Saltar a contenido
HIPAA - Banner with Media - Background

The Collaborative DevSecOps Automation Factory for Everyone

The Collaborative DevSecOps Automation Factory for
Background decoration
Decorative illustration

What is DevSecOps?

DevSecOps stands for development, security, and operations. It’s a holistic, agile approach to culture, automation, and platform design that integrates security as a collaborative responsibility throughout the entire IT as code lifecycle.

Rooted in DevOps and agile software development methods, Sophos Factory combines tools, teams, and practices to standardize, secure, and reuse IT as code pipelines. It enables you to build modern solutions through collaborative automation, empowering Dev, Sec, and Ops teams to build upon accumulated knowledge efficiently.

Use Cases

SOAR and Incident Response

Compliance

Cloud Security

App Security

Network Automation

Infrastructure Automation

xdr-graphic-small

SOAR and Incident Response

Effective incident response requires rapid action. With out-of-the-box prebuilt pipelines enabling many actions and integrations, Sophos Factory allows you to rapidly build pipelines to respond to security events by effortlessly tying together disparate technology and saving that pipeline for later use. See a new security event? Swiftly adjust the pipeline on the fly to speed up response time and ensure future events are effectively mitigated.

Ecosystem

Sophos Factory works with industry-leading partners to make automation accessible across your environment through pre-built DevSecOps pipelines published to solutions catalogs.

sophos-badge-logo-box
aws-logo-box
azure-logo-box
google-cloud-logo-box
hashicorp-logo-box
mitre-logo-box
cis-logo-box
veracode-logo-box
snyk-logo-box
aqua-logo-box
cyberark-logo-box

Jobs

Trigger your pipelines via jobs that control the data flow into your pipeline and enable a user to kick off a pipeline manually or setup on a schedule. For more sophisticated jobs, we enable interoperability to other systems through incoming webhooks, CLI tool, JavaScript API client, GitHub Action, or even develop directly against the Sophos Factory API.

Incoming webhooks support interoperability to other systems, and we include the following presets with many more coming:

github-logo-box
gitlab-logo-box
bitbucket-logo-box
terraform-logo-box

Modules

Kickstart your DevSecOps journey by browsing pre-built automation content directly from the Sophos Factory solution catalogs or customize each pipeline with an extensive and growing list of step modules.

Vulnerability Scanners

UtilitiesCloud InfrastructureContainer Tools
Utilities  
Built-inPause  
Built-inDebug Message  
Built-inSet Variables  
Built-inWrite File  
Built-inHTTP Request  
Built-inConditional Gate  
Built-inAssert  
Built-inCredential  
Secrets Management  
HashicorpVault  
Source Control  
GitGit Clone  
Cloud Infrastructure  
Microsoft AzureResource Group  
Microsoft AzureARM Template  
Microsoft AzureAzure CLI  
Google CloudGCP Template  
Amazon Web ServicesAWS CloudFormation  
Amazon Web ServicesAWS CLI  
HashicorpTerraform  
Config Management  
Red HatAnsible Playbook  
Compliance Assessment  
OpenSCAPOpenSCAP Scanner  
CIS-CATCIS-CAT Assessor  
Container Tools  
DockerDocker Build & Push  
Scripts  
LocalShell Script  
PythonPython Script  
Node.jsNode.js Script  
MicrosoftPowerShell Script  
GoogleGo Executor  
Kubernetes  
Kuberneteskubectl  
HelmHelm Chart  
HelmHelm CLI  
Vulnerability Scanners  
BridgeCrewCheckov  
AccuricsTerrascan  
SonarSourceSonarScanner  
Container Security  
Aqua SecurityTrivy  
Tool Installers  
Tool InstallerInstall Node.js  
Tool InstallerInstall Java  
Tool InstallerInstall Go  
Tool InstallerInstall Python  

Community Edition

Sophos Factory’s community edition allows two users to take advantage of one runner and three projects at no cost.

Sophos Factory’s community edition allows two users to take advantage of one runner and three projects at no cost. Community edition users are additionally entitled to two-week run retention of data, limited SLA, and email support. Features include:
access-controls-icon

Command line interface

The DevOps-friendly CLI running alongside the graphical pipeline builder allows DevOps and cybersecurity teams to collaborate on the same platform together, using tools they are already familiar with.
icon-cloud2

Virtual machine runners

The platform now provides cloud-hosted virtual machine runners, enabling running arbitrary Docker containers in pipeline steps. This addition allows more users to bring their existing solutions into the platform with minimal friction.
tools-installers-icon-orange

Tool installers

New “tool installer” step modules automatically install automation tools onto the pipeline runner behind the scenes. This feature eliminates custom setup steps to install or upgrade/downgrade tool installations before running pipelines. Supported tools include Python, Node.js, PowerShell, Ansible, Terraform, Vault, CIS-CAT Assessor, Azure/AWS CLIs, kubectl, Helm, and more.
Shield

Credential integrations

Users can now more easily integrate with external secrets management systems by “importing” secrets into Sophos Factory’s streamlined credential system at runtime. This feature enables deeper integration with popular key stores, such as HashiCorp Vault. It is also a highly secure pipeline execution, where secrets only exist within Sophos Factory’s isolated ephemeral runners on an as needed basis.