Back to integrations
    Cloud Security

    Wiz integration

    Get an exploitability verdict for Wiz container image vulnerabilities, and optionally add it to the finding in Wiz as a note.

    Integration details

    Primary category

    Cloud Security

    Sync direction

    Wiz ↔ Konvu

    Konvu imports Wiz container image findings once a day. With push turned on, Konvu adds its assessment to each finding in Wiz as a note and leaves status and severity alone.

    Status

    Available

    Which Wiz container vulnerabilities can be exploited?

    Wiz shows which container images carry vulnerable packages across your cloud. Konvu takes those container image findings, checks whether each vulnerability can be exploited in the workload, and returns a verdict with evidence. If you turn on push, Konvu adds its assessment to the finding in Wiz as a note, exploitable or not exploitable, without changing its status or severity.

    Wiz findings Konvu analyzes

    Container

    Wiz container image vulnerabilities

    Vulnerabilities Wiz found in container images. One connection covers the whole Wiz tenant.

    Not imported today

    • Wiz SCA findings
    • Host and virtual machine findings
    • Kubernetes findings

    Access and setup

    A Wiz service account (client ID and secret), plus your API endpoint and token URL. Konvu checks read access before it saves the connection, and it creates and updates reports in your tenant to export findings.

    To read findings

    • read:vulnerabilities
    • create:reports
    • read:reports
    • update:reports

    To write back

    • update:vulnerabilities, only if you turn on push

    How Konvu investigates Wiz findings

    What Konvu receives

    The Wiz finding: the container image, the vulnerable package and version, and the CVE.

    What Konvu checks

    • Whether the vulnerable package is used by the software that runs in the image, or only installed.
    • The conditions the CVE needs, such as a running service, an exposed port, or a specific configuration.
    • Whether input an attacker controls can reach the vulnerable code.

    What decides the verdict

    Konvu returns exploitable or false positive, with the reasoning behind it: what runs in the image, the conditions it tested, and what settled the call. When the evidence does not settle it, the finding is left without a verdict rather than guessed.

    Illustrative example

    An OpenSSH finding from Wiz

    A made-up service, written to show how an investigation reads. Not a customer result.

    1. 1

      Scanner finding

      Wiz reports CVE-2024-6387, known as regreSSHion, in an unpatched openssh-server package inside the image of a payments API.

    2. 2

      Application context

      The image runs a single Node.js process. The vulnerability is in the OpenSSH server daemon, sshd, and needs sshd to be running and reachable on the network.

    3. 3

      Investigation

      Konvu checks the image entrypoint and command, which start only the Node.js process, and finds no init script or process manager that launches sshd. The container exposes only the application port.

    4. 4

      Verdict

      False positive for this workload. The package is installed, but the vulnerable daemon never runs.

    5. 5

      Evidence

      The entrypoint and command, the exposed ports, and the check for anything that starts sshd.

    6. 6

      Where it ends up

      The verdict and evidence are recorded in Konvu. With push on, the finding in Wiz gets a "Not exploitable" note from Konvu and stays open. Removing openssh-server from the image is still a sensible cleanup.

    Writeback and controls

    What changes in Wiz

    • With push on, Konvu adds a note to the finding in Wiz saying whether it is exploitable, with the assessment behind it. Later syncs update that note instead of adding another.
    • If a later assessment comes back inconclusive, Konvu removes its earlier note.

    Who triggers it

    Push is off by default. When an admin turns on "Push results directly to Wiz", Konvu sends notes automatically as verdicts come in. With push off, you can still send an assessment manually.

    What stays with your team

    • Resolving, rejecting, or re-prioritizing findings in Wiz. Konvu never changes status or severity.
    • Findings already resolved or rejected in Wiz, and findings with a note someone on your team wrote. Konvu skips both.

    Evaluation questions