wazuhscatune
wazuhscatune is a local application for tailoring a trusted Wazuh Security
Configuration Assessment (SCA) baseline. It opens a browser-based review UI where
each check is either accepted or recorded as an exception with a justification.
Review states:
- Unreviewed — not yet explicitly reviewed.
- Accepted — retained in the tailored policy.
- Exception — justified and removed from the tailored policy.
Requirements
Python 3.11 or newer. Python 3.11, 3.12, and 3.13 are tested on Windows, macOS, and Linux.
wazuhscatune is a local single-user application. Server deployment, multi-user
operation, and use of the internal sca package as a Python library are not
supported.
Install
Install with pipx:
pipx install wazuhscatune
From a local checkout:
pipx install .
Run
wazuhscatune
The application listens on http://127.0.0.1:5000 and opens the local browser.
If the browser does not open automatically, open that address manually.
Workflow
- Upload a Wazuh SCA
.yml,.yaml, or a ZIP previously exported bywazuhscatune. - Name and describe the tailored policy.
- Review every check as accepted or as a justified exception.
- Review the final decisions.
- Export a ZIP containing:
<policy>.yml— tailored SCA policy;<policy>_exceptions.yml— machine-readable exception record;<policy>_exceptions.md— human-readable exception record.
Export is blocked until every check has been reviewed. The uploaded baseline is never modified.
Local data
Review state is saved locally after each decision. Drafts can be recovered while
their uploaded baseline remains available. Application-created temporary files
expire after 48 hours by default; configure this with
WAZUHSCATUNE_FILE_TTL_HOURS.
The browser session lifetime is 24 hours. Uploads, drafts, session files, exports, and logs remain on the local machine.
Validation
Input validation covers YAML syntax and expected Wazuh SCA structure, including policy metadata, requirements, checks, rule lists, compliance mappings, and unique integer check IDs. ZIP imports are bounded by upload, member-count, and extracted policy-size limits. The application does not execute SCA checks or emulate the Wazuh SCA engine.
Development
For development and testing:
python -m pip install -e '.[dev]'
python -m pytest
python -m pycodestyle sca
python -m mypy sca
python -m compileall -q sca
python -m build
python -m twine check --strict dist/*
Python 3.11 is the compatibility floor. pyproject.toml is the authoritative
package and dependency declaration.
Release history is kept in CHANGELOG.md.
License
GNU General Public License v3 or later. See LICENSE.
Release files for wazuhscatune 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| wazuhscatune-0.1.1.tar.gz | 43.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| wazuhscatune-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 93.9 kB
Release files / wazuhscatune-0.1.1.tar.gz
| Download URL | wazuhscatune-0.1.1.tar.gz |
|---|---|
| Size | 43.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
465404303e6c6ad257f4f62b6d62de7e1e286ba6d6f3e8d81f31089064d3a830
|
|
BLAKE2b-256 checksum How to use checksums |
91d6ffbbc4ffead613553aaf01c6511fbd515b910f7f6336d3f079b9c95528fe
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 6, 2026.
Transparency logRelease files / wazuhscatune-0.1.1-py3-none-any.whl
| Download URL | wazuhscatune-0.1.1-py3-none-any.whl |
|---|---|
| Size | 50.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6d2297d0649eb6406b2bd08adfa29647f3357ada10cde9cb16c0e630a5b2f042
|
|
BLAKE2b-256 checksum How to use checksums |
5a1f55c1b2909467ac257d068484a34b085df51990142faf9187ab194e79b153
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 6, 2026.
Transparency log