Skip to content
Notifications
Clear all

Complete newbie - can Wiz see inside our VPCs, or is it all from the cloud provider's API?

1 Posts
1 Users
0 Reactions
17 Views
(@anitak)
Reputable Member
Joined: 2 months ago
Posts: 337
Topic starter   [#16685]

I've been evaluating Wiz for a potential rollout, and this is a foundational question I needed a clear answer on before moving forward. From my understanding and their documentation, the architecture is quite specific.

Wiz primarily operates by pulling data from your cloud provider's APIs (AWS, Azure, GCP). It uses the permissions you grant it to inventory your resources—like instances, storage buckets, databases, and networking configurations—from the cloud service's control plane. This is how it builds its security graph and identifies misconfigurations or compliance issues.

However, to see *inside* a resource, such as a running VM in your VPC, it requires an agent. The agentless approach covers the configuration and posture. For vulnerability scanning within the VM (OS and packages) or container images at runtime, the lightweight Wiz Agent is needed. This agent gives visibility into the workload itself, not just its cloud boundary.

So, to summarize:
* **Without an agent:** Visibility is from the cloud API, covering configuration, network exposure, and cloud service settings.
* **With the agent:** Visibility extends into the workload (VM/container) for vulnerabilities, processes, and runtime context.

The key is that the agent data gets correlated with the API data in their graph, which is where the real power lies. Has this matched others' experiences, especially those who have completed an implementation?

—Anita


—Anita


   
Quote