Skip to content
Secure Smarter — Solutions for Modern Threats

From AI-driven SecOps to cloud security automation, Foresite delivers fully managed and scalable security solutions tailored for enterprise, hybrid, and multi-cloud environments.

Why Foresite — Security Excellence, Your Way

From our Adaptive Security Model to our Google Cloud Premier SecOps Partnership, we combine deep expertise, purpose-built technology, and customer-first flexibility.

Google Cloud Security — delivered by Foresite,
Premier SecOps Partner

Combine Google’s native security power with Foresite’s expert-driven, AI-powered operations to secure your cloud and unlock business growth.

Foresite - Google Cloud SecOps Delivery Partner Badge
Two API scope groups from the Wiz integration for Google SecOps: read scopes run unattended, write scopes require a named practitioner to authorize
Stephen MullerSeptember 21, 202612 min read

Google Threat Intelligence in Wiz: What Actually Changed

TL;DR

Google Threat Intelligence now enriches findings inside the Wiz console, so cloud exposure data arrives with adversary context attached. That is deeper integration between two products, not a merger into one. Getting value from it still depends on who reads the enriched finding and what they are authorized to do next.

 

Foresite Cybersecurity is a Google Cloud Premier Partner, a Wiz Premier Partner, and the 2026 Google Cloud Security Partner of the Year for North America, delivering managed security operations through the Catalyst platform. We run both practices, which means when Google Threat Intelligence started showing up inside Wiz, our team had to answer a practical question before our customers asked it: does this change the architecture, or just the screen?

The screen. The architecture did not move.

 

What shipped

On August 4, 2026, Wiz confirmed that Google Threat Intelligence enrichment is live in the platform. Wiz findings are enriched with Mandiant frontline intelligence, crowdsourced intelligence from VirusTotal, and threat insights from Google. For malware findings, GTI supplies context beyond a verdict, which Wiz describes as helping teams understand the threat and prioritize response before an investigation begins. GTI's malicious AI Skill intelligence also flags risky open-source skills that AI agents can import. Wiz confirms this enrichment is available out of the box to all Wiz customers (Wiz, August 4, 2026).

Separately, Google and Wiz have started connecting Wiz Attack Surface Management to the GTI correlation engine so exposures can be matched against real-time adversary activity. That work is explicitly in progress. Google's own language is "we've begun integration efforts" and "we will continue to build towards native integration," with behavior-based guidance on critical risks described as planned rather than shipped (Google Cloud, July 7, 2026).

Wiz ASM maps external attack surface across cloud, AI, SaaS, and on-premises environments, then validates exploitability against vulnerabilities, misconfigurations, default credentials, and exposed secrets. The Wiz Red Agent scans those exposures with AI for logic-driven vulnerabilities traditional scanners miss: authentication bypasses, business logic flaws, multi-step attack chains (same source).

So: enrichment today, correlation next. Both halves are substantial. Putting Mandiant frontline intelligence and VirusTotal's crowdsourced corpus behind cloud findings is not a small piece of engineering. It is the kind of thing only a vendor holding both the intelligence and the platform can do.

 

Two products, still

It is worth being precise here, because the market is not.

Google completed its acquisition of Wiz on March 11, 2026 and said plainly that it would retain the Wiz brand, and that Wiz products would continue to work across AWS, Microsoft Azure, and Oracle Cloud (Google Cloud, March 11, 2026).

The GTI integration predates that. Wiz was named one of the first three partners in the Google Unified Security Recommended program on November 13, 2025, alongside CrowdStrike and Fortinet, with a forthcoming GTI integration already on the roadmap. Google framed the program as "founded on the belief that security ecosystems must be open and interoperable, empowering customers with choice" (Wiz, November 13, 2025).

That sequence is the point. The integration was designed as partner interoperability, months before the acquisition closed, and it shipped on that original footing. What arrived in August was the partnership completing, not the acquisition consolidating.

The July announcement carries two bylines, one from Google Threat Intelligence product management and one from Wiz product management. Two product teams, building something neither owns alone.

GTI appearing in Wiz is Wiz consuming a Google intelligence feed. It is not Wiz becoming Google Threat Intelligence. It is not GTI absorbing cloud posture management.

Two products, two jobs, two licensing conversations.

That matters commercially. We have already seen buyers assume adopting Wiz post-acquisition covers threat intelligence, or that a GTI subscription now delivers cloud posture. Neither is true. The enrichment is real and valuable, and it does not collapse a stack.

 

What it changes operationally

Cloud security teams do not lack findings. They lack grounds for deciding which finding to work first. The shift is that the prioritization argument now arrives attached to the finding instead of being reconstructed afterward.

