tools
Wiz Defend
Wiz Defend detects, investigates, and responds to threats across cloud workloads, identities, data, and AI applications.

Wiz Defend provides runtime threat detection and response using cloud and SaaS logs, runtime signals, and Wiz Security Graph context. It helps security operations teams identify attack paths, investigate incidents, and assess potential blast radius.
The product includes Blue Agent for automated threat investigation, cloud-native containment playbooks, identity and data detection, and AI runtime protection. The Wiz Sensor is an add-on for runtime workload protection, and pricing is provided through a custom quote.
Features
- Correlates cloud logs, runtime signals, and risk context
- Maps telemetry coverage to MITRE ATT&CK
- Detects threats across AI workloads, models, and agentic applications
- Uses Blue Agent to investigate threats and produce a verdict
- Provides cloud-native containment playbooks and root-cause analysis
- Automates response actions with Wiz Workflows
- Detects identity anomalies and unusual access to sensitive data
- Wiz Sensor adds eBPF runtime workload protection
Use cases
- Investigate cloud threats with correlated workload, identity, and cloud evidence
- Detect prompt injection, model exfiltration, and MCP server attacks
- Map telemetry gaps before an incident occurs
- Contain compromised workloads using automated response playbooks
- Identify anomalous identity activity and sensitive-data access
- Coordinate investigations with Google Security Operations