CNAPP / CSPM / Wiz

Wiz

Wiz connects cloud inventory, configuration, vulnerability and identity context to help teams understand exposure paths. Its platform includes agentless visibility and separate runtime capabilities. A graph can explain how conditions relate, but observing a process while it runs requires the relevant runtime component and supported deployment.

Multicloud CNAPPResearch reviewed

What you are evaluating

This profile covers the Wiz platform and separately scoped Sensor capability. Agentless API or snapshot visibility is not runtime monitoring. Verify cloud, workload and module coverage rather than assuming the same capability exists for every connected account.

A useful evaluation context

A multicloud team can evaluate shared exposure context while deciding which workloads also require runtime sensors and operational response.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Agentless cloud connections provide inventory and posture context through supported APIs and scanning methods.
  • Security graph and code-to-cloud functions relate exposure findings to resources and development ownership.
  • Wiz Sensor adds separately deployed runtime visibility; the platform also documents infrastructure-as-code and AI-related capabilities with their own scope.

Where it fits in the work

  1. Connect a bounded cloud lab and compare its known assets, roles and network paths with the discovered inventory.
  2. Trace one synthetic exposure relationship to its resource owner or source configuration, checking the evidence behind each graph edge.
  3. Where live behavior matters, deploy the supported sensor separately and verify the runtime signal rather than relying on the agentless inventory.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

Connect synthetic resources with a known role-to-resource relationship and run a benign documented event on a separately instrumented lab workload.

Evidence to look for

The graph explains the configured relationship, while the runtime event has distinct sensor evidence and an identifiable covered workload.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. What permissions and data access are required by each agentless scan?
  2. Which runtime signal requires Wiz Sensor, and which operating systems or deployment patterns support it?
  3. Can the team export evidence and ownership mappings without making the visual graph its only record?

Find your next idea.

Tip: press / to open search. Escape closes this window.