Oracle Cloud Infrastructure (OCI)

Oracle Cloud, finally on the same radar as the rest.

Oracle Cloud is the second great blind spot. Teams running Autonomous Database, OCI compute, and Oracle workloads rarely have a cost-and-security tool that even speaks OCI, so the estate drifts unmonitored.

Nuvozy covers OCI broadly, Compute, Block/Object/File storage, ADB & DB Systems, VCN, IAM/policies, Vault/KMS, Cloud Guard, GoldenGate, Container Instances, Data Flow, Network Firewall, and VSS, with field names validated against the real Oracle SDK and a security-first detector mix.

Underserved

Almost no cost or CSPM platform covers OCI, so this is often a team's first real visibility into their Oracle estate.

Security-first

IAM policy posture, Vault/KMS, Cloud Guard, and Network Firewall gaps, all in one read-only pass.

SDK-validated

Detector field names validated against the real Oracle Python SDK, not just the docs.

What we scan on Oracle Cloud

A representative sample of the Oracle Cloud checks, grouped by service domain. Cost waste and security risk are surfaced in the same read-only pass. The complete, searchable list is further down this page.

Compute & storage

Compute, Block/Object/File storage, Container Instances.

Idle & oversized compute

Instances running with little real utilization.

Orphaned block volumes & backups

Storage left behind by deleted resources.

Object & file storage hygiene

Exposure and lifecycle gaps across buckets and file systems.

Container Instances & Data Flow waste

Serverless and analytics resources nobody uses.

Database

Autonomous Database, DB Systems, GoldenGate.

Autonomous Database idle/oversized

ADB scaled or licensed beyond actual use.

DB Systems utilization

Database nodes running well below capacity.

GoldenGate deployment hygiene

Replication deployments on outdated or unused configs.

Network

VCN, load balancers, Network Firewall.

Idle load balancers

Balancers with no backends or traffic.

VCN & gateway plumbing

Network resources provisioned and abandoned.

Network Firewall posture

Perimeter rules and exposure gaps.

Security & identity

IAM/policies, Vault/KMS, Cloud Guard, VSS.

IAM policy posture

Over-broad policies beyond least privilege.

Vault & KMS hygiene

Key management and rotation gaps.

Cloud Guard not enabled

Native detective controls left off.

Vulnerability Scanning (VSS) gaps

Workloads without scan coverage.

Every check we run on Oracle Cloud

All 183 checks, generated directly from the scanner so this list matches what actually runs. Search for a service to see whether your stack is covered.

  • Commitment

    GoldenGate deployment using license-included

    A GoldenGate deployment uses the license-included model, which bundles the software licence into the hourly rate. Organizations that already own GoldenGate licences can switch to bring-your-own-licence (BYOL) and pay a lower infrastructure-only rate. Informational.

  • Compute

    Instance on a legacy shape

    Compute instance running on a previous-generation shape (e.g. VM.Standard1/Standard2/E2) that has a cheaper, faster current successor (E4/E5/A1). Migrating modernizes performance and usually cuts cost.

  • Compute

    Underused dedicated VM host

    Dedicated VM host with no or very few instances placed on it. You pay for the whole host regardless of placement, so an empty/near-empty host is wasted spend. Consolidate workloads or release it.

  • Database

    Autonomous Database auto-scaling disabled

    Autonomous Database with compute auto-scaling turned off, so it cannot scale OCPUs to demand. Usually a missed cost-efficiency opportunity.

  • Database

    DB system license model review

    Oracle DB systems using LICENSE_INCLUDED, which is worth reviewing against owned Oracle licenses (BYOL) for potential savings. Informational.

  • Database

    Prod DB system without HA

    Production-looking Oracle DB systems running a single node with no RAC / Data Guard association. Informational resilience review.

  • Database

    Prod MySQL without HA

    Production-looking MySQL HeatWave DB systems with is_highly_available disabled. Informational resilience review.

  • Database

    Underutilized Exadata infrastructure

    A Cloud Exadata infrastructure is available but hosts few databases relative to its provisioned compute/storage. Exadata is billed on the rack regardless of utilization, so a sparsely used estate is costly. Informational.

  • Governance

    Alarm with no notification destination

    An enabled Monitoring alarm has no destination configured, so when it fires no one is notified.

  • Governance

    Analytics instance oversized for non-production

    An Analytics Cloud instance has a high capacity value (OCPU/OLPU) while its name/tags indicate a non-production instance. Analytics capacity bills continuously, so a large non-prod instance is usually over-provisioned. Informational.

  • Governance

    Attached volume without backups

    Block volumes attached to an instance with no volume backup present. An attached, unprotected volume has no recovery point if data is lost.

