Add security context to operational investigations with AWS DevOps Agent and Wiz
DevOps & Developer Productivity Blog
This article describes how AWS DevOps Agent integrates with Wiz to provide security context during operational incident investigations through the Model Context Protocol (MCP).
- AWS DevOps Agent autonomously investigates incidents and identifies operational improvements across AWS and multicloud environments
- Wiz MCP integration queries security graph for vulnerabilities, findings, and exposures during investigations
- Combines operational telemetry with security data to distinguish performance issues from security incidents
- Wiz MCP tools provide CVE details, threat detections, misconfigurations, and AI-generated remediation steps
- Integration automatically runs during investigations without manual triggers or custom development
- Setup requires registering Wiz MCP server, allowlisting tools in Agent Space, and choosing security audit workflow option
- Handles three scenarios: no security findings (operational issue), security threats detected (escalate), or unmonitored resources (coverage gap)
The integration enables on-call engineers to quickly determine whether alerts indicate operational problems or active security incidents by combining both contexts automatically.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2026
2025
2024
2025
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.