Repository Analysis

wazuh/wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

5.2 Low AI signal View on GitHub

Analysis Overview

This report presents the forensic synthetic code analysis of wazuh/wazuh, a C++ project with 16,708 GitHub stars. SynthScan v2.0 examined 1,666,719 lines of code across 5617 source files, recording 5257 pattern matches distributed across 23 syntactic categories. The overall adjusted score of 5.2 places this repository in the Low AI signal band.

The scanner applied 160+ deterministic lexical heuristics, multi-line block detectors, abstract syntax tree depth profilers, and a cross-file Jaccard similarity matrix to construct a statistically normalised synthetic code estimate. All matches are individually weighted by severity coefficient and contextual multiplier before summation, and the resulting headline score is temporally discounted to account for the repository's development history relative to the commercial emergence of large language model coding tooling (November 2022 onward).

5.2
Adjusted Score
5.2
Raw Score
100%
Time Factor
2026-08-28
Last Push
16.7K
Stars
C++
Language
1.7M
Lines of Code
5.6K
Files
5.3K
Pattern Hits
2026-08-29
Scan Date
0.05
HC Hit Rate

What These Metrics Mean

Adjusted Score
Primary synthetic code indicator. Raw score normalised per 1,000 lines of code and multiplied by the temporal discount factor. This is the definitive comparative metric — use it to rank repositories by AI authorship density.
Raw Score
The unmodified sum of all severity-weighted, context-multiplied pattern match scores before temporal discounting. Reflects the absolute signal strength independent of when the repository was last active.
Time Factor
The temporal discount multiplier (0–100%) applied to the raw score. Repositories last updated before ChatGPT's launch (Nov 2022) receive a 5% factor. Full signal is only assigned to repositories active in the post-adoption era (Jan 2024+).
Pattern Hits
Total count of individual pattern matches across all files and categories. A high hit count with a low score may indicate a very large codebase with isolated AI snippets; a low count with a high score indicates dense, concentrated AI signatures.
HC Hit Rate
High+Critical pattern hits per file, averaged across the repository. This orthogonal signal catches repositories where a few files are densely packed with high-severity AI tells — a strong indicator even when the normalised score appears moderate due to codebase size.
Lines of Code / Files
Total lines and files analysed. The scanner examines 94 file extensions. These denominators are used to normalise the score, enabling fair comparison between repositories of vastly different sizes.

Score History

This chart maps the temporal evolution of the adjusted synthetic code score across successive scan runs. An upward trajectory indicates ongoing incorporation of AI-generated code or expanding LLM-assisted scaffolding; a stable or declining trajectory may reflect active human refactoring, code removal, or the adoption of stricter authorship policies. The dashed secondary line (right axis) independently tracks total raw pattern hit count, which can diverge from the normalised score when codebase size changes significantly between scans.

Severity Breakdown

Classifies detected patterns by their diagnostic confidence and structural impact. CRITICAL patterns (coefficient 10) represent definitive synthetic signatures — hallucinated imports, explicit LLM attribution metadata — virtually never produced by human authors. HIGH (5) indicates strong structural tells such as cross-file repetition or cross-linguistic idioms. MEDIUM (2) covers recognisable conversational padding and AI-specific vocabulary. LOW (1) captures subtle indicators like tautological comments and generic boilerplate that require density to carry independent signal.

CRITICAL 5HIGH 267MEDIUM 1006LOW 3979

Directory Score Breakdown

This horizontal bar chart decomposes the repository's raw synthetic code score by top-level directory, allowing you to pinpoint precisely which modules or components carry the highest AI authorship density. Directories with disproportionately high scores relative to their size warrant targeted manual review: concentrated AI signatures often trace back to mass-generated configuration layers, auto-ported test suites, LLM-scaffolded boilerplate classes, or entire subsystems authored under heavy copilot assistance. Use this view to prioritise your human code-review effort.

Pattern Findings

The scanner identified 5257 distinct pattern matches across 23 syntactic categories. Each entry below represents a discrete location in the source code where the engine recorded a statistically significant AI authorship indicator. Expand any category row to inspect the individual file paths, line numbers, code snippets, and the lexical context (CODE, COMMENT, or STRING) in which each match was detected.