  • Governance

    Audit log retention below baseline

    The tenancy's audit-log retention is configured below 90 days, the common compliance baseline for investigating incidents.

  • Governance

    Autonomous Database on an old version

    Autonomous Database whose major Oracle Database version is older than 19c, missing security patches and long-term support.

  • Governance

    Autonomous Database without a recent backup

    An available Autonomous Database has no successful backup in the last 8 days. Automatic backups should run continuously; a stale newest backup means point-in-time recovery is degraded.

  • Governance

    Big Data Service cluster without Cloud SQL

    A multi-node Big Data Service cluster has is_cloud_sql_configured false, so the Cloud SQL query layer is not provisioned. For a cluster of this size that is usually a configuration gap or an underused capability worth reviewing. Informational.

  • Governance

    Boot volume without backup policy

    Boot volumes attached to an instance with no volume-backup policy assigned, leaving the OS/boot disk without an automated recovery point.

  • Governance

    Bucket storage tier mismatched to access pattern

    A bucket's default storage tier looks misaligned with the access pattern implied by its name/tags - cold/archive data sitting in Standard, or hot/serving data in Archive (where every read pays a restore fee). Informational.

  • Governance

    Bucket without cross-region replication

    A Standard or Infrequent-Access bucket has no replication policy, so its objects exist in a single region and would be lost in a regional outage. Business-critical buckets should replicate to a second region for DR.

  • Governance

    Budget without a forecast alert

    A budget has alert rules but none of them is a forecast-based alert, so overspend is only flagged after it has already occurred rather than when it is projected.

  • Governance

    Budget without an alert rule

    A budget exists but has no alert rule, so it tracks spend silently and never notifies anyone when a threshold is crossed.

  • Governance

    Compartment without enabled Events rules

    A compartment has no enabled Events service rule, so resource-lifecycle and operational events trigger no automation or alerting.

  • Governance

    Compartment without enabled alarms

    A compartment has no enabled Monitoring alarm, so there is no proactive alerting on metric thresholds for the resources it holds.

  • Governance

    Compartment without quotas

    A compartment has no compartment quotas, so there is no guardrail capping the number or size of resources that can be provisioned in it.

  • Governance

    Compartment without tag defaults

    A compartment has no tag defaults, so new resources are not automatically tagged for cost allocation, ownership, or environment tracking.

  • Governance

    Container instance without restart policy

    A running Container Instance has its container restart policy set to NEVER, so if a container exits or crashes it is not restarted and the workload silently goes down. Informational.

  • Governance

    DB home on an old patch set

    A database home runs an Oracle Database software version below the 19c long-term-support baseline, so the databases it hosts are missing patch set updates and security fixes. Informational.

  • Governance

    DB system likely over-provisioned on storage

    An Oracle DB system provisions a large amount of data storage while its name/tags indicate a non-production system. Provisioned storage bills regardless of how much is used, so a large non-prod allocation is a likely oversized-storage candidate. Informational.

  • Governance

    DB system on old major version

    Oracle DB systems below 19c or MySQL DB systems below 8.x, which are on old / out-of-support major versions and should be upgraded.

  • Governance

    DRG attachment not in an attached state

    A dynamic routing gateway (DRG) attachment is not in the ATTACHED lifecycle state, so it provides no active connectivity. A stale attachment clutters the routing topology and can mask a broken interconnect. Informational.

  • Governance

    Disabled Events rule

    An Events service rule exists but is disabled, so the automation or alerting it was created for is silently inactive.

  • Governance

    Disabled KMS keys

    KMS keys in the DISABLED state. They cannot encrypt or decrypt but are still retained in the vault. Re-enable if needed or schedule deletion.

  • Governance

    Disabled monitoring alarm

    A Monitoring alarm exists but is disabled, so it never evaluates its metric condition and never alerts.

  • Governance

    Empty DNS zone

    A DNS zone holds only its mandatory SOA/NS infrastructure records and no content records, suggesting it is unused and can be removed.

  • Governance

    Empty Functions application

    Functions applications that contain zero functions. Empty applications are usually leftovers from teardown and should be removed.

  • Governance

    Empty IAM group

    An IAM group has zero members yet may still be referenced by policies. Empty groups clutter the access model and can mask intent: a policy granting the group access is effectively dead until someone is added.

  • Governance

    Empty log group

    A log group contains no enabled logs. It collects nothing and only adds clutter to the logging configuration.

  • Governance

    Empty or stale compartment

    A compartment older than 30 days has no compute instances or block volumes in any scanned region. It may be an abandoned shell worth cleaning up. Informational.

