All integrations
Wiz logo
// Data Integration · Cloud Security

Cracken + Wiz

Wiz reads your cloud accounts through the provider's APIs and snapshots to work out which resources are at risk. Cracken attacks the findings it raises. You get back the ones an attacker can turn into real impact.

Get started
// 01

Connecting Wiz

Connect with

A Wiz service-account client ID and client secret, plus your tenant's Wiz authentication (token) URL

Cadence

Syncs on a schedule — every 6 hours by default

Requires

The hosted connection service enabled on your deployment — always on for Cracken-hosted workspaces

// 02

What Cracken gets from Wiz

  • Cloud security posture findings with severity (critical, high, medium, low, info) and state (open, resolved, snoozed)

  • The cloud resource the finding sits on — resource type plus resource id or name

  • cve list with cvss_base_score, cvss_vector and cvss_version where Wiz carries them

  • device — hostnames, ipv4s, tags — landed as a Device node that contains the Finding

  • first_seen, last_seen and state_updated_at

  • solution, patchable, category and vulnerability_url

  • vendor_id and vendor_severity, Wiz's own labels beside the normalized ones

// 03

What Wiz does not do

Cracken reads Wiz's cloud and vulnerability findings only. Wiz Code, its code-scanning product, is not connected, so those findings never arrive. The connection is read-only and one action wide: there is no scan to trigger, and no way to resolve, ignore or reassign a Wiz issue from Cracken.

// 04

How Cracken uses Wiz

  1. 01

    Connect Wiz

  2. 02

    Sync the cloud findings

  3. 03

    Attack them in the account

  4. 04

    Confirm it connected

// 05

Frequently asked questions

Does Cracken need agents in my cloud accounts to use Wiz data?

No: Cracken reads Wiz's findings over its API with a service-account client ID, client secret, and authentication URL, and deploys nothing into your accounts.

Does Cracken change anything in Wiz?

No: it only lists cloud security findings; it doesn't resolve, snooze, or reopen issues, alter Wiz policies or the Security Graph, or launch scans.

“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”

Cybersecurity Engineer, red team · test-and-measurement manufacturer

Attack with real Wiz context.

See how Cracken works what Wiz already knows into attack paths it proves end to end.