← Back to News

Add security context to operational investigations with AWS DevOps Agent and Wiz

At 2 AM, your on-call engineer gets paged. CPU is spiking on a critical service, latency is climbing, and customers are starting to complain. Before diving into logs and metrics, they face a crucial question: Is this a legitimate operational problem, or am I looking at a security incident? Without proper context, investigating the wrong angle wastes precious time. The collaboration between AWS DevOps Agent and Wiz security platform addresses exactly this problem by automatically enriching operational alerts with security intelligence, helping teams distinguish between performance issues and potential breaches faster.

Here’s how it works technically. When you enable integration between DevOps Agent and Wiz, security context becomes available alongside your operational data. AWS DevOps Agent collects operational telemetry from your infrastructure—CPU, memory, network, application metrics—while Wiz simultaneously pulls security insights about your cloud resources, including vulnerability data, misconfigurations, and suspicious activity patterns. When an alert fires, the combined context shows not just what’s happening operationally, but also whether affected resources have known vulnerabilities, unusual access patterns, or configuration drift that might indicate compromise. For example, if that CPU spike coincides with Wiz detecting unauthorized IAM role assumption or unexpected network connections from your instances, you’re immediately aware this isn’t just a capacity issue.

The practical impact matters because incident response time directly affects blast radius. A security incident that takes 30 minutes longer to identify can mean the difference between a contained issue and lateral movement through your environment. By having security context baked into operational dashboards, you reduce mean time to detection (MTTD) and avoid the common trap of treating security issues as performance problems. A developer seeing elevated database connections might normally tune queries, but with Wiz context showing those connections originated from a compromised credential, they instead trigger incident response instead. This isn’t just faster—it’s more accurate.

The real value emerges in mature DevOps environments where operational and security teams use different tools and speak different languages. An on-call engineer who understands operational metrics but not security scanning now has translation built in. You get simpler alert fatigue reduction since fewer false alarms make it to the engineering team, and when engineers do investigate, they’re better equipped to make the right decisions. For teams running multi-account AWS environments with hundreds of microservices, this kind of integrated context becomes essential for keeping incident response from becoming a coordination nightmare.

Source
↗ AWS DevOps & Developer Productivity Blog