  • Governance

    Empty volume group

    A volume group that contains no volumes. Empty groups are leftover scaffolding from removed workloads and should be deleted.

  • Governance

    Failed container instance

    A Container Instance is in the FAILED lifecycle state. It is not running workloads but may still hold its reserved shape, and a failed instance usually signals a broken deployment that needs attention or cleanup.

  • Governance

    Failed or stale email sender

    An Email Delivery approved sender is in a FAILED or NEEDS_ATTENTION state, so it cannot reliably send mail and should be fixed or removed.

  • Governance

    File systems without snapshots

    File systems with no snapshots have no recovery points; an accidental deletion or corruption is unrecoverable.

  • Governance

    GoldenGate deployment needs attention

    A GoldenGate deployment reports a lifecycle sub-state that indicates a degraded or needs-attention condition (for example RECOVERING or NEEDS_ATTENTION). Replication may be stalled or at risk, so the deployment should be investigated.

  • Governance

    GoldenGate deployment without auto-scaling

    A GoldenGate deployment reserves multiple OCPUs but has auto-scaling disabled, so it pays for its peak core count around the clock instead of scaling down during quiet periods. Informational.

  • Governance

    IAM user with no group memberships

    A local IAM user belongs to no groups, so it has no effective access granted through group policies. Such accounts are usually orphaned and should be deprovisioned to shrink the credential attack surface.

  • Governance

    Idle Integration / Analytics instance

    An Oracle Integration Cloud or Analytics Cloud instance has been left in an INACTIVE/stopped state for an extended period. It may still incur charges and adds attack surface. Clean it up if abandoned. Informational.

  • Governance

    Idle NoSQL table

    A NoSQL table is ACTIVE but has not been created or updated in a long time, suggesting it is abandoned. Provisioned tables reserve throughput, so an unused one is dead weight worth reviewing. Informational.

  • Governance

    Idle bastion with no recent sessions

    A bastion is ACTIVE but has no recent sessions and was created a while ago, so it appears unused. An idle bastion is standing remote-access infrastructure that can be removed to shrink the attack surface. Informational.

  • Governance

    Idle queue

    A Queue has not been updated for a long time and shows no sign of consumers draining it. Abandoned queues are cleanup candidates that clutter the inventory and can hide stale integrations. Cleanup.

  • Governance

    Idle streaming stream

    A Streaming stream has partitions provisioned and has existed for a while but shows no sign of active use. Partitions reserve throughput capacity, so an unused stream is dead weight worth reviewing. Informational.

  • Governance

    Inactive GoldenGate deployment

    A GoldenGate deployment has been stopped (INACTIVE) for a long time. A stopped deployment still reserves its provisioned capacity and clutters the inventory, so it is a cleanup candidate. Cleanup.

  • Governance

    Inactive container instance

    A Container Instance has been stopped (INACTIVE) for a long time. Stopped instances clutter the inventory and can hide abandoned workloads, so they are cleanup candidates. Cleanup.

  • Governance

    Instance pool with size zero

    An instance pool whose target size is 0 runs no instances. It is an idle definition that adds management overhead and is usually safe to delete.

  • Governance

    Instance with monitoring disabled

    Compute instance whose Oracle Cloud Agent monitoring or management plugin is disabled, so it emits no metrics and cannot be patched/managed centrally. A governance and observability gap.

  • Governance

    Integration instance over-provisioned on message packs

    An Oracle Integration Cloud instance provisions several message packs but looks idle or non-production by name/tags. Message packs set the billed throughput ceiling, so an idle instance with many packs is likely over-provisioned. Informational.

  • Governance

    KMS key has no cross-region replica

    A primary KMS key has no replica configured in another region, so the key (and therefore any data encrypted under it) is not available for cross-region disaster recovery or failover.

  • Governance

    Large email suppression list

    The tenancy's Email Delivery suppression list has grown large, indicating sustained bounces/complaints that hurt sender reputation and deliverability.

  • Governance

    Log retention below the audit floor

    An enabled log retains entries for fewer days than a sensible audit floor (30 days), truncating the window available for incident investigation. Short retention can leave a breach undetectable by the time it is noticed.

  • Governance

    Low tag coverage

    A high fraction of compute instances and block volumes carry no freeform tags, undermining cost allocation, ownership, and lifecycle tracking. One summary finding per tenancy.

  • Governance

    Many local IAM users (no federation)

    A large number of local IAM users with no identity-provider federation. Centralizing identities in an IdP (SSO) reduces credential sprawl.

  • Governance

    MySQL DB system backup retention below safe floor

    A MySQL HeatWave DB system has automatic backups enabled but a retention window shorter than a safe floor (7 days) for a production-looking system. A short window narrows the point-in-time recovery range available after an outage or data-corruption event.

