ThreatintelClient¶
-
class
oci.threat_intelligence.ThreatintelClient(config, **kwargs)¶ Use the Threat Intelligence API to view indicators of compromise and related items. For more information, see [Overview of Threat Intelligence](/Content/ThreatIntelligence/Concepts/threatintelligenceoverview.htm).
Methods
__init__(config, **kwargs)Creates a new service client get_indicator(indicator_id, compartment_id, …)Gets a detailed indicator by identifier list_indicator_counts(compartment_id, **kwargs)Get the current count of each indicator type. list_indicators(compartment_id, **kwargs)Returns a list of IndicatorSummary objects. list_threat_types(compartment_id, **kwargs)Gets a list of threat types that are available to use as parameters when querying indicators. -
__init__(config, **kwargs)¶ Creates a new service client
Parameters: - config (dict) – Configuration keys and values as per SDK and Tool Configuration.
The
from_file()method can be used to load configuration from a file. Alternatively, adictcan be passed. You can validate_config the dict usingvalidate_config() - service_endpoint (str) – (optional)
The endpoint of the service to call using this client. For example
https://iaas.us-ashburn-1.oraclecloud.com. If this keyword argument is not provided then it will be derived using the region in the config parameter. You should only provide this keyword argument if you have an explicit need to specify a service endpoint. - timeout (float or tuple(float, float)) – (optional) The connection and read timeouts for the client. The default values are connection timeout 10 seconds and read timeout 60 seconds. This keyword argument can be provided as a single float, in which case the value provided is used for both the read and connection timeouts, or as a tuple of two floats. If a tuple is provided then the first value is used as the connection timeout and the second value as the read timeout.
- signer (
AbstractBaseSigner) –(optional) The signer to use when signing requests made by the service client. The default is to use a
Signerbased on the values provided in the config parameter.One use case for this parameter is for Instance Principals authentication by passing an instance of
InstancePrincipalsSecurityTokenSigneras the value for this keyword argument - retry_strategy (obj) –
(optional) A retry strategy to apply to all calls made by this service client (i.e. at the client level). There is no retry strategy applied by default. Retry strategies can also be applied at the operation level by passing a
retry_strategykeyword argument as part of calling the operation. Any value provided at the operation level will override whatever is specified at the client level.This should be one of the strategies available in the
retrymodule. A convenienceDEFAULT_RETRY_STRATEGYis also available. The specifics of the default retry strategy are described here. - circuit_breaker_strategy (obj) – (optional)
A circuit breaker strategy to apply to all calls made by this service client (i.e. at the client level).
This client uses
DEFAULT_CIRCUIT_BREAKER_STRATEGYas default if no circuit breaker strategy is provided. The specifics of circuit breaker strategy are described here. - circuit_breaker_callback (function) – (optional) Callback function to receive any exceptions triggerred by the circuit breaker.
- allow_control_chars – (optional) allow_control_chars is a boolean to indicate whether or not this client should allow control characters in the response object. By default, the client will not allow control characters to be in the response object.
- config (dict) – Configuration keys and values as per SDK and Tool Configuration.
The
-
get_indicator(indicator_id, compartment_id, **kwargs)¶ Gets a detailed indicator by identifier
Parameters: - indicator_id (str) – (required) unique indicator identifier
- compartment_id (str) – (required) The ID of the tenancy to use to filter results.
- opc_request_id (str) – (optional) The client request ID for tracing.
- retry_strategy (obj) –
(optional) A retry strategy to apply to this specific operation/call. This will override any retry strategy set at the client-level.
This should be one of the strategies available in the
retrymodule. This operation will not retry by default, users can also use the convenientDEFAULT_RETRY_STRATEGYprovided by the SDK to enable retries for it. The specifics of the default retry strategy are described here.To have this operation explicitly not perform any retries, pass an instance of
NoneRetryStrategy. - allow_control_chars (bool) – (optional) allow_control_chars is a boolean to indicate whether or not this request should allow control characters in the response object. By default, the response will not allow control characters in strings
Returns: A
Responseobject with data of typeIndicatorReturn type: Example: Click here to see an example of how to use get_indicator API.
-
list_indicator_counts(compartment_id, **kwargs)¶ Get the current count of each indicator type. Results can be sorted ASC or DESC by count.
Parameters: - compartment_id (str) – (required) The ID of the tenancy to use to filter results.
- opc_request_id (str) – (optional) The client request ID for tracing.
