Wiz
Overview
Wiz provides direct visibility, risk prioritization, and remediation guidance for development teams to address risks in their own infrastructure and applications. The platform connects to cloud environments through provider APIs and scans workloads without deploying agents, maintaining a continuously updated inventory of virtual machines, containers, and other cloud resources along with the vulnerabilities, misconfigurations, and exposures associated with each one.
Available Integrations
| Product(s) | Supported Asset Type(s) | Integration Type |
|---|---|---|
| Wiz | Devices, Cloud Vulnerabilities & Resources | Source |
Please review the configuration instructions in the section below before setting up permissions for apps.
Configuration
- Install a runner: Follow our instructions to install a runner.
-
Choose a Schema: A schema is a configuration template that defines a specific way to connect, authenticate, and interact with a source. The following are the available schemas:
- Client ID / Secret with URL – Uses a client ID and Client Secret from your Wiz service account and the API Endpoint URL found in your Wiz portal to connect and pull assets from Wiz.
-
Configure plugin: Configure the plugin with the required fields.
Client ID / Secret with URL
| Field | Description | Example |
|---|---|---|
API Endpoint URL* | The Wiz GraphQL API has a single endpoint: https://api.<region>.app.wiz.io/graphql, where <region> is the AWS region your tenant resides in (e.g., us1, us2, eu1, or eu2). The specific URL is found in your user profile. | https://api.us1.app.wiz.io/graphql |
| Skip TLS Certification Validation | Skip certificates validation when using a certificate that is self-signed or unable to be validated through a proper certificate authority. | n/a |
Client ID* | Your application's Client ID | 1234567890abcdefghijklmnopqrstuvwxyz0987654321zyxvut |
Client Secret* | Your application's Client Secret | *********************** |
- Add an Integration: Select the integration(s) you'd like to add.
- Configure General Information: OPTIONAL: You can use the following fields to provide additional information about your configuration.
| Field | Description | Example |
|---|---|---|
Name (optional) | Uniquely identifiable attribute of the configuration to delineate other similar configurations with the existing organization. | DMZ network |
Contact Person (optional) | A placeholder to input a name or email address of a contact associated with the integration. | Jane Doe |
Link to Console (optional) | A placeholder to input a link to the console of the product Aurora ASM is integrating with for quick reference and access when configuring or editing the integration. | www.product.com/devices |
Email me about frequent errors | Select this toggle to receive an email whenever an Integration has a ≥30% error rate in a 24-hour period. | n/a |
- Activate Config: Select "Activate" to enable this configuration and begin pulling data.
External Documentation
Creating credentials
You'll be asked to provide source credentials in the form of a Client ID/Secret that Aurora ASM will use to connect to Wiz. The client ID/Secret are associated with a service account that will be used and can be created by following the steps in Access Management – Service Accounts.
Note: To create a Service Account, you must be logged in as a Wiz user with Write (W) permission on service accounts. Project-scoped roles can create Service Accounts only on their own Projects.
Required Permissions
Please refer to the following instructions for configuring permissions for:
API Documentation
Contact Us
If you're having problems configuring an Integration, or if you've found something wrong in this document, please email us at [email protected].
Updated 14 days ago