  • Governance

    MySQL automatic backups disabled

    MySQL HeatWave DB systems whose backup policy has automatic backups disabled, leaving no point-in-time recovery.

  • Governance

    No Service Connector Hub configured

    The tenancy has no Service Connector Hub. Without a connector, logs and audit events are not aggregated to a central sink (Object Storage, Logging, Streaming, or a SIEM) for retention and monitoring. Informational.

  • Governance

    No active tag namespace

    The tenancy has no active defined-tag namespace (none exist, or all are retired), so defined tags cannot be applied for governed cost allocation.

  • Governance

    No budget configured

    The tenancy has no OCI budget configured, so there is no spend guardrail or automatic alerting when cost runs above plan.

  • Governance

    No notification topic configured

    No ONS notification topic exists in any scanned compartment, so alarms and events have nowhere to deliver alerts.

  • Governance

    NoSQL table capacity mode mismatch

    A NoSQL table runs in PROVISIONED capacity mode but is sized at the minimum read/write units, so it reserves throughput around the clock for what looks like a low or bursty workload. On-demand mode bills per request and usually fits better.

  • Governance

    NoSQL table without a default row TTL

    A NoSQL table defines no default time-to-live on its rows, so records are never expired automatically and storage grows without bound. Set a table TTL where rows are time-bounded to cap storage cost.

  • Governance

    OKE cluster on old Kubernetes version

    OKE clusters on a Kubernetes minor version older than the supported set. Old versions stop receiving security patches and block node upgrades.

  • Governance

    Object Storage object events disabled

    Buckets with object_events_enabled false emit no events for object create/update/delete, leaving an audit and automation gap.

  • Governance

    Object Storage versioning disabled

    Buckets with versioning Disabled cannot recover objects from accidental overwrite or deletion.

  • Governance

    Old KMS key without automatic rotation

    A KMS key has automatic rotation disabled and was created more than a year ago, so its key material has likely never been rotated. Long-lived key material increases the blast radius of a key compromise.

  • Governance

    Old standalone database backup

    A standalone database backup is older than 90 days and still ACTIVE. Long-retained manual backups accumulate storage cost and may breach data retention policy; review whether it is still needed.

  • Governance

    Only the Default identity domain exists

    The tenancy has only the built-in Default identity domain. Separate domains let you isolate workloads, environments, or user populations with independent policies. Informational.

  • Governance

    Orphaned database backup

    An ACTIVE standalone database backup references a source database OCID that no longer appears among the scanned DB systems, suggesting the database was deleted while the backup lingers and keeps billing. Informational.

  • Governance

    Orphaned instance configuration

    An instance configuration (launch template) that no instance pool references. Orphaned configurations accumulate and obscure which templates are live.

  • Governance

    Production instances not spread across fault domains

    Two or more running production instances within an availability domain share a single fault domain, so a hardware fault could take them all down at once. Informational.

  • Governance

    Queue with a very long retention window

    A Queue is configured with a message retention window at or near the maximum. Messages that are never consumed are stored for the full window, so an unusually long retention inflates stored-message volume for little benefit. Informational.

  • Governance

    Queue without dead-letter handling

    A Queue has its dead-letter delivery count set to 0 (or unset), so messages that repeatedly fail processing are dropped instead of being moved aside for inspection, which can mask data loss.

  • Governance

    Resource Manager stack drift or failed apply

    A Resource Manager stack reports detected drift or its most recent apply job failed. Either way the deployed infrastructure no longer matches the Terraform state the stack manages.

  • Governance

    Stale Data Flow application

    A Data Flow application has not been updated for a long time, suggesting it is an abandoned job definition cluttering the catalog. Cleanup.

  • Governance

    Stopped Autonomous Database

    Autonomous Database in the STOPPED state for 14+ days. Compute billing pauses, but the database storage keeps billing. Terminate if abandoned.

  • Governance

    Stopped compute instances

    Compute instances in the STOPPED state. Compute billing pauses, but the attached boot and block volumes keep billing. Release if abandoned.

  • Governance

    Unconfirmed notification subscription

    A Notifications (ONS) subscription is stuck in the PENDING state because the endpoint owner never confirmed it. Messages published to the topic are silently not delivered to that subscriber, so alerts can go missing.

  • Governance

    Unused network firewall policy

    A Network Firewall policy is not referenced by any firewall in the same region, so it is an orphaned configuration that clutters the inventory and can drift out of sync with the rules actually in force. Cleanup.

  • Governance

    Unused vaults

    Vaults in the ACTIVE state that contain no usable keys and no active secrets. A provisioned vault bills regardless of contents. Clean up if abandoned.

