Wiz Schema#
graph LR
WizTenant -- RESOURCE --> WizFinding
WizTenant -- RESOURCE --> WizIssue
WizFinding#
Conditional Labels:
CVE(ontology label) whenhas_cveequalstrue. A cross-provider CVE resource in Cartography’s ontology.
SecurityIssue(ontology label) whenis_security_issueequalstrue. A cross-provider SecurityIssue resource in Cartography’s ontology.
Properties#
Ontology-generated fields are shown in italics.
Field |
Index |
Description |
|---|---|---|
id |
Yes |
Wiz finding ID. |
firstseen |
Timestamp when a sync job first created this node. |
|
lastupdated |
Yes |
Timestamp when this Wiz finding was last seen. |
actor_ids |
Wiz actor IDs associated with the finding. |
|
actor_names |
Wiz actor names associated with the finding. |
|
cloud_account_ids |
Wiz cloud account IDs associated with the finding. |
|
cloud_account_names |
Wiz cloud account names associated with the finding. |
|
cloud_organization_ids |
Wiz cloud organization IDs associated with the finding. |
|
cloud_organization_names |
Wiz cloud organization names associated with the finding. |
|
created_at |
Timestamp when Wiz created the finding. |
|
cve_description |
CVE description associated with the finding. |
|
cve_id |
Yes |
CVE ID associated with the finding. |
cvss_severity |
Yes |
CVSS severity associated with the finding. |
description |
Wiz finding description. |
|
detailed_name |
Detailed vulnerability or finding name from Wiz. |
|
detection_method |
Wiz detection method for the finding. |
|
exploitability_score |
CVSS exploitability score for the finding. |
|
finding_type |
Yes |
Wiz finding family. |
first_detected_at |
Timestamp when Wiz first detected the finding. |
|
first_seen_at |
Timestamp when Wiz first saw the finding. |
|
fixed_version |
Fixed package or component version. |
|
has_cisa_kev_exploit |
Whether Wiz reports the CVE in the CISA KEV catalog. |
|
has_cve |
Whether the finding has a CVE identifier. |
|
has_exploit |
Whether Wiz reports a known exploit. |
|
impact_score |
CVSS impact score for the finding. |
|
is_security_issue |
Whether the finding is a non-CVE security issue. |
|
last_detected_at |
Timestamp when Wiz last detected the finding. |
|
link |
External reference URL for the finding. |
|
location_path |
Affected file or runtime path for the finding. |
|
name |
Yes |
Wiz finding name. |
origins |
Wiz origins associated with the finding. |
|
portal_url |
Wiz portal URL for the finding. |
|
project_ids |
Yes |
Wiz project IDs associated with the finding. |
project_names |
Wiz project names associated with the finding. |
|
remediation |
Wiz remediation guidance for the finding. |
|
resolution_reason |
Reason Wiz marked the finding resolved. |
|
resolved_at |
Timestamp when Wiz resolved the finding. |
|
resource_cloud_platform |
Cloud platform of the affected resource. |
|
resource_external_id |
Yes |
Provider-native ID of the affected resource. |
resource_id |
Yes |
Wiz ID of the affected resource. |
resource_name |
Name of the affected Wiz resource. |
|
resource_native_type |
Cloud-native type of the affected resource. |
|
resource_region |
Cloud region of the affected resource. |
|
resource_status |
Wiz status of the affected resource. |
|
resource_type |
Yes |
Wiz type of the affected resource. |
result |
Yes |
Wiz finding result. |
rule_as_control |
Whether Wiz treats the rule as a control. |
|
rule_builtin |
Whether the Wiz rule is built in. |
|
rule_description |
Wiz rule description associated with the finding. |
|
rule_graph_id |
Yes |
Wiz graph rule ID associated with the finding. |
rule_id |
Yes |
Wiz rule ID associated with the finding. |
rule_name |
Wiz rule name associated with the finding. |
|
score |
CVSS score associated with the finding. |
|
severity |
Yes |
Wiz finding severity. |
status |
Yes |
Wiz finding status. |
subscription_external_id |
Yes |
Provider-native subscription ID for the affected resource. |
