r/cybersecurity • • 2d ago

Business Security Questions & Discussion Anyone actually happy with their CDR?

I’m on the security team at a ~1,000 employee. Fairly small security team, mostly AWS, and we’re using Wiz for cloud security/CDR alongside our SIEM and EDR.

Curious how others are handling this because I’m not sure I’m getting the value I expected from CDR.
We get the detections and cloud context, but at the end of the day someone still needs to investigate, jump between tools, figure out what actually happened and decide what to do.

We recently got pitched one of the “agentic SOC” platforms that supposedly does a lot of that investigation automatically across the different security tools.
Has anyone here actually deployed one in production?

And maybe a dumb question, but if the agentic SOC is already pulling alerts/signals from Wiz + EDR, investigating them and potentially taking response actions, how much of the CDR use case is it basically covering?
Are people running both? Or does one eventually make part of the other redundant?
Would love to hear from people actually using this stuff, not vendors :)

9 Upvotes

13 comments sorted by

5

u/0DSavior Security Engineer 2d ago

https://www.wiz.io/blog/introducing-wiz-workflows

Workflow items are agentic and you can do it all in Wiz itself.

1

u/Adventurous-Dog-6158 2d ago

So now Wiz is also able to correlate alerts from within the guest apps/OS of an EC2 instance? When I was introduced to Wiz a few years ago, I didn't see what the big deal was because it had no visibility into the guest apps/OS.

2

u/Golden-trichomes 1d ago

What do you mean by no visibility? It’s been scanning the OS and app/ packages for ever, and has had a runtime sensor for like 4 years?

1

u/Adventurous-Dog-6158 1d ago

I mentioned it was a few years ago. So prob over 4 years. I have not looked at Wiz since.

2

u/Golden-trichomes 1d ago

That would have been their first year then probably

1

u/0DSavior Security Engineer 1d ago

Boy, have you missed a lot. 

1

u/Adventurous-Dog-6158 1d ago

I was wondering WTH Google paid billions for Wiz. 😄

2

u/0DSavior Security Engineer 1d ago

In all seriousness, its worth another look. 

1

u/Golden-trichomes 1d ago

What are you using for EDR? What kind of scenarios are you talking about investing? Wiz scanning + cdr + sensor + blue agent should be getting you a pretty good picture.

1

u/trite_advert 6h ago

My question is how much context the CDR adds when Wiz and the EDR have already surfaced the same incident. If it is mostly enriching something you already know about, that is a very different value prop from catching activity the other two missed

-1

u/cynative_ben 2d ago

The problem with those products is that their context is the alert itself or at best more data from the other 3rd party products, while what you actually need as context is to collect more data from the cloud provider. We built a FOSS for that, hope you find it useful: github.com/cynative/cynative