Skip to content

Wiz MCP Commands

Comprehensive Wiz MCP (Model Context Protocol) commands and workflows for AI-powered cloud security automation.

MCP Server Setup

CommandDescription
wiz-mcp installInstall Wiz MCP server
wiz-mcp configureConfigure MCP server
wiz-mcp startStart MCP server
wiz-mcp stopStop MCP server
wiz-mcp statusCheck server status
wiz-mcp --versionShow version information
wiz-mcp --helpShow help information

Authentication and Connection

CommandDescription
wiz-mcp auth loginLogin to Wiz platform
wiz-mcp auth logoutLogout from platform
wiz-mcp auth statusCheck authentication status
wiz-mcp auth tokenManage API tokens
wiz-mcp connect --endpoint <url>Connect to Wiz endpoint
export WIZ_API_TOKEN=<token>Set environment token

AI Assistant Integration

CommandDescription
wiz-mcp claude connectConnect to Claude Desktop
wiz-mcp cursor connectConnect to Cursor IDE
wiz-mcp vscode connectConnect to VS Code
wiz-mcp chat enableEnable chat interface
wiz-mcp chat disableDisable chat interface

Security Queries

CommandDescription
wiz-mcp query vulnerabilitiesQuery vulnerability data
wiz-mcp query complianceQuery compliance status
wiz-mcp query risksQuery security risks
wiz-mcp query assetsQuery cloud assets
wiz-mcp query incidentsQuery security incidents
wiz-mcp query policiesQuery security policies

Cloud Asset Management

CommandDescription
wiz-mcp assets listList cloud assets
wiz-mcp assets scanScan cloud assets
wiz-mcp assets filter --type vmFilter by asset type
wiz-mcp assets filter --risk highFilter by risk level
wiz-mcp assets exportExport asset inventory

Vulnerability Management

CommandDescription
wiz-mcp vulns listList vulnerabilities
wiz-mcp vulns show <vuln-id>Show vulnerability details
wiz-mcp vulns filter --severity criticalFilter by severity
wiz-mcp vulns filter --status openFilter by status
wiz-mcp vulns remediate <vuln-id>Get remediation guidance
wiz-mcp vulns exportExport vulnerability data

Compliance Monitoring

CommandDescription
wiz-mcp compliance statusCheck compliance status
wiz-mcp compliance --framework cisCheck CIS compliance
wiz-mcp compliance --framework pciCheck PCI compliance
wiz-mcp compliance --framework soxCheck SOX compliance
wiz-mcp compliance reportGenerate compliance report

Incident Response

CommandDescription
wiz-mcp incidents listList security incidents
wiz-mcp incidents show <incident-id>Show incident details
wiz-mcp incidents investigate <incident-id>Start investigation
wiz-mcp incidents timeline <incident-id>Show incident timeline
wiz-mcp incidents respond <incident-id>Initiate response

Policy Management

CommandDescription
wiz-mcp policies listList security policies
wiz-mcp policies show <policy-id>Show policy details
wiz-mcp policies validateValidate policies
wiz-mcp policies violationsShow policy violations
wiz-mcp policies enforce <policy-id>Enforce policy

AI-Powered Analysis

CommandDescription
wiz-mcp ai analyzeAI-powered security analysis
wiz-mcp ai recommendationsGet AI recommendations
wiz-mcp ai prioritizeAI-based risk prioritization
wiz-mcp ai investigate <query>AI-assisted investigation
wiz-mcp ai remediation <vuln-id>AI remediation suggestions

Automation Workflows

CommandDescription
wiz-mcp workflows listList automation workflows
wiz-mcp workflows create <name>Create new workflow
wiz-mcp workflows run <workflow-id>Run workflow
wiz-mcp workflows schedule <workflow-id>Schedule workflow
wiz-mcp workflows logs <workflow-id>View workflow logs

Integration Management

CommandDescription
wiz-mcp integrations listList integrations
wiz-mcp integrations add <service>Add integration
wiz-mcp integrations configure <service>Configure integration
wiz-mcp integrations test <service>Test integration
wiz-mcp integrations remove <service>Remove integration