Google Threat Intelligence expresses vulnerability risk as a rating with defined values of low, medium, high, critical, and unrated, where unrated means the vulnerability was assessed but no specific rating could be determined (Google Cloud documentation). That last value is the honest one, and it is why enrichment does not replace judgment. A rating is an input to a decision, not the decision.

 

The permission split is the whole argument

Enriched findings only produce outcomes if something downstream is built to act on them. That plumbing already exists, and reading it closely turns the governance question from a slogan into a configuration.

Google SecOps ships a marketplace integration for Wiz and a separate one for Google Threat Intelligence. Two integrations, two credential sets, two configurations (Google SecOps documentation). If you needed a final answer on whether these have become one product, that is it.

The Wiz integration exposes eight actions, and Google documents them in two groups. Read and query operations: Ping, Get Issue Details, List Resource Vulnerability Findings, and Get Blue Agent Analysis. Write and modify operations: Reopen Issue, Resolve Issue, Ignore Issue, and Add Comment To Issue.

Now look at the scopes Google requies for each.

 

Read and query operations

Operation Required scopes
Test Connectivity read:issues
Get Issue Details read:issues, read:posture_issues, read:threat_issues, read:comments
List Resource Vulnerability Findings read:vulnerabilities
Get Blue Agent Analysis read:threat_issues

 

Write and modify operations

Operation Required scopes
Reopen Issue write:issue_status, update:posture_issue_status, write:threat_issue_status
Resolve Issue write:threat_issue_status, write:threat_issues
Ignore Issue update:posture_issue_ignore, write:issue_ignore
Add Comment To Issue write:issue_comments, write:threat_issue_comments, write:comments

 

Google then adds a note: if granular scoping is not required by your organization's security policy, an administrator can grant read:all, write:all, and update:all instead, covering every operation above in three lines. That option exists for good reason, and documenting both paths is the right call. Plenty of teams need to move on day one.

We take the granular path every time. The split is the control.

Watch out for write:all. It is the fastest path through a deployment conversation and the one that quietly hands your automation authority nobody explicitly granted it. If your Wiz integration holds it today, you have no technical boundary between an agent investigating and an agent acting.

This is what practitioner-governed means in practice. It is a permission grant, not a policy statement.

The read path changes nothing. The write path changes someone else's environment. A named practitioner sits on the boundary.

The read path changes nothing. The write path changes someone else's environment. A named practitioner sits on the boundary.

Give an automated investigation pipeline the read scopes and let it run at machine speed. Pull issue detail. List vulnerability findings on the affected resource. Retrieve Wiz's Blue Agent analysis. Correlate against GTI. None of it mutates anything in the customer's tenant.

The write scopes are different. Closing an issue, ignoring it, reopening it: those change state in someone else's environment, and they sit behind a named practitioner.

Autonomous investigation. Human authorization. Agentic never means uncontrolled. Google and Wiz built the controls into the integration. What we add is the discipline to use them, on every tenant, every time.

Three agents are in play and they are easy to confuse. Wiz's Red Agent, now generally available, reasons through business logic to find exploitable flaws that signature-matching scanners miss. The Blue Agent accelerates investigation by assembling the context an analyst needs upfront. The Green Agent analyzes an issue against proven methodologies and applies fixes, with Remediation and Response, now in public preview, executing tailored actions inside the customer's cloud environment.

Red finds. Blue explains. Green acts.

That third one is the whole reason the write scopes matter. An agent that executes remediation in someone else's environment is precisely the capability that belongs behind a named practitioner rather than a blanket permission grant. David Grable argued in April that unaudited autonomy is a liability. The permission table is what that argument looks like as a configuration.

 

The taxonomy of closure

One more detail from the same documentation.

Ignore Issue and Resolve Issue are not interchangeable. Ignore works only on Graph Control or Cloud Configuration issues, and takes False Positive, Exception, or Won't Fix. Resolve works only on Threat Detection issues, and takes Malicious Threat, Not Malicious Threat, Security Test Threat, Planned Action Threat, or Inconclusive Threat.

Two issue classes, two closure paths, ten possible reasons.

Left ungoverned, every analyst picks a favorite and your closure data is noise within a quarter. Enforced consistently, that field is an audit trail. It tells you what you dismissed, why, and whether the pattern holds up to a regulator.

Unglamorous work. It is also the difference between a tool that is deployed and a program that is run.

Where this sits at Foresite

Google and Wiz build the intelligence and the platform. Operating them inside a live environment, against real compliance obligations and real change windows, is a different discipline. That is the one we practice.

Five capabilities inside Catalyst carry it.

Cloud security posture and exposure. Discovery across cloud, identity, workload, and data, run on Security Command Center and Wiz, plus the Security Graph relationships that turn a list of findings into an attack path.

