惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
美团技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客
J
Java Code Geeks
Jina AI
Jina AI
罗磊的独立博客
宝玉的分享
宝玉的分享
S
SegmentFault 最新的问题
D
DataBreaches.Net
博客园 - 叶小钗
腾讯CDC
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Last Week in AI
Last Week in AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Google DeepMind News
Google DeepMind News
阮一峰的网络日志
阮一峰的网络日志
B
Blog
V
Visual Studio Blog
雷峰网
雷峰网
博客园 - 【当耐特】
Apple Machine Learning Research
Apple Machine Learning Research
Engineering at Meta
Engineering at Meta
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
CTO Point of View: Why Wiz is launching a Runtime Sensor
Ami Luttwak · 2023-06-05 · via Wiz Blog | RSS feed

Three years ago, we set out to help security and dev teams transform their cloud security operating model by simplifying prevention. Since then, we have helped teams gain immediate visibility to everything they build and run in the cloud, improve their security posture, and dramatically reduce risk. This approach has enabled them to build faster and more securely than ever before.

The number one priority in cloud is risk reduction

In the cloud, attacks happen in minutes. Attackers can start exfiltrating your critical data almost immediately after they discover an exposed database. If you wait for an alert on data exfiltration, it is already too late. This makes prevention and security posture management priority number one. Prevention requires an always-on, full-coverage, scan-everything strategy – and this can only be achieved with agentless technologies that make coverage the default rather than opt-in.

Wiz has introduced an agentless, API-centered approach to seamlessly scan any workload and give full visibility of cloud environments across VMs, containers, serverless and PaaS. Our unique Security Graph provides deep cloud context, and enables organizations to triage and correlate critical attack paths, producing high-fidelity results that any security or development team can interpret and act upon immediately.

We are excited to see how this approach has already become the industry standard for reducing risk in the cloud.

Bringing Wiz to Cloud Detection and Response

After establishing posture as their cornerstone, organizations can build securely by design in the cloud. Then organizations can turn to residual risk: cloud detection and response controls.

Detecting cloud attacks requires deep context that spans both cloud and workload. Last year we released our CDR module, which focuses on analyzing cloud and Kubernetes events, enriching them with the Security Graph context for deep prioritization and blast radius analysis. With the Wiz Runtime Sensor signal, we can now complete the additional workload runtime context of network, process, and memory for complete end-to-end visibility of cloud attacks.

Revolutionizing threat detection in the cloud

Threat detection in the cloud today faces a similar set of challenges as those that Wiz set out to solve in the posture space: the complexity of cloud environments presents a new challenge for security teams. Traditional detection tools were created for on-prem and adopt a workload-only focus that produces siloed, contextless alerts. On top of that, SOC teams struggle to complete the picture due to lack of cloud context and visibility requiring constant dev team involvement.

The Wiz Runtime Sensor – born for cloud

Wiz CDR takes a cloud-first approach to detection and response. By starting from a deep analysis of cloud context using the Wiz Security Graph, then analyzing cloud and Kubernetes events, and only then incorporating runtime signals, we have created a lightweight runtime component truly meant for cloud.

  • Lightweight – Most signals, including vulnerabilities, host configurations and more, are still collected from our agentless API-based scan. We only use the Runtime Sensor to collect true runtime signals such as runtime network use, processes, and memory use. This allows the Runtime Sensor to remain a lightweight eBPF agent.

  • Breaking the silos – The Wiz Runtime Sensor generates workload signals that are well-integrated with the surrounding cloud and Kubernetes activity, as well as the Wiz Security Graph context to uncover attacker movement across layers and within the cloud environment, enabling immediate assessment of incident blast radius and impact. For example, a suspicious process on a highly privileged machine that can access buckets with sensitive data can be immediately prioritized.

  • Designed for cloud-native workloads – the Wiz Runtime Sensor was specifically designed to protect cloud-native, highly ephemeral workloads, which sets it apart from traditional solutions that are focused on server or endpoint host-centric protection. When malicious activity occurs on short-lived containers or other ephemeral resources, the Wiz Runtime Sensor detects it and associates the detection and response to the specific workload (e.g., a Kubernetes Deployment), enabling accurate surface and scope for responding to the threat.

Wiz CDR can also consume signals from existing EDR and runtime solutions, enabling organizations to choose their own stack and extend it with cloud context.

With the added Wiz Runtime Sensor signal, and the capability to consume signals from existing EDR and runtime solutions, Wiz now covers the full deployment pipeline from code to runtime, across all cloud layers from workload to infrastructure, enabling us to bring true cloud context to threat detection.

If you want to learn more about the Wiz Runtime Sensor, read the Sensor launch blog.