subscription_id |
Yes |
Wiz subscription ID for the affected resource. |
subscription_name |
Subscription name for the affected resource. |
|
target_external_id |
External ID of the Wiz finding target. |
|
target_object_provider_unique_id |
Yes |
Provider-unique ID of the Wiz finding target. |
triggering_event_ids |
Wiz triggering event IDs for the finding. |
|
updated_at |
Timestamp when Wiz last updated the finding. |
|
vendor_severity |
Yes |
Vendor-reported severity for the finding. |
version |
Affected package or component version. |
|
_ont_base_score |
Yes |
Normalized field sourced from |
_ont_base_severity |
Yes |
Normalized field sourced from |
_ont_cve_id |
Yes |
Normalized field sourced from |
_ont_description |
Normalized field sourced from |
|
_ont_exploitability_score |
Yes |
Normalized field sourced from |
_ont_first_seen |
Yes |
Normalized field sourced from |
_ont_impact_score |
Yes |
Normalized field sourced from |
_ont_severity |
Yes |
Normalized field sourced from |
_ont_source |
Module that populated this node’s ontology fields. |
|
_ont_status |
Yes |
Normalized field sourced from |
_ont_title |
Yes |
Normalized field sourced from |
_ont_type |
Yes |
Normalized field sourced from |
Relationships#
(:WizFinding)-[:LINKED_TO]->(:CVE)(:WizTenant)-[:RESOURCE]->(:WizFinding)
WizIssue#
Ontology Mapping: This node uses the ontology label
SecurityIssue.
Properties#
Ontology-generated fields are shown in italics.
Field |
Index |
Description |
|---|---|---|
id |
Yes |
Wiz issue ID. |
firstseen |
Timestamp when a sync job first created this node. |
|
lastupdated |
Yes |
Timestamp when this Wiz issue was last seen. |
control_description |
Wiz control description associated with the issue. |
|
control_id |
Yes |
Wiz control ID associated with the issue. |
control_name |
Wiz control name associated with the issue. |
|
created_at |
Timestamp when Wiz created the issue. |
|
due_at |
Wiz issue due timestamp. |
|
issue_type |
Yes |
Wiz issue type. |
name |
Yes |
Wiz issue name. |
project_ids |
Yes |
Wiz project IDs associated with the issue. |
project_names |
Wiz project names associated with the issue. |
|
resolution_recommendation |
Wiz remediation guidance for the issue. |
|
resolved_at |
Timestamp when Wiz resolved the issue. |
|
resource_cloud_platform |
Cloud platform of the affected resource. |
|
resource_external_id |
Yes |
Provider-native ID of the affected resource. |
resource_id |
Yes |
Wiz ID of the affected resource. |
resource_name |
Name of the affected Wiz resource. |
|
resource_native_type |
Cloud-native type of the affected resource. |
|
resource_type |
Yes |
Wiz type of the affected resource. |
service_ticket_urls |
Service ticket URLs associated with the issue. |
|
severity |
Yes |
Wiz issue severity. |
source_rule_id |
Yes |
Wiz source rule ID for the issue. |
source_rule_name |
Wiz source rule name for the issue. |
|
status |
Yes |
Wiz issue status. |
status_changed_at |
Timestamp when the Wiz issue status last changed. |
|
updated_at |
Timestamp when Wiz last updated the issue. |
|
_ont_first_seen |
Yes |
Normalized field sourced from |
_ont_severity |
Yes |
Normalized field sourced from |
_ont_source |
Module that populated this node’s ontology fields. |
|
_ont_status |
Yes |
Normalized field sourced from |
_ont_title |
Yes |
Normalized field sourced from |
_ont_type |
Yes |
Normalized field sourced from |
Relationships#
(:WizTenant)-[:RESOURCE]->(:WizIssue)
WizTenant#
Ontology Mapping: This node uses the ontology label
Tenant.
Properties#
Field |
Index |
Description |
|---|---|---|
id |
Yes |
Stable Wiz tenant identifier. |
firstseen |
Timestamp when a sync job first created this node. |
|
lastupdated |
Yes |
Timestamp when this Wiz tenant was last seen. |
graphql_url |
Wiz GraphQL API endpoint used for this tenant. |
Relationships#
(:WizTenant)-[:RESOURCE]->(:WizFinding)(:WizTenant)-[:RESOURCE]->(:WizIssue)