Platform operations. Certified engineers run your Google SecOps platform. The SOAR integration and its scopes live here, which makes the read and write split a configuration decision we own on your behalf, on every tenant.

Threat operations. Google Threat Intelligence and Mandiant, operationalized into correlation, risk scoring, and forensics inside your workflow. GTI and Mandiant produce more usable intelligence than most teams have the capacity to action. This is where it becomes detection content and hunting priorities on a schedule.

Managed detection and response. Where a prioritized exposure becomes an investigation with an owner, a timeline, and a decision.

AI workload protection. Where GTI's malicious AI Skill intelligence lands as agents start importing open-source skills into production.

The connective tissue is the part no product can ship, because it is not a product problem. Enrichment tells you a finding is being exploited in the wild. It cannot tell you whether that workload is in scope for your CDE, whether the owning team has a change window this week, or whether remediation breaks a dependency. Those answers live in your environment, and they come from named practitioners who know it.

Google gives you a verdict. We give you an outcome, validated by a named practitioner.

 

What to do about it now

Confirm what you already have. If you are a Wiz customer, check what GTI context is now attached to your findings. Some you triaged last quarter may read differently today.

Audit your service account scopes. If your Wiz integration holds write:all, you have automation with authority nobody explicitly granted it. Split read from write before you scale the automation, not after.

Decide who owns the enriched finding. If Wiz output goes to cloud engineering and GTI context goes to a threat intel function that meets on Thursdays, the enrichment is decorative. Route both to one queue with authority to act.

Do not consolidate on an assumption. GTI in Wiz is not a reason to cut either line item. Confirm what your entitlement covers, in writing, before it becomes a renewal conversation.

 

Where this goes

Google has been direct that the deeper work is ahead: exposure data feeding the GTI correlation engine, and behavior-based guidance describing how an attacker typically operates after exploiting a vulnerability, down to host commands and malware. When that lands, enrichment stops being context and becomes a playbook trigger.

The reason it matters is in the first line of Google's own post. AI is accelerating vulnerability discovery and exploitation on both sides of the fight. That is the version worth building for, and the one that punishes organizations who have not sorted out authority in advance. A faster signal into an ungoverned process just produces a faster backlog.

Google and Wiz are building the signal. Make sure someone owns what happens next.

Not sure how your Wiz integration is scoped?

If your Google SecOps environment connects to Wiz, those scopes are already set one way or the other. A Foresite practitioner will walk your configuration with you and tell you what your automation is currently authorized to do in your tenant.

Talk to a cloud security specialist →



FAQ

Is Google Threat Intelligence now included in Wiz?

Partly. Google Threat Intelligence enrichment of Wiz findings went live in August 2026. Broader integration between Wiz Attack Surface Management and the GTI correlation engine is still in progress per Google. Confirm your entitlement and which enrichment capabilities you have with your Wiz representative rather than assuming full GTI coverage.

 

Did Google merge Wiz and Google Threat Intelligence into one product?

No. Google completed the Wiz acquisition in March 2026 and stated it would retain the Wiz brand and keep Wiz products working across AWS, Azure, and Oracle Cloud. GTI enrichment inside the Wiz console is one product consuming another's intelligence feed. They remain separately licensed products with different jobs: Wiz covers cloud exposure, GTI covers adversary intelligence.

 

What is a GTI Risk Rating?

Google Threat Intelligence assigns vulnerabilities a risk rating with defined values of low, medium, high, critical, and unrated. Unrated means the vulnerability was assessed but no specific rating could be determined. The rating reflects Google's assessment of real-world risk rather than raw CVSS severity, which makes it an input to prioritization rather than a substitute for environmental context.

 

How does Foresite run Wiz and Google Threat Intelligence together?

Foresite runs cloud security posture and exposure on Security Command Center and Wiz, and platform operations on Google SecOps, which is where the integration scopes are owned. Threat operations curate the GTI and Mandiant intelligence into detection content, and managed detection and response runs the investigation. Named practitioners authorize any action that changes state in the customer environment.

 

What permissions does the Wiz integration for Google SecOps need?

Google documents them in two groups. Read actions need read:issues, read:vulnerabilities, read:threat_issues, and read:comments. Write actions need write:issue_status, update:posture_issue_ignore, write:threat_issue_status, and write:issue_comments. Google notes you can grant read:all, write:all, and update:all instead. Avoid that. Keeping read and write separate is what lets automated investigation run at speed while a named practitioner authorizes anything that changes state.

 
avatar
Stephen Muller
Stephen Muller is a Senior Customer Engineer at Foresite Cybersecurity, a Google Cloud Premier Partner and the 2026 Google Cloud Security Partner of the Year. He works hands-on with customer deployments of Google SecOps and Wiz, including the integration scoping and SOAR configuration described in this post.

RELATED ARTICLES