Skip to content

Fix Wiz Defend Passthrough severity function - #2068

Merged
alessandrarizzo merged 2 commits into
developfrom
fix/wiz-defend-passthrough-severity
May 26, 2026
Merged

alessandrarizzo merged 2 commits into
developfrom
fix/wiz-defend-passthrough-severity

Conversation

@arielkr256

Copy link
Copy Markdown
Contributor

Summary

Test plan

  • pipenv run panther_analysis_tool test --filter RuleID=Wiz.Defend.Alert.Passthrough passes (High/Low/Informational test cases)
  • make fmt && make lint pass via pre-commit

🤖 Generated with Claude Code

   Map INFORMATIONAL to INFO and fall back to DEFAULT for unknown
   values,
   so severity() always returns a value Panther accepts (fixes
   #2057).
@arielkr256
arielkr256 requested a review from a team as a code owner May 20, 2026 16:11
@cursor

cursor Bot commented May 20, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Changes alert severity normalization and dedup behavior for Wiz Defend passthrough events, which can affect alert routing, prioritization, and grouping. Scope is small and localized to one rule file.

Overview
Fixes Wiz.Defend.Alert.Passthrough severity handling by normalizing the incoming event.severity to Panther’s allowed set: maps INFORMATIONAL to INFO, passes through known values, and falls back to DEFAULT for anything else.

Updates dedup() to treat INFORMATIONAL like other low-severity alerts (INFO/LOW) when choosing the lower-noise tdrId-based dedup key.

Reviewed by Cursor Bugbot for commit 78b20f7. Bugbot is set up for automated code reviews on this repo. Configure here.

@arielkr256 arielkr256 added the bug Something isn't working label May 20, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 3660bfb. Configure here.

Comment thread rules/wiz_rules/wiz_defend_passthrough.py Outdated
@alessandrarizzo
alessandrarizzo added this pull request to the merge queue May 26, 2026
Merged via the queue into develop with commit bc18564 May 26, 2026
18 checks passed
@alessandrarizzo
alessandrarizzo deleted the fix/wiz-defend-passthrough-severity branch May 26, 2026 14:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

2 participants