  • Network

    Disabled internet gateways

    Internet gateways present but disabled route nothing; they are usually leftover configuration (informational).

  • Network

    Idle load balancers with no listeners

    Load balancers with zero listeners cannot accept any traffic yet keep billing per hour.

  • Network

    Load balancers with no backends

    Load balancers whose backend sets have zero backends. The LB bills per hour while serving no traffic to any target.

  • Network

    Unattached reserved public IPs

    Reserved public IPs assigned to no entity. A reserved public IP keeps billing whether or not it is attached to a resource.

  • Network

    Unused NAT gateways

    NAT gateways whose VCN has no DRG or internet gateway and no private subnet egress usage (best-effort, informational).

  • Network

    Unused dynamic routing gateways

    Dynamic routing gateways (DRGs) with no attachments route nothing and are likely leftover (informational).

  • Security

    API Gateway with public endpoint

    API Gateways with a PUBLIC endpoint type. Public gateways are internet-reachable; confirm authentication, rate-limiting, and WAF are in place.

  • Security

    Admin policy not restricted to a network source

    A tenancy-root policy grants 'manage all-resources in tenancy' without a 'where request.networkSource.name=...' condition, so administrative access is reachable from any network.

  • Security

    Analytics instance is publicly accessible

    An Analytics Cloud instance uses a public network endpoint with no IP/VCN allow-list, so its dashboards and data are reachable from the internet instead of only a private endpoint.

  • Security

    Auth tokens present

    Users holding long-lived auth tokens. These bearer credentials do not expire on their own and should be rotated and reviewed periodically.

  • Security

    Autonomous Database not requiring mTLS

    Autonomous Database that accepts non-mTLS (TLS-only) connections. Mutual TLS adds client-certificate authentication and is the safer default.

  • Security

    Autonomous Database with no IP whitelist

    Publicly reachable Autonomous Database whose access-control whitelist is empty, leaving the public endpoint open to every source IP.

  • Security

    Bastion allows long sessions

    A bastion's maximum session TTL exceeds three hours. Long-lived sessions widen the window in which a forwarded port or SSH session can be abused.

  • Security

    Bastion open to the internet

    A bastion's client CIDR allow-list includes 0.0.0.0/0, so a session may be created from any address on the internet rather than known networks.

  • Security

    Big Data Service cluster is publicly accessible

    A Big Data Service cluster has nodes with public IP addresses (or does not require a NAT gateway), exposing Hadoop/Spark management and data ports to the internet.

  • Security

    Big Data Service cluster not secured

    A Big Data Service cluster is active but does not have secure mode (Kerberos authentication) enabled, leaving Hadoop services without strong authentication between components and clients.

  • Security

    Bucket pre-authenticated request without expiry

    A bucket pre-authenticated request (PAR) has no expiry time, or one set far in the future. A PAR is an unauthenticated signed URL, so a long-lived one is a standing credential that cannot be revoked short of deleting it.

  • Security

    Cloud Guard disabled

    Cloud Guard is DISABLED for the tenancy, so OCI is not continuously evaluating resource and activity posture for risks.

  • Security

    Cloud Guard has no reporting region

    Cloud Guard is enabled but no reporting region is configured, so aggregated problems and recommendations have no home region.

  • Security

    Cloud Guard has no root target

    Cloud Guard is enabled but no active target covers the root compartment, so child compartments are not monitored by inheritance.

  • Security

    Cloud Guard self-managed resources enabled

    Cloud Guard has self_manage_resources set to true, which means the Oracle-managed detector and responder recipes are not applied. Detection coverage then depends entirely on custom recipes the tenant maintains, which are easy to leave incomplete.

  • Security

    Console access on API-only user

    Local users that have API/secret credentials and a Console password but no MFA. The Console password is likely unused and should be removed.

  • Security

    Customer secret keys present

    Users holding customer secret keys (S3-compatible access keys for Object Storage). These static credentials should be reviewed and rotated.

  • Security

    DNS zone without a DMARC record

    A public DNS zone that hosts content records has no _dmarc TXT record, so the domain publishes no DMARC policy. Without DMARC, receivers cannot tell the domain owner how to handle spoofed mail, weakening anti-phishing protection.

  • Security

    DNS zone without change protection

    A public DNS zone has is_protected set to false, so it lacks the managed protection OCI offers against accidental or unauthorized record changes. Mail-bearing domains in particular should be protected so anti-spoofing records (SPF/DKIM/DMARC) cannot be silently altered.

  • Security

    Data Flow app on end-of-life Spark

    A Data Flow application targets a Spark version that is past upstream end-of-life, so it no longer receives security patches and may carry known vulnerabilities in Spark and its bundled dependencies.