Reading the findings table: The Severity column indicates the diagnostic confidence level (CRITICAL / HIGH / MEDIUM / LOW). The Context column identifies whether the match occurred inside executable code, an inline comment, or a string literal — comment-context matches receive a ×1.5 weight because LLMs systematically over-annotate. The ⚡ bolt icon marks clustered matches: three or more patterns within a 10-line window, each receiving an additional ×1.5 density multiplier as dense clusters constitute far stronger evidence of synthetic authorship than isolated hits.

Decorative Section Separators829 hits · 2697 pts
SeverityFileLineSnippetContext
MEDIUMtools/manager_benchmark/cleanup_agents.sh3# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/cleanup_agents.sh15# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/run_matrix.sh3# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/run_matrix.sh25# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/result_summary.py68# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/result_summary.py70# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/result_summary.py170# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/result_summary.py172# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/result_summary.py240# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/result_summary.py242# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/run_benchmark.sh3# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/run_benchmark.sh32# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/scrape_metrics.sh3# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/scrape_metrics.sh20# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/indexer_control.sh2# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/indexer_control.sh18# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/prepare_manager.sh3# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/manager_benchmark/prepare_manager.sh24# ---------------------------------------------------------------------------COMMENT
MEDIUMtools/devContainer/reinstall-cmake.sh2#-------------------------------------------------------------------------------------------------------------COMMENT
MEDIUMtools/devContainer/reinstall-cmake.sh5#-------------------------------------------------------------------------------------------------------------COMMENT
MEDIUMframework/wazuh/rbac/tests/test_decorators.py194# ---------------------------------------------------------------------------COMMENT
MEDIUMframework/wazuh/rbac/tests/test_decorators.py196# ---------------------------------------------------------------------------COMMENT
MEDIUMframework/wazuh/rbac/tests/test_decorators.py310# ---------------------------------------------------------------------------COMMENT
MEDIUMframework/wazuh/rbac/tests/test_decorators.py312# ---------------------------------------------------------------------------COMMENT
MEDIUM…ork/wazuh/core/cluster/tests/test_cluster_name_sync.py16# =============================COMMENT
MEDIUM…ork/wazuh/core/cluster/tests/test_cluster_name_sync.py18# =============================COMMENT
MEDIUM…ork/wazuh/core/cluster/tests/test_cluster_name_sync.py31# =============================COMMENT
MEDIUM…ork/wazuh/core/cluster/tests/test_cluster_name_sync.py33# =============================COMMENT
MEDIUM…ork/wazuh/core/cluster/tests/test_cluster_name_sync.py68# ============================================================COMMENT
MEDIUM…ork/wazuh/core/cluster/tests/test_cluster_name_sync.py70# ============================================================COMMENT
MEDIUM…re/cluster/tests/test_cluster_name_sync_integration.py11# =============================COMMENT
MEDIUM…re/cluster/tests/test_cluster_name_sync_integration.py13# =============================COMMENT
MEDIUM…re/cluster/tests/test_cluster_name_sync_integration.py44# =============================COMMENT
MEDIUM…re/cluster/tests/test_cluster_name_sync_integration.py46# =============================COMMENT
MEDIUM…re/cluster/tests/test_cluster_name_sync_integration.py88# ============================================================COMMENT
MEDIUM…re/cluster/tests/test_cluster_name_sync_integration.py90# ============================================================COMMENT