- sort_order (str) –
(optional) The sort order to use, either ‘ASC’ or ‘DESC’.
Allowed values are: “ASC”, “DESC”
- retry_strategy (obj) –
(optional) A retry strategy to apply to this specific operation/call. This will override any retry strategy set at the client-level.
This should be one of the strategies available in the
retrymodule. This operation will not retry by default, users can also use the convenientDEFAULT_RETRY_STRATEGYprovided by the SDK to enable retries for it. The specifics of the default retry strategy are described here.To have this operation explicitly not perform any retries, pass an instance of
NoneRetryStrategy. - allow_control_chars (bool) – (optional) allow_control_chars is a boolean to indicate whether or not this request should allow control characters in the response object. By default, the response will not allow control characters in strings
Returns: A
Responseobject with data of typeIndicatorCountCollectionReturn type: Example: Click here to see an example of how to use list_indicator_counts API.
-
list_indicators(compartment_id, **kwargs)¶ Returns a list of IndicatorSummary objects.
Parameters: - compartment_id (str) – (required) The ID of the tenancy to use to filter results.
- threat_type_name (list[str]) – (optional) The result set will include indicators that have any of the provided threat types. To filter for multiple threat types repeat the query parameter.
- type (str) –
(optional) The indicator type of entities to be returned.
Allowed values are: “DOMAIN_NAME”, “FILE_NAME”, “MD5_HASH”, “SHA1_HASH”, “SHA256_HASH”, “IP_ADDRESS”, “URL”
- value (str) – (optional) The indicator value of entities to be returned.
- confidence_greater_than_or_equal_to (int) – (optional) The minimum confidence score of entities to be returned.
- time_updated_greater_than_or_equal_to (datetime) – (optional) The oldest update time of entities to be returned.
- limit (int) – (optional) The maximum number of items to return.
- page (str) – (optional) A token representing the position at which to start retrieving results. This must come from the opc-next-page header field of a previous response.
- sort_order (str) –
(optional) The sort order to use, either ‘ASC’ or ‘DESC’.
Allowed values are: “ASC”, “DESC”
- sort_by (str) –
(optional) The field to sort by. Only one field to sort by may be provided.
Allowed values are: “confidence”, “timeUpdated”
- opc_request_id (str) – (optional) The client request ID for tracing.
- retry_strategy (obj) –
(optional) A retry strategy to apply to this specific operation/call. This will override any retry strategy set at the client-level.
This should be one of the strategies available in the
retrymodule. This operation will not retry by default, users can also use the convenientDEFAULT_RETRY_STRATEGYprovided by the SDK to enable retries for it. The specifics of the default retry strategy are described here.To have this operation explicitly not perform any retries, pass an instance of
NoneRetryStrategy. - allow_control_chars (bool) – (optional) allow_control_chars is a boolean to indicate whether or not this request should allow control characters in the response object. By default, the response will not allow control characters in strings
Returns: A
Responseobject with data of typeIndicatorSummaryCollectionReturn type: Example: Click here to see an example of how to use list_indicators API.
-
list_threat_types(compartment_id, **kwargs)¶ Gets a list of threat types that are available to use as parameters when querying indicators. This is sorted by threat type name according to the sort order query param.
Parameters: - compartment_id (str) – (required) The ID of the tenancy to use to filter results.
- limit (int) – (optional) The maximum number of items to return.
- page (str) – (optional) A token representing the position at which to start retrieving results. This must come from the opc-next-page header field of a previous response.
- sort_order (str) –
(optional) The sort order to use, either ‘ASC’ or ‘DESC’.
Allowed values are: “ASC”, “DESC”
- opc_request_id (str) – (optional) The client request ID for tracing.
- retry_strategy (obj) –
(optional) A retry strategy to apply to this specific operation/call. This will override any retry strategy set at the client-level.
This should be one of the strategies available in the
retrymodule. This operation will not retry by default, users can also use the convenientDEFAULT_RETRY_STRATEGYprovided by the SDK to enable retries for it. The specifics of the default retry strategy are described here.To have this operation explicitly not perform any retries, pass an instance of
NoneRetryStrategy. - allow_control_chars (bool) – (optional) allow_control_chars is a boolean to indicate whether or not this request should allow control characters in the response object. By default, the response will not allow control characters in strings
Returns: A
Responseobject with data of typeThreatTypesCollectionReturn type: Example: Click here to see an example of how to use list_threat_types API.
-