget configured, so there is no spend guardrail or automatic alerting when cost runs above plan.
- Governance
No notification topic configured
No ONS notification topic exists in any scanned compartment, so alarms and events have nowhere to deliver alerts.
- Governance
NoSQL table capacity mode mismatch
A NoSQL table runs in PROVISIONED capacity mode but is sized at the minimum read/write units, so it reserves throughput around the clock for what looks like a low or bursty workload. On-demand mode bills per request and usually fits better.
- Governance
NoSQL table without a default row TTL
A NoSQL table defines no default time-to-live on its rows, so records are never expired automatically and storage grows without bound. Set a table TTL where rows are time-bounded to cap storage cost.
- Governance
OKE cluster on old Kubernetes version
OKE clusters on a Kubernetes minor version older than the supported set. Old versions stop receiving security patches and block node upgrades.
- Governance
Object Storage object events disabled
Buckets with object_events_enabled false emit no events for object create/update/delete, leaving an audit and automation gap.
- Governance
Object Storage versioning disabled
Buckets with versioning Disabled cannot recover objects from accidental overwrite or deletion.
- Governance
Old KMS key without automatic rotation
A KMS key has automatic rotation disabled and was created more than a year ago, so its key material has likely never been rotated. Long-lived key material increases the blast radius of a key compromise.
- Governance
Old standalone database backup
A standalone database backup is older than 90 days and still ACTIVE. Long-retained manual backups accumulate storage cost and may breach data retention policy; review whether it is still needed.
- Governance
Only the Default identity domain exists
The tenancy has only the built-in Default identity domain. Separate domains let you isolate workloads, environments, or user populations with independent policies. Informational.
- Governance
Orphaned database backup
An ACTIVE standalone database backup references a source database OCID that no longer appears among the scanned DB systems, suggesting the database was deleted while the backup lingers and keeps billing. Informational.
- Governance
Orphaned instance configuration
An instance configuration (launch template) that no instance pool references. Orphaned configurations accumulate and obscure which templates are live.
- Governance
Production instances not spread across fault domains
Two or more running production instances within an availability domain share a single fault domain, so a hardware fault could take them all down at once. Informational.
- Governance
Queue with a very long retention window
A Queue is configured with a message retention window at or near the maximum. Messages that are never consumed are stored for the full window, so an unusually long retention inflates stored-message volume for little benefit. Informational.
- Governance
Queue without dead-letter handling
A Queue has its dead-letter delivery count set to 0 (or unset), so messages that repeatedly fail processing are dropped instead of being moved aside for inspection, which can mask data loss.
- Governance
Resource Manager stack drift or failed apply
A Resource Manager stack reports detected drift or its most recent apply job failed. Either way the deployed infrastructure no longer matches the Terraform state the stack manages.
- Governance
Stale Data Flow application
A Data Flow application has not been updated for a long time, suggesting it is an abandoned job definition cluttering the catalog. Cleanup.
- Governance
Stopped Autonomous Database
Autonomous Database in the STOPPED state for 14+ days. Compute billing pauses, but the database storage keeps billing. Terminate if abandoned.
- Governance
Stopped compute instances
Compute instances in the STOPPED state. Compute billing pauses, but the attached boot and block volumes keep billing. Release if abandoned.
- Governance
Unconfirmed notification subscription
A Notifications (ONS) subscription is stuck in the PENDING state because the endpoint owner never confirmed it. Messages published to the topic are silently not delivered to that subscriber, so alerts can go missing.
- Governance
Unused network firewall policy
A Network Firewall policy is not referenced by any firewall in the same region, so it is an orphaned configuration that clutters the inventory and can drift out of sync with the rules actually in force. Cleanup.
- Governance
Unused vaults
Vaults in the ACTIVE state that contain no usable keys and no active secrets. A provisioned vault bills regardless of contents. Clean up if abandoned.
- Network
Disabled internet gateways
Internet gateways present but disabled route nothing; they are usually leftover configuration (informational).
- Network
Idle load balancers with no listeners
Load balancers with zero listeners cannot accept any traffic yet keep billing per hour.
- Network
Load balancers with no backends
Load balancers whose backend sets have zero backends. The LB bills per hour while serving no traffic to any target.
- Network
Unattached reserved public IPs
Reserved public IPs assigned to no entity. A reserved public IP keeps billing whether or not it is attached to a resource.