  • Security

    Data Safe assessment reports high risk

    A Data Safe security assessment reports one or more high-risk findings, indicating database configuration weaknesses that need remediation.

  • Security

    Data Safe target without a security assessment

    A database is registered as a Data Safe target but has no security assessment, so its configuration risk has never been evaluated.

  • Security

    Database not registered with Data Safe

    A database (DB system or autonomous database) has no Data Safe target registration, so it has no user/privilege auditing, activity monitoring, or security assessment posture.

  • Security

    Dedicated Autonomous Database publicly accessible

    Dedicated Autonomous Database (Exadata Dedicated Infrastructure) reachable over a public endpoint. Dedicated estates are expected to stay private.

  • Security

    Default security list is permissive

    A VCN's default security list has ingress from 0.0.0.0/0. Resources land in the default list unless explicitly reassigned, so broad rules here silently expose new subnets.

  • Security

    Dynamic group has an overly broad matching rule

    A dynamic group's matching rule matches a very wide set of principals (e.g. all instances in the tenancy), so any matched resource inherits whatever the group is granted.

  • Security

    Email sender without DKIM

    An approved Email Delivery sender's domain has no active DKIM key, so its outbound mail is unsigned and far more likely to be spoofed or rejected.

  • Security

    Email sender without SPF

    An approved Email Delivery sender has SPF disabled for its domain, weakening sender authentication alongside DKIM.

  • Security

    Expired auth token still attached to a user

    An IAM user has an auth token whose time_expires is in the past but which is still attached to the account. Expired credentials should be deleted so they cannot be reactivated or cause confusion during credential audits.

  • Security

    Failed network firewall

    A Network Firewall is in the FAILED lifecycle state, so it is not inspecting or filtering traffic on its subnet as intended, potentially leaving a routing path unprotected.

  • Security

    File system export open to the world

    An NFS export with an export option granting READ_WRITE access to all source CIDRs (0.0.0.0/0) exposes the file system to any reachable host.

  • Security

    File system export without root squash

    An NFS export option with identity_squash=NONE maps a remote root user to root on the file system, allowing privileged access to all files.

  • Security

    File systems without customer-managed keys

    File systems with no kms_key_id are encrypted with Oracle-managed keys; a customer-managed KMS key gives control over rotation and revocation.

  • Security

    Functions application may be on a public subnet

    A Functions application whose name/tags indicate an internal/worker role has no internet-facing need, yet nothing marks its subnet as private. Hosting internal functions on a public subnet widens exposure. Informational - confirm the subnet is private.

  • Security

    GoldenGate deployment not on latest version

    A GoldenGate deployment is not running the latest available version (is_latest_version=false), so it may be missing security and stability fixes shipped in newer GoldenGate releases.

  • Security

    IAM network source allows the whole internet

    An IAM network source includes 0.0.0.0/0 (or ::/0) in its public source list, so a policy condition bound to it imposes no real IP restriction.

  • Security

    IAM user without MFA

    Local IAM users who can sign in to the Console but have not activated multi-factor authentication.

  • Security

    Identity domain visible on the login page

    An identity domain has is_hidden_on_login set to false, so it is shown on the IdP discovery/login page. Exposing internal or administrative domains on the public login surface aids reconnaissance and credential-stuffing.

  • Security

    Instance allowing IMDS v1

    Compute instance whose legacy instance-metadata-service (IMDS v1) endpoints are still enabled. v1 is unauthenticated and a known SSRF credential-exfiltration vector; v2 should be enforced.

  • Security

    Instance with a public IP

    Compute instance whose VNIC has a public IP address, exposing it directly to the internet. Confirm the exposure is intended and gated.

  • Security

    Integration instance is publicly accessible

    An Oracle Integration Cloud (OIC) instance exposes a public network endpoint, making its console and runtime reachable from the internet rather than only from a private VCN endpoint.

  • Security

    Internet-exposed GoldenGate deployment

    A GoldenGate deployment has a public endpoint (is_public=true), so its replication control plane and console are reachable from the internet. Replication deployments handle production data and should sit on a private subnet behind controlled network access.

  • Security

    KMS key uses software protection

    A KMS key is stored with SOFTWARE protection mode rather than in an HSM. Software-protected key material has lower assurance and is unsuitable for sensitive or production data that requires hardware-backed keys.

  • Security

    KMS keys pending deletion

    KMS keys in the PENDING_DELETION state. Once the waiting period elapses the key material is destroyed and anything it encrypted becomes unrecoverable. Confirm the deletion is intended.

