SecObserve on Ubuntu 24.04

Azure Security

SecObserve, open source vulnerability management for software development teams, secured on first boot.

Base
Hardened build
minimal ports, security patches applied at build time
Access
Unique credentials
generated on first boot, readable only by root
Verified
Boots working
services pass a health gate before release
Support
24/7, 365 days
by email and live chat, 24 hour response SLA

Overview

SecObserve is an open source vulnerability management system for software development teams and cloud environments. It gathers results from a wide range of security tools into one place: import findings from SAST, DAST, dependency, secret, infrastructure as code and container scanners such as Trivy, Semgrep, Gitleaks, Grype, Checkov and ZAP, then triage, assess and track observations per product and branch. Components and licenses can be tracked from SBOMs, assessments can be automated with rules and security gates, metrics dashboards show risk over time, and results can be exported as VEX documents in CSAF, OpenVEX and CycloneDX formats.

Why the cloudimg image

cloudimg ships the full open source SecObserve stack, hardened and fully patched, with a bundled PostgreSQL database on a private container network that is never exposed on a host port. Because a vulnerability management system holds your most sensitive security findings, a unique admin password, Django secret key, field encryption key and database password are generated for each VM on first boot, before the web port answers, so the upstream default credentials never exist at any point. A paired step by step deployment guide and 24/7 support are included.

Common uses

  • One place to triage findings from SAST, SCA, secret, IaC and container scanners
  • Component and license tracking from SBOMs with automated assessment rules
  • VEX document export in CSAF, OpenVEX and CycloneDX formats

See it running

Real screenshots taken while testing this image against its deployment guide.

SecObserve on Ubuntu 24.04 screenshot 1 SecObserve on Ubuntu 24.04 screenshot 2 SecObserve on Ubuntu 24.04 screenshot 3 SecObserve on Ubuntu 24.04 screenshot 4