๐ฃ๐ฟ๐ผ๐ฑ๐๐ฐ๐ ๐๐ฝ๐ฑ๐ฎ๐๐ฒ: Data flow diagrams are now interactive. Across ๐ฒ๐๐ฒ๐ฟ๐ cloud service we cover.
Hereโs whatโs new:
โ ๐๐ผ๐๐ฒ๐ฟ any component to surface its threats
โ ๐ฃ๐ถ๐ป the popup to keep it visible while you explore
โ ๐๐น๐ถ๐ฐ๐ธ through to the full threat detail
For our customers, log in and try it across every service youโre covered for.
Try it with the Amazon S3 model: https://t.co/5ZEs4bfecO.
#ProductUpdate #DataFlowDiagrams #CloudSecurity #AWS #S3
CloudTrail is where your regulators, your SIEM, and your auditors all look. So when a service starts quietly writing customer details into it, that's a problem.
Two things worth doing this week:
1๏ธโฃReview where CloudTrail logs are stored and who can read them
2๏ธโฃSpot-check what the services handling your most sensitive data are actually writing to the event record
We made our cloud security research more explorable.
Browse our cloud security research for Amazon S3 (also covers AWS S3 glacier), Azure Storage (also Azure blobs, files), BigQuery (BigQuery Data Transfer Service, Analytics Hub).
Each service includes:
โ threat scenarios with data flow diagrams
โ prioritised controls mapped to 180+ frameworks
โ continuous updates as cloud providers ship changes
View now ๐
https://t.co/7hO8u330ty
#cloudsecurity #multicloud #trustoncloud #ai #onboarding
66% of your cloud controls aren't covered by default Wiz rules. we know because we mapped every single one across AWS S3, Azure Storage, and GCP BigQuery.
then we open-sourced 50+ custom rules to close it. used by 4 global systemic banks. free on Github: https://t.co/EJ2SrXFBqn
#cloudsecurity #CNAPP #infosec #Cloudcontrols
5/ Each package includes: mapping of default Wiz rules โ our controls + Rego CCRs for every gap. All open-source. Learn more: https://t.co/VrBoNmVvSs
1/ We just open-sourced @wiz_io CCR packages for AWS S3, Azure Storage & GCP BigQuery.
Default Wiz coverage: ~34% for these services. Here's what's missing and why it matters for regulated enterprises ๐งต
๐จ Using AWS "What's New" #RSS feed for cloud monitoring? You might be missing critical updates.
A few years back, our dashboards stayed green while we went blind to changes. Here's what happened ๐งต
Before the next re:Invent:
โ Pull daily during burst weeks
โ Use the API, not just RSS
โ Add completeness checks: make "missing updates" an alert, not an accident
(4/5)