For us they replaced a bunch of different tools and a hodgepodge of custom scripts and hacks.
For those who have not heard of them - it's basically asset and vulnerability management for absolutely everything you have running in the cloud. This includes stuff running in your k8s clusters, etc. And they do all this without having to manage a fleet of agents on everything and costing you money in resource usage. Not that Wiz is cheap, far from it :(
Just because you aren’t the target market for something doesn’t mean it isn’t real or valuable.
Source: used to compete against them. I no longer have any dog in this fight.
It can scan a lot of stuff and give you pretty interesting insights and alerts.
And do you know what managers like? It creates Jira tickets automatically with all the findings, and they can assign them to people and say they've done their thing. We hate that because tickets appear and disappear magically in hundreds each time Wiz scans, sometimes with no obvious explanations.
But here come some of the bad things:
- UI/UX: Terrible. It's so difficult and confusing reaching from one place to the other and finding stuff that you had open just instants ago. Slow too. I've seen the security people do nice filters and search queries but it's not intuitive at all.
- Doesn't support very basic features. For example, in Docker Hub they don't support scanning full organizations or using organizational tokens for scanning individual repositories. They personally told me in our support channel that they were looking into it... in April 2023. Still waiting. (The API is slightly different than a regular Docker Hub public repo but, come on, an enterprise security tool that doesn't support connecting to a Docker Hub org... that's just silly)
- Closed docs. You can only check the docs if logged in. I hate that and also limits the work with people that's not a Wiz user.
- Terraform provider:
It's quite limited, that means you need A LOT of manual work to integrate stuff with their scanners
It's changelog URL doesn't work, so good luck with knowing when features appear or when you get breaking changes
No source AFAIK, you just get a binary. Good luck.
- Pricing. Can't remember the specifics but I hear a lot of complaints about how expensive they are. Also, no public pricing.I have seen Wiz at AWS re:Invent multiple years in a row, and have seen their product used to good success in multiple companies I've worked with. It's not vaporware, it's a real product that really works and has a place in the cloud/container security space. I don't think anyone is lying here at all. The fact it's /also/ an acquisition vehicle as a path to an exit for the founders is a separate thing.
Second, I have no idea what you're doing to get Wix results from a search for Wiz. When I search for Wiz, I get a whole bunch of results about Wiz, including links to discussion threads where random people (i.e., not high-rep HN users) also talk about how much they like the product.
Finally, something to consider: would Google actually pay $32B for a company that "nobody has heard of" and doesn't provide any value? Probably not. I would hope not.