Investing Together: Wiz Defend and Google Security Operations

Continuing to deepen the integration between Wiz Defend and Google Security Operations, helping teams work faster wherever they choose to investigate

The AI era is putting new pressure on security teams to detect, investigate, and respond faster. As we explored in Pillar 4 of our AI Threat Readiness Framework, keeping pace with AI-driven threats requires comprehensive context, automated investigation, and response that can move as fast as the threat itself. But speed isn’t just about what one security tool can do- it’s also about removing the friction between the tools teams rely on every day. When investigations span multiple platforms, context and workflows must move seamlessly between them.

That’s why we’re continuing to invest in the integration between Wiz Defend and Google Security Operations. We’re bringing Wiz’s deep cloud context and analysis capabilities into Google Security Operations, streamlining the experience across both platforms. This will allow analysts to investigate Wiz threats in the platform they already use and help security teams work faster, wherever they choose to investigate. 

A shared data model across platforms

Wiz Defend and Google Security Operations are now working across a shared data model, allowing teams to investigate alerts directly within either platform. The official Wiz Content Pack, now available for Google Security Operations customers, provides access to all out-of-the-box Wiz content, including rules, dashboards, search queries, playbooks, and response policies. 

The integration is available with a single click, allowing teams to investigate Wiz threats directly in Google Security Operations. Now, analysts working across both platforms can work from a single, unified investigation, instead of triaging disconnected alerts across two tools.

The Wiz Content Pack is now available in Google Security Operations

Accelerate Google Security Operations investigations with Blue Agent analysis

The Wiz Blue Agent brings AI-powered threat investigation to every Wiz threat, automatically correlating cloud context, runtime signals, identity data, and other evidence to understand what happened and determine whether a threat is actually malicious. Trained on a knowledge base maintained by our Research and Customer Incident Response teams, Blue goes beyond surface-level triage, investigating like a trained incident responder by determining root cause, correlating data, and drawing conclusions from information available in the environment. Analysts can review and audit the investigation and verdict, helping them improve MTTR while maintaining accuracy. 

Blue Agent threat analysis is now available directly in Google Security Operations. For threats that Blue has investigated, analysts can access those findings directly in Google Security Operations without leaving their existing workflow. 

Playbooks are now available to fetch Wiz Blue Agent Analysis
Teams can automatically view Blue Agent analysis in Google Security Operations cases

Always current, wherever you work

Status, severity, and comments now bidirectionally sync between Wiz threats and Google Security Operations cases in real time, so teams always have the latest information, regardless of where they’re working. Deep links make it easy to move between the platforms, giving analysts the flexibility to go deeper in either while keeping the investigation connected.

See status, severity, and comments across both platforms

Your cloud telemetry, in one place

Sensor runtime events can now be streamed directly into Google Security Operations, giving teams the ability to hunt, investigate, and retain cloud telemetry across both platforms. For conducting retrospective analysis or proactive threat hunting, teams can access their cloud runtime data directly in the platform where they already work.

Get started

Our teams are continuing to work closely together and deepen the integration between Wiz Defend and Google Security Operations. We’re focused on making it easy for customers to work across both platforms with workflows that work seamlessly between the two. Try it yourself by enabling the Wiz Content Pack and exploring the new integration.

Continue reading

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management