MEDIUM…re/cluster/tests/test_cluster_name_sync_integration.py176# ============================================================COMMENT
MEDIUM…re/cluster/tests/test_cluster_name_sync_integration.py178# ============================================================COMMENT
MEDIUM…re/cluster/tests/test_cluster_name_sync_integration.py257# ============================================================COMMENT
MEDIUM…re/cluster/tests/test_cluster_name_sync_integration.py259# ============================================================COMMENT
MEDIUM…re/cluster/tests/test_cluster_name_sync_integration.py412# ============================================================COMMENT
MEDIUM…re/cluster/tests/test_cluster_name_sync_integration.py414# ============================================================COMMENT
MEDIUM…re/cluster/tests/test_cluster_name_sync_integration.py470# ============================================================COMMENT
MEDIUM…re/cluster/tests/test_cluster_name_sync_integration.py472# ============================================================COMMENT
MEDIUMframework/wazuh/core/tests/test_engine_http.py195# ── VdHTTPClient ─────────────────────────────────────────────────────────COMMENT
MEDIUMframework/wazuh/core/indexer/indexer.py29# ============================================================================COMMENT
MEDIUMframework/wazuh/core/indexer/indexer.py31# ============================================================================COMMENT
MEDIUMframework/wazuh/core/indexer/indexer.py133# ============================================================================COMMENT
MEDIUMframework/wazuh/core/indexer/indexer.py135# ============================================================================COMMENT
MEDIUM…work/wazuh/core/indexer/tests/test_metrics_snapshot.py581# ---------------------------------------------------------------------------COMMENT
MEDIUM…work/wazuh/core/indexer/tests/test_metrics_snapshot.py583# ---------------------------------------------------------------------------COMMENT
MEDIUM…work/wazuh/core/indexer/tests/test_metrics_snapshot.py669# ---------------------------------------------------------------------------COMMENT
MEDIUM…work/wazuh/core/indexer/tests/test_metrics_snapshot.py671# ---------------------------------------------------------------------------COMMENT
MEDIUM…work/wazuh/core/indexer/tests/test_metrics_snapshot.py837# ---------------------------------------------------------------------------COMMENT
MEDIUM…work/wazuh/core/indexer/tests/test_metrics_snapshot.py839# ---------------------------------------------------------------------------COMMENT
MEDIUM…work/wazuh/core/indexer/tests/test_metrics_snapshot.py906# ---------------------------------------------------------------------------COMMENT
MEDIUM…work/wazuh/core/indexer/tests/test_metrics_snapshot.py908# ---------------------------------------------------------------------------COMMENT
MEDIUM…work/wazuh/core/indexer/tests/test_metrics_snapshot.py1013# ---------------------------------------------------------------------------COMMENT
MEDIUM…work/wazuh/core/indexer/tests/test_metrics_snapshot.py1015# ---------------------------------------------------------------------------COMMENT
MEDIUM…work/wazuh/core/indexer/tests/test_metrics_snapshot.py1169# ---------------------------------------------------------------------------COMMENT
769 more matches not shown…
Hyper-Verbose Identifiers1527 hits · 1437 pts
SeverityFileLineSnippetContext
LOWtools/mitre/mitredb.py570def parse_json_ext_references(data_object):CODE
LOWframework/scripts/rbac_control.py24async def restore_default_passwords(script_args):CODE
LOWframework/scripts/tests/test_agent_upgrade.py33def test_get_script_arguments(mock_ArgumentParser):CODE
LOWframework/scripts/tests/test_agent_upgrade.py168async def test_main_internal_error_ko(capfd):CODE
LOWframework/scripts/tests/test_wazuh_manager_clusterd.py245def test_get_script_arguments(argument_parser_mock):CODE
LOWframework/scripts/tests/test_rbac_control.py41async def test_restore_default_passwords(forward_mock: AsyncMock, safe_load_mock, print_mock, user_input, db_setup):CODE