- Network
Unused NAT gateways
NAT gateways whose VCN has no DRG or internet gateway and no private subnet egress usage (best-effort, informational).
- Network
Unused dynamic routing gateways
Dynamic routing gateways (DRGs) with no attachments route nothing and are likely leftover (informational).
- Security
API Gateway with public endpoint
API Gateways with a PUBLIC endpoint type. Public gateways are internet-reachable; confirm authentication, rate-limiting, and WAF are in place.
- Security
Admin policy not restricted to a network source
A tenancy-root policy grants 'manage all-resources in tenancy' without a 'where request.networkSource.name=...' condition, so administrative access is reachable from any network.
- Security
Analytics instance is publicly accessible
An Analytics Cloud instance uses a public network endpoint with no IP/VCN allow-list, so its dashboards and data are reachable from the internet instead of only a private endpoint.
- Security
Auth tokens present
Users holding long-lived auth tokens. These bearer credentials do not expire on their own and should be rotated and reviewed periodically.
- Security
Autonomous Database not requiring mTLS
Autonomous Database that accepts non-mTLS (TLS-only) connections. Mutual TLS adds client-certificate authentication and is the safer default.
- Security
Autonomous Database with no IP whitelist
Publicly reachable Autonomous Database whose access-control whitelist is empty, leaving the public endpoint open to every source IP.
- Security
Bastion allows long sessions
A bastion's maximum session TTL exceeds three hours. Long-lived sessions widen the window in which a forwarded port or SSH session can be abused.
- Security
Bastion open to the internet
A bastion's client CIDR allow-list includes 0.0.0.0/0, so a session may be created from any address on the internet rather than known networks.
- Security
Big Data Service cluster is publicly accessible
A Big Data Service cluster has nodes with public IP addresses (or does not require a NAT gateway), exposing Hadoop/Spark management and data ports to the internet.
- Security
Big Data Service cluster not secured
A Big Data Service cluster is active but does not have secure mode (Kerberos authentication) enabled, leaving Hadoop services without strong authentication between components and clients.
- Security
Bucket pre-authenticated request without expiry
A bucket pre-authenticated request (PAR) has no expiry time, or one set far in the future. A PAR is an unauthenticated signed URL, so a long-lived one is a standing credential that cannot be revoked short of deleting it.
- Security
Cloud Guard disabled
Cloud Guard is DISABLED for the tenancy, so OCI is not continuously evaluating resource and activity posture for risks.
- Security
Cloud Guard has no reporting region
Cloud Guard is enabled but no reporting region is configured, so aggregated problems and recommendations have no home region.
- Security
Cloud Guard has no root target
Cloud Guard is enabled but no active target covers the root compartment, so child compartments are not monitored by inheritance.
- Security
Cloud Guard self-managed resources enabled
Cloud Guard has self_manage_resources set to true, which means the Oracle-managed detector and responder recipes are not applied. Detection coverage then depends entirely on custom recipes the tenant maintains, which are easy to leave incomplete.
- Security
Console access on API-only user
Local users that have API/secret credentials and a Console password but no MFA. The Console password is likely unused and should be removed.
- Security
Customer secret keys present
Users holding customer secret keys (S3-compatible access keys for Object Storage). These static credentials should be reviewed and rotated.
- Security
DNS zone without a DMARC record
A public DNS zone that hosts content records has no _dmarc TXT record, so the domain publishes no DMARC policy. Without DMARC, receivers cannot tell the domain owner how to handle spoofed mail, weakening anti-phishing protection.
- Security
DNS zone without change protection
A public DNS zone has is_protected set to false, so it lacks the managed protection OCI offers against accidental or unauthorized record changes. Mail-bearing domains in particular should be protected so anti-spoofing records (SPF/DKIM/DMARC) cannot be silently altered.
- Security
Data Flow app on end-of-life Spark
A Data Flow application targets a Spark version that is past upstream end-of-life, so it no longer receives security patches and may carry known vulnerabilities in Spark and its bundled dependencies.
- Security
Data Safe assessment reports high risk
A Data Safe security assessment reports one or more high-risk findings, indicating database configuration weaknesses that need remediation.
- Security
Data Safe target without a security assessment
A database is registered as a Data Safe target but has no security assessment, so its configuration risk has never been evaluated.
