ZeroHour
Wiz Blogpublished ()ingested Gil Nahari1

Investing Together: Wiz Defend and Google Security Operations

infoToolsimportance 28
AI summary · glm-5.3

Wiz ships a Content Pack for Google Security Operations enabling shared investigations, Blue Agent AI analysis, bidirectional sync and cloud telemetry streaming.

Wiz announced deeper integration between Wiz Defend and Google Security Operations via a shared data model and an official Wiz Content Pack with out-of-the-box rules, dashboards, search queries, playbooks, and response policies. Wiz Blue Agent AI-powered threat investigations, correlating cloud context, runtime signals, and identity data, are now accessible directly within Google SecOps. Status, severity, and comments bidirectionally sync in real time, and sensor runtime events can be streamed into Google SecOps for hunting and retention.

  • Wiz Content Pack delivers rules, dashboards, queries, playbooks in Google SecOps, one-click enable
  • Blue Agent AI investigations with auditable verdicts now viewable in Google SecOps
  • Bidirectional real-time sync of status, severity, and comments across platforms
  • Sensor runtime telemetry streams into Google SecOps for hunting and retrospective analysis
Full article590 words · extracted from wiz.io · click to collapse

The AI era is putting new pressure on security teams to detect, investigate, and respond faster. As we explored in Pillar 4 of our AI Threat Readiness Framework, keeping pace with AI-driven threats requires comprehensive context, automated investigation, and response that can move as fast as the threat itself. But speed isn’t just about what one security tool can do- it’s also about removing the friction between the tools teams rely on every day. When investigations span multiple platforms, context and workflows must move seamlessly between them.

That’s why we’re continuing to invest in the integration between Wiz Defend and Google Security Operations. We’re bringing Wiz’s deep cloud context and analysis capabilities into Google Security Operations, streamlining the experience across both platforms. This will allow analysts to investigate Wiz threats in the platform they already use and help security teams work faster, wherever they choose to investigate. 

A shared data model across platforms

Wiz Defend and Google Security Operations are now working across a shared data model, allowing teams to investigate alerts directly within either platform. The official Wiz Content Pack, now available for Google Security Operations customers, provides access to all out-of-the-box Wiz content, including rules, dashboards, search queries, playbooks, and response policies. 

The integration is available with a single click, allowing teams to investigate Wiz threats directly in Google Security Operations. Now, analysts working across both platforms can work from a single, unified investigation, instead of triaging disconnected alerts across two tools.

The Wiz Content Pack is now available in Google Security Operations

Accelerate Google Security Operations investigations with Blue Agent analysis

The Wiz Blue Agent brings AI-powered threat investigation to every Wiz threat, automatically correlating cloud context, runtime signals, identity data, and other evidence to understand what happened and determine whether a threat is actually malicious. Trained on a knowledge base maintained by our Research and Customer Incident Response teams, Blue goes beyond surface-level triage, investigating like a trained incident responder by determining root cause, correlating data, and drawing conclusions from information available in the environment. Analysts can review and audit the investigation and verdict, helping them improve MTTR while maintaining accuracy. 

Blue Agent threat analysis is now available directly in Google Security Operations. For threats that Blue has investigated, analysts can access those findings directly in Google Security Operations without leaving their existing workflow. 

Playbooks are now available to fetch Wiz Blue Agent Analysis
Teams can automatically view Blue Agent analysis in Google Security Operations cases

Always current, wherever you work

Status, severity, and comments now bidirectionally sync between Wiz threats and Google Security Operations cases in real time, so teams always have the latest information, regardless of where they’re working. Deep links make it easy to move between the platforms, giving analysts the flexibility to go deeper in either while keeping the investigation connected.

See status, severity, and comments across both platforms

Your cloud telemetry, in one place

Sensor runtime events can now be streamed directly into Google Security Operations, giving teams the ability to hunt, investigate, and retain cloud telemetry across both platforms. For conducting retrospective analysis or proactive threat hunting, teams can access their cloud runtime data directly in the platform where they already work.

Get started

Our teams are continuing to work closely together and deepen the integration between Wiz Defend and Google Security Operations. We’re focused on making it easy for customers to work across both platforms with workflows that work seamlessly between the two. Try it yourself by enabling the Wiz Content Pack and exploring the new integration.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.wiz.io/blog/wiz-defend-and-google-security-operations