How Wiz’s Blue Agent Traced a Multi-Cloud Attack | Wiz Blog

How Wiz’s Blue Agent Traced a Multi-Cloud Attack | Wiz Blog

The Blue Agent is Wiz’s autonomous SOC investigator. When a threat fires, the Blue Agent begins its investigation: gathering evidence, comparing activity against historical baselines, checking IP reputation, validating actor identity, and correlating signals across cloud platforms. The Blue Agent then returns a verdict, along with the complete investigation flow, allowing analysts to focus only on high priority investigations that require a human touch.

We’re excited to give you a behind the scenes look at how the Blue Agent works by walking through a real investigation of a complex, multi-platform attack.

The Case Study

It started with a VPN alert on a CI/CD service account. Was this a developer working remotely through a personal VPN, or something else?

The Blue Agent picked up the case and started pulling threads. By the time it finished, it had traced that IP across three platforms and uncovered an active attack campaign consisting of compromised credentials spanning multiple…

https://www.wiz.io/blog/blue-agent-data-exfiltration-investigation