August 25, 2026
Monad expands its Wiz-certified connector coverage

Monad's Wiz integration now includes five connectors validated for interoperability by Wiz, expanding certified coverage beyond vulnerabilities to issues, cloud configuration findings, cloud resource inventory, and audit logs.
With Monad, customers can incrementally ingest these datasets, filter and enrich records in flight, normalize or otherwise transform them into any schema, and route each stream to the SIEM, data lake, ticketing system, or other destination that needs it. The connectors were validated through Wiz's WIN program.
Five connectors for Wiz data
- Issues: toxic combinations, threat detections, and cloud configuration issues. Filters include severity, status, project, stack layer, and other criteria.
- Vulnerabilities: CVE-level findings tied to assets such as container images, serverless functions, and VMs, with detection method and exploit context preserved.
- Cloud Configuration Findings: misconfigurations and control failures across cloud environments.
- Cloud Resource Inventory: asset metadata filterable by cloud platform and entity type.
- Audit Logs: activity inside a Wiz tenant, including logins, scope changes, and service account activity, using the
admin:auditscope. Syncing starts when the connector is enabled, with an optional backfill of up to 180 days.
Shape Wiz data for each destination
The Issues connector can filter at the Wiz API level by severity, from INFORMATIONAL through CRITICAL, as well as by status, type, stack layer, project, and whether an issue already has a service ticket or remediation attached. Source filters determine what enters the pipeline; routing rules determine what each destination receives.
Monad can transform each data type into the schema its destination expects, including standard schemas like OCSF. Available mappings can standardize fields such as severity, status, timestamps, resource context, and vulnerability details. Teams can also enrich Wiz records with context from other sources in the same pipeline, then use JQ to shape the result for each destination.
For example, a single pipeline can route CRITICAL toxic combinations to a SOC queue, preserve the full dataset in a data lake, send remediation records to a ticketing system, and transform Cloud Resource Inventory for a CMDB. Each destination receives the data it needs in the format it expects, reducing unnecessary volume, processing overhead, and analyst noise.
From Wiz to your security stack
If you're already using Wiz and need to get its findings, vulnerabilities, configuration data, inventory, or audit logs into the rest of your security stack, Monad provides five incremental connectors to get that data moving without building and maintaining custom ingestion workflows.
These five Wiz connectors are part of the 360+ sources and destinations Monad supports today.
Schedule a demo today to see how Monad can filter, transform, and route Wiz data across your security stack.
Related content


Darwin Salazar
|
August 18, 2026

Valerie Worman
|
August 11, 2026
.png)