LOWframework/scripts/tests/test_rbac_control.py66async def test_restore_default_passwords_exceptions(safe_load_mock, getpass_mock, print_mock):CODE
LOWframework/scripts/tests/test_rbac_control.py104async def test_reset_rbac_database_exceptions(input_mock, print_mock):CODE
LOWframework/scripts/tests/test_rbac_control.py114def test_get_script_arguments(exit_mock):CODE
LOWframework/scripts/tests/test_agent_groups.py77async def test_show_agents_with_group(print_mock):CODE
LOWframework/scripts/tests/test_agent_groups.py334def test_get_script_arguments(argument_parser_mock, invalid_option_mock):CODE
LOWframework/scripts/tests/test_cluster_control.py286 def add_mutually_exclusive_group(self):CODE
LOWframework/wazuh/security.py1192def revoke_current_user_tokens() -> WazuhResult:CODE
LOWframework/wazuh/agent.py130def get_agents_summary_status(agent_list: list[str] = None) -> WazuhResult:CODE
LOWframework/wazuh/agent.py1420def check_uninstall_permission() -> WazuhResult:CODE
LOWframework/wazuh/rbac/orm.py1816 def get_all_policies_from_role(self, role_id: int) -> Union[list, bool]:CODE
LOWframework/wazuh/rbac/orm.py1842 def get_all_roles_from_policy(self, policy_id: int) -> Union[list, bool]:CODE
LOWframework/wazuh/rbac/orm.py2456 def _set_permissions_and_ownership(database: str):CODE
LOWframework/wazuh/rbac/decorators.py77def _combination_defined_rbac(needed_resources: list, user_resources: str) -> bool:CODE
LOWframework/wazuh/rbac/decorators.py279def _get_required_permissions(actions: list = None, resources: list = None, **kwargs: dict) -> tuple:CODE
LOWframework/wazuh/rbac/decorators.py573def _mask_all_sensitive_fields(text: str, mask_text: str = "***") -> str:CODE
LOWframework/wazuh/rbac/tests/test_orm.py502def test_get_all_roles_from_user(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_orm.py512def test_get_all_policy_from_role(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_orm.py522def test_get_all_role_from_policy(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_orm.py532def test_remove_role_from_user(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_orm.py542def test_remove_policy_from_role(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_orm.py689def test_databasemanager_rollback(fresh_in_memory_db):CODE
LOWframework/wazuh/rbac/tests/test_orm.py696def test_databasemanager_set_database_version(fresh_in_memory_db):CODE
LOWframework/wazuh/rbac/tests/test_orm.py706def test_check_database_integrity(chmod_mock, chown_mock, remove_mock, safe_move_mock, fresh_in_memory_db):CODE
LOWframework/wazuh/rbac/tests/test_orm.py100def test_token_valid_after_revoke_same_second_ms(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_orm.py133def test_delete_all_expired_rules(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_orm.py262def test_delete_all_security_rules(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_orm.py453def test_add_role_policy_level(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_orm.py553def test_remove_role_from_policy(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_orm.py564def test_databasemanager___init__(fresh_in_memory_db):CODE
LOWframework/wazuh/rbac/tests/test_orm.py572def test_databasemanager_connect(sessionmaker_mock, create_engine_mock, fresh_in_memory_db):CODE
LOWframework/wazuh/rbac/tests/test_orm.py587def test_databasemanager_close_sessions(sessionmaker_mock, create_engine_mock, fresh_in_memory_db):CODE
LOWframework/wazuh/rbac/tests/test_orm.py600def test_databasemanager_create_database(create_db_mock, fresh_in_memory_db):CODE
LOWframework/wazuh/rbac/tests/test_orm.py613def test_databasemanager_get_database_version(fresh_in_memory_db):CODE
LOWframework/wazuh/rbac/tests/test_orm.py619def test_databasemanager_insert_default_resources(fresh_in_memory_db):CODE
LOWframework/wazuh/rbac/tests/test_orm.py663def test_databasemanager_get_table(fresh_in_memory_db):CODE
LOWframework/wazuh/rbac/tests/test_orm.py752def test_check_database_integrity_exceptions(remove_mock, close_sessions_mock, exception, fresh_in_memory_db):CODE
LOWframework/wazuh/rbac/tests/test_orm.py827def test_check_database_integrity_missing_default_policy(chmod_mock, chown_mock, remove_mock, safe_move_mock, fresh_in_mCODE