  • Security

    KMS keys without rotation

    KMS master encryption keys in the ENABLED state that have no scheduled automatic rotation. Long-lived static keys widen the blast radius of a key compromise.

  • Security

    Logging not enabled for active compartment

    A compartment runs compute instances but has no enabled service or custom logs, so activity on those assets is not being captured.

  • Security

    Low MFA enrollment coverage

    The number of users with an active MFA TOTP device is well below the total user count, so most accounts can still authenticate with a password alone. Partial MFA coverage leaves the unenrolled accounts exposed to credential theft.

  • Security

    MFA not enforced tenancy-wide

    No tenancy sign-on policy enforces multi-factor authentication: no users have an activated TOTP MFA device, so Console sign-in is single-factor across the tenancy.

  • Security

    Managed certificate already expired

    A managed certificate's current version is past its not-after date. Any endpoint still serving it presents an expired certificate, breaking TLS.

  • Security

    Managed certificate expiring soon

    A managed certificate's current version expires within 30 days. An expired certificate breaks TLS for every endpoint that serves it.

  • Security

    Multiple active API keys

    Users with two or more active API signing keys. Extra keys are often abandoned rotation leftovers and expand the attack surface.

  • Security

    Network security group open to the internet

    A network security group ingress rule allows a sensitive port (SSH, RDP, or a database engine) from 0.0.0.0/0, exposing it to the entire internet.

  • Security

    No IAM network sources defined

    The tenancy has no IAM network sources. Without a named source, no policy can restrict console/API access to known IP ranges or VCNs, so credentials are usable from anywhere on the internet.

  • Security

    No identity federation (SSO)

    The tenancy has no SAML identity provider configured, so all sign-ins rely on local IAM credentials instead of a central identity provider (SSO). Federation centralizes lifecycle and MFA control.

  • Security

    No network perimeter on authentication

    The tenancy authentication policy defines no network sources, so Console and API sign-in is not restricted to trusted networks. Network sources let you confine sensitive access to known CIDRs.

  • Security

    No vulnerability scan targets

    The Vulnerability Scanning Service has no host or container scan targets configured in any scanned region, so compute instances and container images are not being checked for known CVEs and open ports.

  • Security

    OKE cluster with public API endpoint

    OKE clusters whose Kubernetes API server endpoint has a public IP. A public control-plane endpoint widens the attack surface; prefer private.

  • Security

    Object Storage bucket without a customer-managed key

    Buckets with no kms_key_id use Oracle-managed encryption keys, leaving key rotation and revocation outside customer control.

  • Security

    Object Storage pre-authenticated request with broad access

    Pre-authenticated requests with an AnyObject* access type or that target the whole bucket grant URL-only access to many objects, bypassing IAM.

  • Security

    Open critical Cloud Guard problems

    Cloud Guard has open (ACTIVE) problems at CRITICAL or HIGH risk level that have not been resolved or dismissed.

  • Security

    Policy grants IAM administration to a non-admin group

    An IAM policy statement grants 'manage' over an identity resource family (users, groups, policies, dynamic-groups) to a non-Administrators group, enabling privilege escalation.

  • Security

    Policy grants broad admin at the tenancy level

    An IAM policy statement grants a broad 'manage' verb at the tenancy scope to a non-Administrators subject, widening the blast radius tenancy-wide.

  • Security

    Policy grants manage all-resources to a non-admin group

    An IAM policy statement grants the 'manage all-resources' verb/resource to a group other than Administrators, conferring near-tenancy-admin power.

  • Security

    Policy grants to any-user / overly broad principal

    An IAM policy statement grants permissions to the 'any-user' or 'any-group' principal, exposing the resources to every identity.

  • Security

    Public (standard) bastion

    A bastion is of the STANDARD type, which exposes its endpoint on the public internet. Where a private/internal access path exists, a public bastion needlessly broadens the attack surface. Informational.

  • Security

    Public DNS zone without DNSSEC

    A public (GLOBAL scope) primary DNS zone has DNSSEC unsigned, leaving its records open to spoofing and cache-poisoning attacks.

  • Security

    Public Object Storage buckets

    Buckets with public_access_type ObjectRead or ObjectReadWithoutList let anyone read objects without authentication. A data-exposure risk.

  • Security

    Public container repository

    OCIR container repositories marked public. Anyone can pull images without authentication, risking leaked software and embedded secrets.

  • Security

    Public load balancer looks like an internal tier

    A load balancer is public (is_private false) while its name or tags indicate an internal or backend tier. Internal services exposed through a public load balancer widen the attack surface unnecessarily. Informational.

  • Security

    Public load balancer without WAF

    A public (internet-facing) load balancer has no Web Application Firewall policy attached, so HTTP(S) traffic reaches its backends with no L7 filtering against common web attacks.

