Wiz Cloud Vulnerability Triage
When Wiz detects a high-severity cloud vulnerability, notify Slack and prompt for a ServiceNow ticket.
Overview
Wiz is excellent at detecting cloud misconfigurations and vulnerabilities, but acting on them requires human judgment. This playbook catches high and critical Wiz alerts, surfaces the details in Slack with the full context, and asks the security team whether to open a ServiceNow incident, mapping Wiz severity to ServiceNow urgency automatically.
Who this is for: Cloud security engineers and SOC analysts running Wiz across multi-cloud environments
Why automate this
Wiz alerts can be noisy. Too much automation leads to alert fatigue, too little leads to missed criticals. This playbook strikes the balance: every high/critical gets immediate visibility in Slack, and the human decides whether it deserves a formal ticket. No alert is lost, and no ticket is wasted.
How it works
- 01
Poll the Wiz API for new alerts matching the severity filter
- 02
Extract alert metadata: resource, severity, CVE, recommendation
- 03
Post a detailed Slack message with the alert context
- 04
Include an interactive 'Create Ticket' button in Slack
- 05
On click, create a ServiceNow incident with severity-mapped urgency
Impact
Human-in-the-loop triage for Wiz cloud security alerts
Maps Wiz severity to ServiceNow urgency consistently
Slack-first UX for fast analyst decisions
Creates auditable ticket trails only when warranted
Related playbooks
Keep automating
Splunk Incident to ServiceNow Ticket + Slack Alert
Automatically open a ServiceNow ticket and notify your security channel whenever a Splunk incident fires.
CrowdStrike Host Isolation with ServiceNow & Slack
Isolate or restore a compromised host in CrowdStrike, notify the device owner, and track it in ServiceNow.
Outlook Phishing Detection with VirusTotal
Scan every inbound Outlook email for malicious URLs and attachments, delete threats, and notify Slack.
Bring this playbook into your SOC
See Deployer Workflows in action with a live walkthrough of this playbook. We'll show you how to connect your SIEM, EDR, and ticketing tools in under 15 minutes.