Wiz
Agentless cloud security with bidirectional Issue mirroring, status sync, comment sync, and due-date sync between Wiz and Cortex XSOAR.
- Category
- Utilities
- Pack
- Wiz
Configuration parameters
- incidentType — Incident type
- credentials — Service Account ID (required)
- auth_endpoint — Authentication Endpoint
- api_endpoint — API Endpoint (required)
- incidentFetchInterval — Incidents Fetch Interval
- first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- max_fetch — Max Issues to Fetch
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- severity — Issue severity to fetch
- status — Issue status to fetch
- issue_type — Issue type to fetch
- mirror_direction — Incident Mirror Direction
- mirror_limit — Mirror API page size
- comment_tag — Tag for comment mirroring
Commands (20)
- get-mapping-fields — Returns the list of fields for an incident type. Called by the mirroring engine, not for manual use.
- get-modified-remote-data — Get the list of incidents modified since the last update. Called by the mirroring engine, not for manual use.
- get-remote-data — Get remote data for a single incident. Called by the mirroring engine, not for manual use.
- update-remote-system — Push local changes to Wiz. Called by the mirroring engine, not for manual use.
- wiz-clear-issue-due-date — Clear a due date on a Wiz Issue.
- wiz-clear-issue-note — Clear a note from a Wiz Issue.
- wiz-copy-to-forensics-account — Copy VM's Volumes to a Forensics Account.
- wiz-get-issue — Get the details of a Wiz Issue Id.
- wiz-get-issue-evidence — Get the Wiz Issue evidence.
- wiz-get-issues — Get the Issues on cloud resources.
- wiz-get-project-team — Get the Project Owners and Security Champions details.
- wiz-get-resource — Get details of a resource.
- wiz-get-resources — Get details of resources.
- wiz-issue-in-progress — Set a Wiz Issue to in progress.
- wiz-reject-issue — Reject a Wiz Issue.
- wiz-reopen-issue — Reopen a Wiz Issue.
- wiz-rescan-machine-disk — DEPRECATED.
- wiz-resolve-issue — Resolve a Wiz Threat Detection Issue. For non-Threat-Detection issues (Toxic Combination, Cloud Configuration, Attack Surface) use wiz-reject-issue — those types are auto-resolved by Wiz when the underlying problem is fixed and cannot be manually resolved.
- wiz-set-issue-due-date — Set a due date on a Wiz Issue.
- wiz-set-issue-note — Set a note on a Wiz Issue.