What we still need to verify : 1 point in this profile is not yet confirmed against vendor documentation.
- Current module names and the scope of the code and runtime sensor offerings: confirm against vendor documentation
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Wiz scans cloud environments agentlessly, reading workload disk snapshots and provider API state through a read-only role, and assembles the result into a security graph. The graph is the product. Nodes are resources, identities, workloads and data stores, edges are the relationships between them. Findings are queries over that graph, which is how a vulnerable package becomes a risk statement: this container is publicly reachable, runs an exploitable library, and holds a role that can read customer data.
That toxic combination model is the answer to the volume problem every cloud security team has. Instead of ranking thousands of findings by severity, it surfaces the far smaller number of chains that are exploitable end to end. Around the graph sit the expected modules: cloud posture and compliance reporting, Kubernetes security, identity and entitlement analysis, data classification, secret detection, IaC and repository scanning, and an optional runtime sensor for the live detection that snapshot-based scanning cannot provide.
Where it fits
Wiz connects to cloud accounts through roles, so onboarding is a permissions exercise rather than a deployment project, and coverage of connected accounts is complete from the start. It is operated by a cloud security team, with findings routed to the engineering teams that own the affected resources. The code scanning pieces reach earlier into development and the runtime sensor reaches later into production, but the center of gravity is continuous assessment of the deployed estate.
Strengths
- The graph model produces prioritization that stands up to scrutiny, which is what makes remediation conversations with engineering teams productive.
- Agentless onboarding means near-complete coverage quickly, without negotiating agent deployment with every application owner.
- The graph query interface lets a security engineer answer novel questions directly, rather than waiting for a vendor to ship a detection.
- Consistent model across AWS, Azure, GCP and Kubernetes, which matters for teams whose estate genuinely spans providers.
Limitations
- Snapshot-based assessment is point in time. Without the runtime sensor there is no live detection, and short-lived workloads can be missed between scan cycles.
- The breadth encourages consolidation, and consolidation creates lock-in across policies, queries, integrations and historical data.
- Prioritization quality depends on the graph being complete. Unconnected accounts, non-cloud infrastructure and unmanaged assets are not in the model, and their absence is not obvious from the console.
Who it suits
Fits organizations with large multi-cloud estates and a security team whose bottleneck is deciding what to fix first rather than finding issues at all. Poorly matched to small single-cloud teams whose real gaps are unscanned images and unreviewed Terraform, which open-source tooling in CI plus native cloud controls address with less overhead.
Used Wiz? Recommend it under your own name and title.
Recommend this tool