LOWframework/wazuh/rbac/tests/test_orm.py870def test_check_database_integrity_modified_default_policy(chmod_mock, chown_mock, remove_mock, safe_move_mock, fresh_in_CODE
LOWframework/wazuh/rbac/tests/test_decorators.py198def test_has_update_permissions_no_perms(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_decorators.py204def test_has_update_permissions_with_manager_update_config(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_decorators.py210def test_has_update_permissions_with_cluster_update_config(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_decorators.py216def test_has_update_permissions_read_only_role(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_decorators.py222def test_has_update_permissions_empty_action_dict(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_decorators.py228def test_has_update_permissions_non_dict_action_value(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_decorators.py234def test_has_update_permissions_none_rbac(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_decorators.py240def test_has_update_permissions_deny_manager_update_config(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_decorators.py246def test_has_update_permissions_deny_cluster_update_config(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_decorators.py252def test_has_update_permissions_mixed_deny_allow_allows(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_decorators.py113def test_expose_resourcesless(db_setup, decorator_params, rbac, allowed, mode):CODE
LOWframework/wazuh/rbac/tests/test_decorators.py158def test_mask_sensitive_config_without_permissions(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_decorators.py170def test_mask_sensitive_config_with_permissions(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_decorators.py181def test_mask_sensitive_config_on_affected_items_result(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_decorators.py264def test_has_update_permissions_all_deny(db_setup):CODE
LOWframework/wazuh/rbac/tests/test_decorators.py276def test_mask_sensitive_config_raw_xml_with_deny_rule(db_setup):CODE
1467 more matches not shown…
Over-Commented Block1045 hits · 1025 pts
SeverityFileLineSnippetContext
LOWtools/purge_wazuh.sh1#!/usr/bin/env bashCOMMENT
LOWtools/manager_benchmark/cleanup_agents.sh1#!/usr/bin/env bashCOMMENT
LOWtools/manager_benchmark/run_matrix.sh1#!/usr/bin/env bashCOMMENT
LOWtools/manager_benchmark/run_matrix.sh21# afterward. The matrix's own scenarios use non-overlapping first_id ranges, so oneCOMMENT
LOWtools/manager_benchmark/run_benchmark.sh1#!/usr/bin/env bashCOMMENT
LOWtools/manager_benchmark/run_benchmark.sh21# must pass it explicitly. There is no node knob: a session declares no cluster node.COMMENT
LOWtools/manager_benchmark/scrape_metrics.sh1#!/usr/bin/env bashCOMMENT
LOWtools/manager_benchmark/indexer_control.sh1#!/usr/bin/env bashCOMMENT
LOWtools/manager_benchmark/prepare_manager.sh1#!/usr/bin/env bashCOMMENT
LOW…manager_benchmark/tool_simulator/internal/wire/cmac.go1// Package wire speaks the bytes the manager expects: authd enrollment, theCOMMENT
LOW…er_benchmark/tool_simulator/internal/runner/session.go21//COMMENT
LOW…nager_benchmark/tool_simulator/internal/runner/scan.go1package runnerCOMMENT
LOW…ager_benchmark/tool_simulator/internal/runner/agent.go21 client *wire.ClientCOMMENT
LOW…ger_benchmark/tool_simulator/internal/scanvd/scanvd.go1// Package scanvd sends the on-demand Vulnerability Detection re-scan request anCOMMENT
LOW…_benchmark/tool_simulator/internal/source/documents.go21COMMENT
LOW…er_benchmark/tool_simulator/internal/scenario/types.go221// operators "eq", "gte" and "lte". More than one operator forms a conjunctionCOMMENT
LOW…ager_benchmark/tool_simulator/internal/engine/batch.go1// Package engine frames log events into the H/E batch remoted forwards to theCOMMENT
LOWtools/testing/enrollment-simulator/src/simulator.cpp1#include "simulator.h"COMMENT
LOWtools/testing/enrollment-simulator/src/simulator.h1#pragma onceCOMMENT
LOWruleset/sca/amazon/cis_amazon_linux_2023.yml1# Security Configuration AssessmentCOMMENT
LOWruleset/sca/amazon/cis_amazon_linux_2023.yml3481 - "Hide Artifacts"COMMENT