- Security
Database not registered with Data Safe
A database (DB system or autonomous database) has no Data Safe target registration, so it has no user/privilege auditing, activity monitoring, or security assessment posture.
- Security
Dedicated Autonomous Database publicly accessible
Dedicated Autonomous Database (Exadata Dedicated Infrastructure) reachable over a public endpoint. Dedicated estates are expected to stay private.
- Security
Default security list is permissive
A VCN's default security list has ingress from 0.0.0.0/0. Resources land in the default list unless explicitly reassigned, so broad rules here silently expose new subnets.
- Security
Dynamic group has an overly broad matching rule
A dynamic group's matching rule matches a very wide set of principals (e.g. all instances in the tenancy), so any matched resource inherits whatever the group is granted.
- Security
Email sender without DKIM
An approved Email Delivery sender's domain has no active DKIM key, so its outbound mail is unsigned and far more likely to be spoofed or rejected.
- Security
Email sender without SPF
An approved Email Delivery sender has SPF disabled for its domain, weakening sender authentication alongside DKIM.
- Security
Expired auth token still attached to a user
An IAM user has an auth token whose time_expires is in the past but which is still attached to the account. Expired credentials should be deleted so they cannot be reactivated or cause confusion during credential audits.
- Security
Failed network firewall
A Network Firewall is in the FAILED lifecycle state, so it is not inspecting or filtering traffic on its subnet as intended, potentially leaving a routing path unprotected.
- Security
File system export open to the world
An NFS export with an export option granting READ_WRITE access to all source CIDRs (0.0.0.0/0) exposes the file system to any reachable host.
- Security
File system export without root squash
An NFS export option with identity_squash=NONE maps a remote root user to root on the file system, allowing privileged access to all files.
- Security
File systems without customer-managed keys
File systems with no kms_key_id are encrypted with Oracle-managed keys; a customer-managed KMS key gives control over rotation and revocation.
- Security
Functions application may be on a public subnet
A Functions application whose name/tags indicate an internal/worker role has no internet-facing need, yet nothing marks its subnet as private. Hosting internal functions on a public subnet widens exposure. Informational - confirm the subnet is private.
- Security
GoldenGate deployment not on latest version
A GoldenGate deployment is not running the latest available version (is_latest_version=false), so it may be missing security and stability fixes shipped in newer GoldenGate releases.
- Security
IAM network source allows the whole internet
An IAM network source includes 0.0.0.0/0 (or ::/0) in its public source list, so a policy condition bound to it imposes no real IP restriction.
- Security
IAM user without MFA
Local IAM users who can sign in to the Console but have not activated multi-factor authentication.
- Security
Identity domain visible on the login page
An identity domain has is_hidden_on_login set to false, so it is shown on the IdP discovery/login page. Exposing internal or administrative domains on the public login surface aids reconnaissance and credential-stuffing.
- Security
Instance allowing IMDS v1
Compute instance whose legacy instance-metadata-service (IMDS v1) endpoints are still enabled. v1 is unauthenticated and a known SSRF credential-exfiltration vector; v2 should be enforced.
- Security
Instance with a public IP
Compute instance whose VNIC has a public IP address, exposing it directly to the internet. Confirm the exposure is intended and gated.
- Security
Integration instance is publicly accessible
An Oracle Integration Cloud (OIC) instance exposes a public network endpoint, making its console and runtime reachable from the internet rather than only from a private VCN endpoint.
- Security
Internet-exposed GoldenGate deployment
A GoldenGate deployment has a public endpoint (is_public=true), so its replication control plane and console are reachable from the internet. Replication deployments handle production data and should sit on a private subnet behind controlled network access.
- Security
KMS key uses software protection
A KMS key is stored with SOFTWARE protection mode rather than in an HSM. Software-protected key material has lower assurance and is unsuitable for sensitive or production data that requires hardware-backed keys.
- Security
KMS keys pending deletion
KMS keys in the PENDING_DELETION state. Once the waiting period elapses the key material is destroyed and anything it encrypted becomes unrecoverable. Confirm the deletion is intended.
- Security
KMS keys without rotation
KMS master encryption keys in the ENABLED state that have no scheduled automatic rotation. Long-lived static keys widen the blast radius of a key compromise.
- Security
Logging not enabled for active compartment
A compartment runs compute instances but has no enabled service or custom logs, so activity on those assets is not being captured.
