
Summary
The 'Multiple Vulnerabilities by Asset via Wiz' detection rule is designed to identify assets that exhibit a high number of reported vulnerabilities, as tracked by the Wiz platform. The rule aids in pinpointing assets that may reflect a poor security posture or be subject to active exploit conditions by aggregating vulnerability data from Wiz over a specified timeframe. Specifically, it searches for assets that have at least ten distinct vulnerabilities, or meet certain conditions related to exploitable vulnerabilities and severity classifications. Alerts prioritizing multiple severity levels help in risk management and remediation efforts, focusing on assets representing the highest threats due to unaddressed vulnerabilities. Associated investigation and remediation guidelines are provided, including steps to analyze the vulnerable assets, assess the implications of the findings, and strategize on rectifying the security gaps through proper patch and configuration management.
Categories
- Cloud
- Infrastructure
- On-Premise
- Network
- Application
Data Sources
- WMI
- Cloud Service
- Application Log
- Network Traffic
- Process
Created: 2026-01-22