LOWruleset/sca/amazon/cis_amazon_linux_2023.yml3501 # 3.2 Network Parameters (Host Only).COMMENT
LOWruleset/sca/amazon/cis_amazon_linux_2023.yml5961COMMENT
LOWruleset/sca/amazon/cis_amazon_linux_2023.yml8681 condition: allCOMMENT
LOWruleset/sca/amazon/cis_amazon_linux_1.yml1# Security Configuration AssessmentCOMMENT
LOWruleset/sca/amazon/cis_amazon_linux_2.yml1# Security Configuration AssessmentCOMMENT
LOWruleset/sca/amazon/cis_amazon_linux_2.yml7881 # 6.2.13 Ensure users' home directories permissions are 750 or more restrictive. (Automated) - Not ImplementedCOMMENT
LOWruleset/sca/debian/cis_debian8.yml1# Security Configuration AssessmentCOMMENT
LOWruleset/sca/debian/cis_debian9.yml1# Security Configuration AssessmentCOMMENT
LOWruleset/sca/debian/cis_debian13.yml1# Security Configuration AssessmentCOMMENT
LOWruleset/sca/debian/cis_debian13.yml9881COMMENT
LOWruleset/sca/debian/cis_debian12.yml1# Security Configuration AssessmentCOMMENT
LOWruleset/sca/debian/cis_debian12.yml9881 # 7.2.4 Ensure shadow group is empty. (Automated) - Not ImplementedCOMMENT
LOWruleset/sca/debian/cis_debian10.yml1# Security Configuration AssessmentCOMMENT
LOWruleset/sca/debian/cis_debian10.yml3921 - "Masquerading"COMMENT
LOWruleset/sca/debian/cis_debian11.yml1# Security Configuration AssessmentCOMMENT
LOWruleset/sca/debian/cis_debian11.yml2321COMMENT
LOWruleset/sca/debian/cis_debian11.yml3541 ############################################################COMMENT
LOWruleset/sca/debian/cis_debian11.yml3561 # 3.3.6 Ensure bogus ICMP responses are ignored (Automated) - Not ImplementedCOMMENT
LOWruleset/sca/debian/cis_debian11.yml9621COMMENT
LOWruleset/sca/debian/cis_debian7.yml1# Security Configuration AssessmentCOMMENT
LOWruleset/sca/rocky/cis_rocky_linux_8.yml1# Security Configuration AssessmentCOMMENT
LOWruleset/sca/rocky/cis_rocky_linux_8.yml3901COMMENT
LOWruleset/sca/rocky/cis_rocky_linux_8.yml5421 - "Clear Windows Event Logs"COMMENT
LOWruleset/sca/rocky/cis_rocky_linux_9.yml1# Security Configuration AssessmentCOMMENT
LOWruleset/sca/rocky/cis_rocky_linux_9.yml3481 - "not c:lsmod -> r:tipc"COMMENT
LOWruleset/sca/rocky/cis_rocky_linux_9.yml4181 - c:auditctl -l -> r:-w /etc/sudoers\.d -p wa -k scope|-w /etc/sudoers\.d -p wa key=scopeCOMMENT
LOWruleset/sca/rocky/cis_rocky_linux_9.yml5241 rules:COMMENT
LOWruleset/sca/rocky/cis_rocky_linux_10.yml1# Security Configuration AssessmentCOMMENT
LOWruleset/sca/rocky/cis_rocky_linux_10.yml3481 - "not c:lsmod -> r:tipc"COMMENT
LOWruleset/sca/rocky/cis_rocky_linux_10.yml4181 - c:auditctl -l -> r:-w /etc/sudoers\.d -p wa -k scope|-w /etc/sudoers\.d -p wa key=scopeCOMMENT
LOWruleset/sca/rocky/cis_rocky_linux_10.yml5241 rules:COMMENT
LOWruleset/sca/ol/9/cis_oracle_linux_9.yml1# Security Configuration AssessmentCOMMENT
LOWruleset/sca/ol/9/cis_oracle_linux_9.yml3381 ###############################################COMMENT
LOWruleset/sca/ol/9/cis_oracle_linux_9.yml3401 # 3.3.4 Ensure suspicious packets are logged. (Automated) - Not ImplementedCOMMENT
LOWruleset/sca/ol/10/cis_oracle_linux_10.yml1# Security Configuration AssessmentCOMMENT
LOWruleset/sca/ol/10/cis_oracle_linux_10.yml3381 ###############################################COMMENT
LOWruleset/sca/ol/10/cis_oracle_linux_10.yml3401 # 3.3.4 Ensure suspicious packets are logged. (Automated) - Not ImplementedCOMMENT
LOWruleset/sca/centos/9/cis_centos9_linux.yml1# Security Configuration AssessmentCOMMENT
LOWruleset/sca/centos/9/cis_centos9_linux.yml3981 - "Masquerading"COMMENT
985 more matches not shown…
Cross-File Repetition183 hits · 915 pts
SeverityFileLineSnippetContext
HIGHframework/scripts/agent_groups.py0get script arguments. returns ------- argparse.namespace arguments passed to the script.STRING
HIGHframework/scripts/agent_upgrade.py0get script arguments. returns ------- argparse.namespace arguments passed to the script.STRING
HIGHframework/scripts/wazuh_manager_clusterd.py0get script arguments. returns ------- argparse.namespace arguments passed to the script.STRING
HIGHframework/wazuh/core/cluster/local_server.py0get basic information about the node. returns ------- dict basic node information.STRING
HIGHframework/wazuh/core/cluster/common.py0get basic information about the node. returns ------- dict basic node information.STRING
