Wiz integration
Get an exploitability verdict for Wiz container image vulnerabilities, and optionally add it to the finding in Wiz as a note.
Integration details
Primary category
Cloud Security
Sync direction
Wiz ↔ Konvu
Konvu imports Wiz container image findings once a day. With push turned on, Konvu adds its assessment to each finding in Wiz as a note and leaves status and severity alone.
Status
Available
Which Wiz container vulnerabilities can be exploited?
Wiz shows which container images carry vulnerable packages across your cloud. Konvu takes those container image findings, checks whether each vulnerability can be exploited in the workload, and returns a verdict with evidence. If you turn on push, Konvu adds its assessment to the finding in Wiz as a note, exploitable or not exploitable, without changing its status or severity.
Wiz findings Konvu analyzes
Container
Wiz container image vulnerabilities
Vulnerabilities Wiz found in container images. One connection covers the whole Wiz tenant.
Not imported today
- Wiz SCA findings
- Host and virtual machine findings
- Kubernetes findings
Access and setup
A Wiz service account (client ID and secret), plus your API endpoint and token URL. Konvu checks read access before it saves the connection, and it creates and updates reports in your tenant to export findings.
To read findings
read:vulnerabilitiescreate:reportsread:reportsupdate:reports
To write back
update:vulnerabilities, only if you turn on push
How Konvu investigates Wiz findings
What Konvu receives
The Wiz finding: the container image, the vulnerable package and version, and the CVE.
What Konvu checks
- Whether the vulnerable package is used by the software that runs in the image, or only installed.
- The conditions the CVE needs, such as a running service, an exposed port, or a specific configuration.
- Whether input an attacker controls can reach the vulnerable code.
What decides the verdict
Konvu returns exploitable or false positive, with the reasoning behind it: what runs in the image, the conditions it tested, and what settled the call. When the evidence does not settle it, the finding is left without a verdict rather than guessed.
Illustrative example
An OpenSSH finding from Wiz
A made-up service, written to show how an investigation reads. Not a customer result.
- 1
Scanner finding
Wiz reports CVE-2024-6387, known as regreSSHion, in an unpatched openssh-server package inside the image of a payments API.
- 2
Application context
The image runs a single Node.js process. The vulnerability is in the OpenSSH server daemon, sshd, and needs sshd to be running and reachable on the network.
- 3
Investigation
Konvu checks the image entrypoint and command, which start only the Node.js process, and finds no init script or process manager that launches sshd. The container exposes only the application port.
- 4
Verdict
False positive for this workload. The package is installed, but the vulnerable daemon never runs.
- 5
Evidence
The entrypoint and command, the exposed ports, and the check for anything that starts sshd.
- 6
Where it ends up
The verdict and evidence are recorded in Konvu. With push on, the finding in Wiz gets a "Not exploitable" note from Konvu and stays open. Removing openssh-server from the image is still a sensible cleanup.
Writeback and controls
What changes in Wiz
- With push on, Konvu adds a note to the finding in Wiz saying whether it is exploitable, with the assessment behind it. Later syncs update that note instead of adding another.
- If a later assessment comes back inconclusive, Konvu removes its earlier note.
Who triggers it
Push is off by default. When an admin turns on "Push results directly to Wiz", Konvu sends notes automatically as verdicts come in. With push off, you can still send an assessment manually.
What stays with your team
- Resolving, rejecting, or re-prioritizing findings in Wiz. Konvu never changes status or severity.
- Findings already resolved or rejected in Wiz, and findings with a note someone on your team wrote. Konvu skips both.
Evaluation questions
The technical detail
More integrations
View allAWS Inspector
Check whether the vulnerabilities AWS Inspector finds in your ECR container images are exploitable.
- Cloud Security
AWS Security Hub
Get exploitability verdicts for the AWS Inspector container findings in Security Hub, read directly from Inspector.
- Cloud Security
Check Point CloudGuard
Filter CloudGuard posture findings to focus on exploitable security gaps.
- Cloud Security
Datadog Cloud Security
Prioritize Datadog CSM findings with environment-specific exploitability analysis.
- Cloud Security
Google Cloud Security Command Center
Triage SCC findings with exploit data across GCP assets and vulnerabilities.
- Cloud Security
Lacework
Focus Lacework anomaly alerts on hosts with exploitable vulnerabilities.
- Cloud Security