
The Collaborative DevSecOps Automation Factory for Everyone

Dev, Sec, and Ops teams can innovate collaboratively, building modern security-first automation



What is DevSecOps?
Rooted in DevOps and agile software development methods, Sophos Factory combines tools, teams, and practices to standardize, secure, and reuse IT as code pipelines. It enables you to build modern solutions through collaborative automation, empowering Dev, Sec, and Ops teams to build upon accumulated knowledge efficiently.
Use Cases
SOAR and Incident Response
Compliance
Cloud Security
App Security
Network Automation
Infrastructure Automation

SOAR and Incident Response
Ecosystem
Sophos Factory works with industry-leading partners to make automation accessible across your environment through pre-built DevSecOps pipelines published to solutions catalogs.











Jobs
Trigger your pipelines via jobs that control the data flow into your pipeline and enable a user to kick off a pipeline manually or setup on a schedule. For more sophisticated jobs, we enable interoperability to other systems through incoming webhooks, CLI tool, JavaScript API client, GitHub Action, or even develop directly against the Sophos Factory API.
Incoming webhooks support interoperability to other systems, and we include the following presets with many more coming:




Modules
Kickstart your DevSecOps journey by browsing pre-built automation content directly from the Sophos Factory solution catalogs or customize each pipeline with an extensive and growing list of step modules.
Vulnerability Scanners
| Utilities | Cloud Infrastructure | Container Tools | |
|---|---|---|---|
| Utilities | |||
| Built-in | Pause | ||
| Built-in | Debug Message | ||
| Built-in | Set Variables | ||
| Built-in | Write File | ||
| Built-in | HTTP Request | ||
| Built-in | Conditional Gate | ||
| Built-in | Assert | ||
| Built-in | Credential | ||
| Secrets Management | |||
| Hashicorp | Vault | ||
| Source Control | |||
| Git | Git Clone | ||
| Cloud Infrastructure | |||
| Microsoft Azure | Resource Group | ||
| Microsoft Azure | ARM Template | ||
| Microsoft Azure | Azure CLI | ||
| Google Cloud | GCP Template | ||
| Amazon Web Services | AWS CloudFormation | ||
| Amazon Web Services | AWS CLI | ||
| Hashicorp | Terraform | ||
| Config Management | |||
| Red Hat | Ansible Playbook | ||
| Compliance Assessment | |||
| OpenSCAP | OpenSCAP Scanner | ||
| CIS-CAT | CIS-CAT Assessor | ||
| Container Tools | |||
| Docker | Docker Build & Push | ||
| Scripts | |||
| Local | Shell Script | ||
| Python | Python Script | ||
| Node.js | Node.js Script | ||
| Microsoft | PowerShell Script | ||
| Go Executor | |||
| Kubernetes | |||
| Kubernetes | kubectl | ||
| Helm | Helm Chart | ||
| Helm | Helm CLI | ||
| Vulnerability Scanners | |||
| BridgeCrew | Checkov | ||
| Accurics | Terrascan | ||
| SonarSource | SonarScanner | ||
| Container Security | |||
| Aqua Security | Trivy | ||
| Tool Installers | |||
| Tool Installer | Install Node.js | ||
| Tool Installer | Install Java | ||
| Tool Installer | Install Go | ||
| Tool Installer | Install Python | ||
Community Edition
Sophos Factory’s community edition allows two users to take advantage of one runner and three projects at no cost. Community edition users are additionally entitled to two-week run retention of data, limited SLA, and email support. Features include:
![Cybersecurity Awareness Month: 10 tips to Stay Safe Online that anyone can use - Featured - [963158] 5tips-fam-1200](https://images.contentstack.io/v3/assets/blt38f1f401b66100ad/blt6a74d6f67ce06bf1/691c2af18cc4407309374eb4/5tips-fam-1200.jpeg?width=NaN&quality=80)