HIGHframework/wazuh/core/cluster/master.py0get basic information about the node. returns ------- dict basic node information.STRING
HIGHtests/integration/conftest.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_syscollector/conftest.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…ation/test_syscollector/test_configuration/__init__.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_remoted/conftest.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…ed/test_agent_communication/test_request_agent_info.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…munication/test_multi_agent_protocols_communication.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…agent_communication/test_agents_switching_protocols.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…remoted/test_agent_communication/test_agent_version.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…_communication/test_invalid_protocols_communication.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…st_agent_communication/test_protocols_communication.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…ed/test_agent_communication/test_multi_agent_status.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…/test_agent_communication/test_agent_pending_status.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…/test_agent_communication/test_shared_configuration.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…remoted/test_configurations/test_queue_size_too_big.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…ed/test_configurations/test_invalid_connection_port.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…est_remoted/test_configurations/test_valid_local_ip.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…ed/test_configurations/test_rids_valid_closing_time.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…t_remoted/test_configurations/test_valid_queue_size.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…remoted/test_configurations/test_invalid_connection.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…t_remoted/test_configurations/test_valid_connection.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…est_configurations/test_invalid_connection_protocol.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…t_remoted/test_configurations/test_invalid_local_ip.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…/test_configurations/test_rids_invalid_closing_time.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_remoted/test_rids/test_rids.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_remoted/test_rids/test_config.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…egration/test_remoted/test_manager/test_manager_ack.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…integration/test_remoted/test_multi_groups/conftest.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…moted/test_multi_groups/test_merged_mg_file_content.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…emoted/test_socket_communication/test_ping_pong_msg.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_sca/conftest.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_sca/test_basic/conftest.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_sca/test_basic/__init__.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_logcollector/utils.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…ation/test_logcollector/test_configuration/__init__.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…ts/integration/test_logcollector/test_read/__init__.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_authd/conftest.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…tegration/test_authd/test_api_registration/conftest.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…tegration/test_authd/test_api_registration/__init__.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…s/integration/test_authd/test_use_password/conftest.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…s/integration/test_authd/test_use_password/__init__.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_authd/test_ssl/conftest.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_authd/test_ssl/__init__.