Skip to main content

wazuhscatune

wazuhscatune is a local application for tailoring a trusted Wazuh Security Configuration Assessment (SCA) baseline. It opens a browser-based review UI where each check is either accepted or recorded as an exception with a justification.

Review states:

  • Unreviewed — not yet explicitly reviewed.
  • Accepted — retained in the tailored policy.
  • Exception — justified and removed from the tailored policy.

Review Wazuh SCA checks

Requirements

Python 3.11 or newer. Python 3.11, 3.12, and 3.13 are tested on Windows, macOS, and Linux.

wazuhscatune is a local single-user application. Server deployment, multi-user operation, and use of the internal sca package as a Python library are not supported.

Install

Install with pipx:

pipx install wazuhscatune

From a local checkout:

pipx install .

Run

wazuhscatune

The application listens on http://127.0.0.1:5000 and opens the local browser. If the browser does not open automatically, open that address manually.

Upload Wazuh SCA file

Workflow

  1. Upload a Wazuh SCA .yml, .yaml, or a ZIP previously exported by wazuhscatune.
  2. Name and describe the tailored policy.
  3. Review every check as accepted or as a justified exception.
  4. Review the final decisions.
  5. Export a ZIP containing:
    • <policy>.yml — tailored SCA policy;
    • <policy>_exceptions.yml — machine-readable exception record;
    • <policy>_exceptions.md — human-readable exception record.

Export is blocked until every check has been reviewed. The uploaded baseline is never modified.

Review decisions before export

Local data

Review state is saved locally after each decision. Drafts can be recovered while their uploaded baseline remains available. Application-created temporary files expire after 48 hours by default; configure this with WAZUHSCATUNE_FILE_TTL_HOURS.

The browser session lifetime is 24 hours. Uploads, drafts, session files, exports, and logs remain on the local machine.

Validation

Input validation covers YAML syntax and expected Wazuh SCA structure, including policy metadata, requirements, checks, rule lists, compliance mappings, and unique integer check IDs. ZIP imports are bounded by upload, member-count, and extracted policy-size limits. The application does not execute SCA checks or emulate the Wazuh SCA engine.

Development

For development and testing:

python -m pip install -e '.[dev]'
python -m pytest
python -m pycodestyle sca
python -m mypy sca
python -m compileall -q sca
python -m build
python -m twine check --strict dist/*

Python 3.11 is the compatibility floor. pyproject.toml is the authoritative package and dependency declaration.

Release history is kept in CHANGELOG.md.

License

GNU General Public License v3 or later. See LICENSE.

Release files for wazuhscatune 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for wazuhscatune 0.1.0
File Size Uploaded
wazuhscatune-0.1.0.tar.gz 42.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for wazuhscatune 0.1.0
File Interpreter ABI Platform
wazuhscatune-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 92.8 kB

Release files / wazuhscatune-0.1.0.tar.gz

Download URL wazuhscatune-0.1.0.tar.gz
Size 42.9 kB
Tags Source
SHA-256 checksum
How to use checksums
124a182c1ff46980ca90c66720138fafce4e9a5024396099c096c36d4b1e54c4
BLAKE2b-256 checksum
How to use checksums
d3efaffd5dfc2d63afc626cc9f8d463ab57b33bc656f8caa32ac865f87cbbd8a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 6, 2026.

Transparency log

Release files / wazuhscatune-0.1.0-py3-none-any.whl

Download URL wazuhscatune-0.1.0-py3-none-any.whl
Size 49.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
525241cd5f3a915bc8fa51dfe2c8205d3a60bc068c8793caf7b47d889d4a87fa
BLAKE2b-256 checksum
How to use checksums
76d3d06e28383211fb9cc3a449d2dea00704c8bfaa2e9885ec3dc6bfca7ea06c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 6, 2026.

Transparency log

Release history Release notifications | RSS feed

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page