Reporting and Analytics

CommandDescription
wiz-mcp reports generateGenerate security report
wiz-mcp reports scheduleSchedule reports
wiz-mcp reports export --format pdfExport report as PDF
wiz-mcp reports export --format jsonExport report as JSON
wiz-mcp analytics dashboardOpen analytics dashboard

Cloud Provider Integration

CommandDescription
wiz-mcp aws connectConnect AWS account
wiz-mcp azure connectConnect Azure subscription
wiz-mcp gcp connectConnect GCP project
wiz-mcp kubernetes connectConnect Kubernetes cluster
wiz-mcp docker connectConnect Docker registry

Security Scanning

CommandDescription
wiz-mcp scan infrastructureScan cloud infrastructure
wiz-mcp scan containersScan container images
wiz-mcp scan codeScan source code
wiz-mcp scan iacScan Infrastructure as Code
wiz-mcp scan secretsScan for exposed secrets

Risk Assessment

CommandDescription
wiz-mcp risk assessPerform risk assessment
wiz-mcp risk scoreCalculate risk score
wiz-mcp risk trendsShow risk trends
wiz-mcp risk matrixGenerate risk matrix
wiz-mcp risk forecastRisk forecasting

Monitoring and Alerts

CommandDescription
wiz-mcp monitor startStart continuous monitoring
wiz-mcp monitor stopStop monitoring
wiz-mcp alerts listList active alerts
wiz-mcp alerts configureConfigure alert rules
wiz-mcp alerts testTest alert configuration

Data Export and Import

CommandDescription
wiz-mcp export --type vulnerabilitiesExport vulnerability data
wiz-mcp export --type assetsExport asset data
wiz-mcp export --type complianceExport compliance data
wiz-mcp import --file <file>Import data from file
wiz-mcp syncSync data with Wiz platform

Configuration Management

CommandDescription
wiz-mcp config showShow current configuration
wiz-mcp config set <key> <value>Set configuration value
wiz-mcp config resetReset to default configuration
wiz-mcp config validateValidate configuration
wiz-mcp config backupBackup configuration

Performance and Optimization

CommandDescription
wiz-mcp optimize performanceOptimize performance
wiz-mcp cache clearClear cache
wiz-mcp cache statusCheck cache status
wiz-mcp --parallel <count>Set parallel processing
wiz-mcp --timeout <seconds>Set operation timeout

Debugging and Troubleshooting

CommandDescription
wiz-mcp debug --log-level debugEnable debug logging
wiz-mcp debug connectivityTest connectivity
wiz-mcp debug permissionsCheck permissions
wiz-mcp debug validateValidate setup
wiz-mcp logs --tail 100View recent logs

Environment Variables

VariableDescription
WIZ_API_TOKENWiz API authentication token
WIZ_ENDPOINTWiz API endpoint URL
WIZ_MCP_PORTMCP server port
WIZ_MCP_HOSTMCP server host
WIZ_LOG_LEVELLogging level

Configuration Files

FileDescription
wiz-mcp.config.jsonMain configuration file
wiz-mcp-policies.ymlPolicy configuration
wiz-mcp-workflows.ymlWorkflow definitions
.wiz-mcp-ignoreFiles to ignore

Docker Integration

CommandDescription
docker run wiz/mcp-serverRun MCP server in Docker
docker run -p 8080:8080 wiz/mcp-serverRun with port mapping
docker run -e WIZ_API_TOKEN=$TOKEN wiz/mcp-serverRun with environment variables

Kubernetes Deployment

CommandDescription
kubectl apply -f wiz-mcp-deployment.yamlDeploy MCP server
kubectl get pods -l app=wiz-mcpCheck MCP pods
kubectl logs -l app=wiz-mcpView MCP logs
kubectl port-forward svc/wiz-mcp 8080:8080Port forward to MCP service

API Endpoints

EndpointDescription
GET /api/v1/healthHealth check
GET /api/v1/vulnerabilitiesGet vulnerabilities
GET /api/v1/assetsGet cloud assets
GET /api/v1/complianceGet compliance status
POST /api/v1/scanTrigger security scan

Webhook Configuration

EventDescription
vulnerability.detectedNew vulnerability found
compliance.violationCompliance violation detected
incident.createdSecurity incident created
risk.elevatedRisk level elevated
scan.completedSecurity scan completed