Wiz Integration
Wiz cloud risk findings correlated with runtime threat signals.
What this integration does
Wiz meets agentic SOC
Wiz is a leading cloud security posture management (CSPM) and cloud-native application protection platform (CNAPP). ManySignal integrates with Wiz to ingest vulnerability findings, misconfigurations, toxic combinations, and runtime threats, correlating them with CloudTrail, Okta, and CrowdStrike data to add runtime threat context to Wiz's risk scores.
Wiz issue and finding ingestion via Wiz API
Toxic combination (attack path) ingestion
Runtime threat detection ingestion from Wiz Runtime Sensor
Data collected
- Wiz Issues (misconfigurations, vulnerabilities, secrets)
- Wiz toxic combinations and attack paths
- Runtime threat events from Wiz Sensor
- Asset inventory metadata
Actions supported
- Open Wiz issue in external tracker (Jira, ServiceNow)
- Mark Wiz issue as accepted risk
- Trigger Wiz auto-remediation workflow
- Create Wiz security exception
Getting started
Set up in minutes
- 1
Create a Wiz service account
- 2
Configure the connector
- 3
Configure ingestion scope
Wiz Integration: frequently asked questions
Does ManySignal replace Wiz?
No. Wiz handles agentless cloud security posture and vulnerability assessment. ManySignal provides runtime threat detection, alert triage, and incident response — complementary capabilities.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.