- Security
Low MFA enrollment coverage
The number of users with an active MFA TOTP device is well below the total user count, so most accounts can still authenticate with a password alone. Partial MFA coverage leaves the unenrolled accounts exposed to credential theft.
- Security
MFA not enforced tenancy-wide
No tenancy sign-on policy enforces multi-factor authentication: no users have an activated TOTP MFA device, so Console sign-in is single-factor across the tenancy.
- Security
Managed certificate already expired
A managed certificate's current version is past its not-after date. Any endpoint still serving it presents an expired certificate, breaking TLS.
- Security
Managed certificate expiring soon
A managed certificate's current version expires within 30 days. An expired certificate breaks TLS for every endpoint that serves it.
- Security
Multiple active API keys
Users with two or more active API signing keys. Extra keys are often abandoned rotation leftovers and expand the attack surface.
- Security
Network security group open to the internet
A network security group ingress rule allows a sensitive port (SSH, RDP, or a database engine) from 0.0.0.0/0, exposing it to the entire internet.
- Security
No IAM network sources defined
The tenancy has no IAM network sources. Without a named source, no policy can restrict console/API access to known IP ranges or VCNs, so credentials are usable from anywhere on the internet.
- Security
No identity federation (SSO)
The tenancy has no SAML identity provider configured, so all sign-ins rely on local IAM credentials instead of a central identity provider (SSO). Federation centralizes lifecycle and MFA control.
- Security
No network perimeter on authentication
The tenancy authentication policy defines no network sources, so Console and API sign-in is not restricted to trusted networks. Network sources let you confine sensitive access to known CIDRs.
- Security
No vulnerability scan targets
The Vulnerability Scanning Service has no host or container scan targets configured in any scanned region, so compute instances and container images are not being checked for known CVEs and open ports.
- Security
OKE cluster with public API endpoint
OKE clusters whose Kubernetes API server endpoint has a public IP. A public control-plane endpoint widens the attack surface; prefer private.
- Security
Object Storage bucket without a customer-managed key
Buckets with no kms_key_id use Oracle-managed encryption keys, leaving key rotation and revocation outside customer control.
- Security
Object Storage pre-authenticated request with broad access
Pre-authenticated requests with an AnyObject* access type or that target the whole bucket grant URL-only access to many objects, bypassing IAM.
- Security
Open critical Cloud Guard problems
Cloud Guard has open (ACTIVE) problems at CRITICAL or HIGH risk level that have not been resolved or dismissed.
- Security
Policy grants IAM administration to a non-admin group
An IAM policy statement grants 'manage' over an identity resource family (users, groups, policies, dynamic-groups) to a non-Administrators group, enabling privilege escalation.
- Security
Policy grants broad admin at the tenancy level
An IAM policy statement grants a broad 'manage' verb at the tenancy scope to a non-Administrators subject, widening the blast radius tenancy-wide.
- Security
Policy grants manage all-resources to a non-admin group
An IAM policy statement grants the 'manage all-resources' verb/resource to a group other than Administrators, conferring near-tenancy-admin power.
- Security
Policy grants to any-user / overly broad principal
An IAM policy statement grants permissions to the 'any-user' or 'any-group' principal, exposing the resources to every identity.
- Security
Public (standard) bastion
A bastion is of the STANDARD type, which exposes its endpoint on the public internet. Where a private/internal access path exists, a public bastion needlessly broadens the attack surface. Informational.
- Security
Public DNS zone without DNSSEC
A public (GLOBAL scope) primary DNS zone has DNSSEC unsigned, leaving its records open to spoofing and cache-poisoning attacks.
- Security
Public Object Storage buckets
Buckets with public_access_type ObjectRead or ObjectReadWithoutList let anyone read objects without authentication. A data-exposure risk.
- Security
Public container repository
OCIR container repositories marked public. Anyone can pull images without authentication, risking leaked software and embedded secrets.
- Security
Public load balancer looks like an internal tier
A load balancer is public (is_private false) while its name or tags indicate an internal or backend tier. Internal services exposed through a public load balancer widen the attack surface unnecessarily. Informational.
- Security
Public load balancer without WAF
A public (internet-facing) load balancer has no Web Application Firewall policy attached, so HTTP(S) traffic reaches its backends with no L7 filtering against common web attacks.