  • Security

    Public load balancer without a TLS listener

    A public load balancer has listeners configured but none appear to terminate TLS (by listener name they look like plain HTTP or TCP), so it may be serving plaintext traffic to the internet. Informational - confirm the listener protocols.

  • Security

    Public subnet in a sensitive tier

    A subnet allows public IP addresses on VNICs (prohibit_public_ip_on_vnic is false) while its name/tags indicate a sensitive tier such as a database or private/internal layer. Informational.

  • Security

    Publicly accessible Autonomous Database

    Autonomous Database with a public endpoint. No private endpoint and no network security group or IP whitelist restricting access.

  • Security

    Publicly reachable DB systems

    Oracle DB systems or MySQL HeatWave DB systems exposed through a public endpoint. Database listeners should sit on a private subnet.

  • Security

    Security list open to the internet

    A security list ingress rule allows a sensitive port (SSH, RDP, or a database engine) from 0.0.0.0/0, exposing it to the entire internet.

  • Security

    Security list opens all ports to the internet

    A security list ingress rule from 0.0.0.0/0 covers all protocols or the full TCP/UDP port range, exposing every service on attached subnets.

  • Security

    Stale API signing key

    User API signing keys older than 90 days. Long-lived keys widen the window for a leaked credential to be abused.

  • Security

    User in Administrators group

    Local IAM users placed directly in the built-in Administrators group, which grants tenancy-wide privileges.

  • Security

    VCN subnet without flow logs

    A subnet has no VCN flow log enabled, so there is no record of accepted or rejected traffic for incident investigation or anomaly detection.

  • Security

    Vault secrets without rotation

    Vault secrets in the ACTIVE state that have no automatic rotation policy. Static, unrotated secrets stay valid indefinitely if leaked.

  • Security

    Volume not using customer-managed keys

    Block or boot volumes encrypted with the Oracle-managed key (no kms_key_id). Where customer-managed keys are policy, assign a Vault key.

  • Security

    WAF policy in detection-only mode

    A Web Application Firewall policy declares only ALLOW/CHECK actions and no blocking (RETURN_HTTP_RESPONSE) action, so it logs matching requests but never blocks them.

  • Security

    WAF policy not attached to any firewall

    A Web Application Firewall policy exists but is referenced by no WAF firewall, so it protects nothing. Usually leftover configuration.

  • Security

    Weak password policy

    The tenancy authentication password policy is below CIS minimums: the minimum length is under 14 characters or character-class complexity (lowercase, uppercase, numeric, special) is not enforced.

  • Storage

    Idle file systems (no exports)

    File systems with no exports and no mount targets are unreachable by any NFS client, yet their metered storage keeps billing.

  • Storage

    Object Storage bucket without a lifecycle policy

    Buckets with no object lifecycle policy never auto-delete or tier old objects, so stale data accumulates and bills indefinitely.

  • Storage

    Old manual volume backups

    Manually created volume backups older than 180 days. Unlike policy backups they are never pruned and accumulate storage cost indefinitely.

  • Storage

    Old unused custom images

    Custom (non Oracle-provided) compute images older than 180 days that no instance launched from. Each image's backing storage bills monthly.

  • Storage

    Orphaned boot volumes

    Boot volumes in the AVAILABLE state attached to no instance for 7+ days. A detached boot volume bills full price for data nothing boots.

  • Storage

    Orphaned volume backups

    Volume backups older than 30 days whose source volume no longer exists in the scan. Often abandoned recovery points that keep billing.

  • Storage

    Stream with long retention in non-prod

    A Streaming stream in a compartment/stream that looks non-production retains messages for the maximum window. Long retention rarely matters outside production and grows the stored data footprint. Informational.

  • Storage

    Unattached block volumes

    Block volumes in the AVAILABLE state attached to no instance for 7+ days. They bill full price whether or not anything uses them.

Checks marked opt-in use a paid or billing-data cloud API and never run unless you switch them on. A default scan uses only free APIs.

How you connect

An API signing key

Add a read-only user to a group with a read-only policy and upload the API signing key in the dashboard.

Read-only IAM policy (inspect/read verbs). Encrypted at rest, revocable any time.

How the dollars are calculated

Curated baseline pricing (live OCI pricing is on the roadmap); every finding labels its pricing source.

Every finding is backed by the raw cloud API response it came from, with a confidence score and the pricing source labelled, no black-box numbers.

Scan your Oracle Cloud estate free

Connect an api signing key and run a read-only scan. Findings come priced in real dollars with a fix and the evidence for each.

Start scanning free

Other clouds we scan