AWS DevOps Agent now integrates with Wiz via the Model Context Protocol (MCP) to bring security context into operational incident investigations. When an alert fires, the agent automatically queries Wiz's security graph alongside operational telemetry to determine whether a CPU spike or latency anomaly is a performance issue or an active security incident. The integration surfaces CVE data, exploitability status, internet exposure, active threats, and malware findings without requiring engineers to manually switch tools. Three triage scenarios are covered: no security findings (operational issue), confirmed vulnerability or active threat (security incident requiring isolation), and resource not monitored by Wiz (coverage gap flagged). Setup involves registering the Wiz remote MCP server in the AWS DevOps Agent console, allowlisting Wiz tools in an Agent Space, and choosing between an auto-run skill, a pre-built skill import, or a custom skill.

10m read timeFrom aws.amazon.com
Post cover image
Table of contents
AWS DevOps AgentWiz MCPBetter together: how combined context changes triageHow the integration works: the MCP bridgeGetting startedThe power of co-build: extending context through MCPConclusionAbout the Authors
25 Impressions