- Security
Public load balancer without a TLS listener
A public load balancer has listeners configured but none appear to terminate TLS (by listener name they look like plain HTTP or TCP), so it may be serving plaintext traffic to the internet. Informational - confirm the listener protocols.
- Security
Public subnet in a sensitive tier
A subnet allows public IP addresses on VNICs (prohibit_public_ip_on_vnic is false) while its name/tags indicate a sensitive tier such as a database or private/internal layer. Informational.
- Security
Publicly accessible Autonomous Database
Autonomous Database with a public endpoint. No private endpoint and no network security group or IP whitelist restricting access.
- Security
Publicly reachable DB systems
Oracle DB systems or MySQL HeatWave DB systems exposed through a public endpoint. Database listeners should sit on a private subnet.
- Security
Security list open to the internet
A security list ingress rule allows a sensitive port (SSH, RDP, or a database engine) from 0.0.0.0/0, exposing it to the entire internet.
- Security
Security list opens all ports to the internet
A security list ingress rule from 0.0.0.0/0 covers all protocols or the full TCP/UDP port range, exposing every service on attached subnets.
- Security
Stale API signing key
User API signing keys older than 90 days. Long-lived keys widen the window for a leaked credential to be abused.
- Security
User in Administrators group
Local IAM users placed directly in the built-in Administrators group, which grants tenancy-wide privileges.
- Security
VCN subnet without flow logs
A subnet has no VCN flow log enabled, so there is no record of accepted or rejected traffic for incident investigation or anomaly detection.
- Security
Vault secrets without rotation
Vault secrets in the ACTIVE state that have no automatic rotation policy. Static, unrotated secrets stay valid indefinitely if leaked.
- Security
Volume not using customer-managed keys
Block or boot volumes encrypted with the Oracle-managed key (no kms_key_id). Where customer-managed keys are policy, assign a Vault key.
- Security
WAF policy in detection-only mode
A Web Application Firewall policy declares only ALLOW/CHECK actions and no blocking (RETURN_HTTP_RESPONSE) action, so it logs matching requests but never blocks them.
- Security
WAF policy not attached to any firewall
A Web Application Firewall policy exists but is referenced by no WAF firewall, so it protects nothing. Usually leftover configuration.
- Security
Weak password policy
The tenancy authentication password policy is below CIS minimums: the minimum length is under 14 characters or character-class complexity (lowercase, uppercase, numeric, special) is not enforced.
- Storage
Idle file systems (no exports)
File systems with no exports and no mount targets are unreachable by any NFS client, yet their metered storage keeps billing.
- Storage
Object Storage bucket without a lifecycle policy
Buckets with no object lifecycle policy never auto-delete or tier old objects, so stale data accumulates and bills indefinitely.
- Storage
Old manual volume backups
Manually created volume backups older than 180 days. Unlike policy backups they are never pruned and accumulate storage cost indefinitely.
- Storage
Old unused custom images
Custom (non Oracle-provided) compute images older than 180 days that no instance launched from. Each image's backing storage bills monthly.
- Storage
Orphaned boot volumes
Boot volumes in the AVAILABLE state attached to no instance for 7+ days. A detached boot volume bills full price for data nothing boots.
- Storage
Orphaned volume backups
Volume backups older than 30 days whose source volume no longer exists in the scan. Often abandoned recovery points that keep billing.
- Storage
Stream with long retention in non-prod
A Streaming stream in a compartment/stream that looks non-production retains messages for the maximum window. Long retention rarely matters outside production and grows the stored data footprint. Informational.
- Storage
Unattached block volumes
Block volumes in the AVAILABLE state attached to no instance for 7+ days. They bill full price whether or not anything uses them.
Checks marked opt-in use a paid or billing-data cloud API and never run unless you switch them on. A default scan uses only free APIs.
How you connect
An API signing key
Add a read-only user to a group with a read-only policy and upload the API signing key in the dashboard.
How the dollars are calculated
Curated baseline pricing (live OCI pricing is on the roadmap); every finding labels its pricing source.
Every finding is backed by the raw cloud API response it came from, with a confidence score and the pricing source labelled, no black-box numbers.
Scan your Oracle Cloud estate free
Connect an api signing key and run a read-only scan. Findings come priced in real dollars with a fix and the evidence for each.
Start scanning free