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_authd/test_cluster/__init__.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…/integration/test_authd/test_use_source_ip/conftest.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…/integration/test_authd/test_use_source_ip/__init__.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…egration/test_authd/test_remote_enrollment/__init__.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_authd/test_common/conftest.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_authd/test_common/__init__.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…/integration/test_authd/test_force_options/__init__.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…ntegration/test_authd/test_drop_privileges/__init__.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_wazuh_db/conftest.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_wazuh_db/test_groups/conftest.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGHtests/integration/test_wazuh_db/test_groups/__init__.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
HIGH…s/integration/test_wazuh_db/test_databases/conftest.py0copyright (c) 2015, wazuh inc. created by wazuh, inc. <info@wazuh.com>. this program is free software; you can redistribSTRING
123 more matches not shown…
Excessive Try-Catch Wrapping391 hits · 484 pts
SeverityFileLineSnippetContext
LOWtools/manager_benchmark/scrape_metrics.sh48except Exception:CODE
LOWtools/agent-upgrade/wpkpack.py100 except Exception as error:CODE
MEDIUMtools/debug/csv-stat.py66 print(f'Error: File {args.file} not found.')CODE
LOWtools/debug/csv-stat.py68 except Exception as e:CODE
MEDIUMtools/debug/csv-stat.py69 print(f'Error: {e}')CODE
LOWframework/scripts/agent_groups.py20except Exception as e:CODE
MEDIUMframework/scripts/agent_groups.py21 print("Error importing 'Wazuh' package.\n\n{0}\n".format(e))CODE
MEDIUMframework/scripts/agent_groups.py382 print("Error {0}: {1}".format(e.code, e.message))STRING
LOWframework/scripts/agent_groups.py385 except Exception as e:STRING
LOWframework/scripts/agent_upgrade.py36except Exception as e:CODE
MEDIUMframework/scripts/agent_upgrade.py37 print("Error importing 'Wazuh' package.\n\n{0}\n".format(e))CODE
MEDIUMframework/scripts/agent_upgrade.py111 print("Error: custom WPK files are delivered from '{0}'. Move the file there and pass "CODE
MEDIUMframework/scripts/agent_upgrade.py116 print("Error: WPK file not found: '{0}'. Place the file in '{1}' before launching the "CODE
MEDIUMframework/scripts/agent_upgrade.py177 print(f"Error {wazuh_err.code}: {wazuh_err.message}")CODE
MEDIUMframework/scripts/agent_upgrade.py181 print(f"Error {getattr(e, 'ext', {}).get('code', e.status)}: {str(e.detail)}")CODE
LOWframework/scripts/agent_upgrade.py184 except Exception as unexpected_err:CODE
MEDIUMframework/scripts/agent_upgrade.py147def main():CODE
LOWframework/scripts/cluster_control.py286 except Exception as e:STRING
LOWframework/scripts/rbac_control.py14except Exception as e:CODE
MEDIUMframework/scripts/rbac_control.py15 print("Error importing 'Wazuh' package.\n\n{0}\n".format(e))CODE
MEDIUMframework/scripts/rbac_control.py102 print(f"Error {e.code}: {e.message}")CODE
LOWframework/scripts/rbac_control.py103 except Exception as e:CODE
LOWframework/scripts/wazuh_manager_clusterd.py206 except Exception as e:CODE
LOWframework/scripts/wazuh_manager_clusterd.py212 except Exception as e:CODE
LOWframework/scripts/wazuh_manager_clusterd.py247 except Exception as e:CODE
LOWframework/scripts/wazuh_manager_clusterd.py269 except Exception:CODE
LOWframework/wazuh/__init__.py31except Exception:CODE
LOWframework/wazuh/__init__.py81 except Exception:CODE
LOWframework/wazuh/agent.py804 except Exception as e:CODE
LOWframework/wazuh/agent.py864 except Exception as e:CODE
LOWframework/wazuh/rbac/orm.py2521 except Exception as e:CODE
LOWframework/wazuh/rbac/decorators.py474 except Exception:CODE
LOWframework/wazuh/rbac/decorators.py703 except Exception:CODE
LOWframework/wazuh/core/configuration.py878 except Exception as e:CODE
LOWframework/wazuh/core/configuration.py886 except Exception as e:CODE
LOWframework/wazuh/core/configuration.py890 except Exception as e:CODE
LOWframework/wazuh/core/configuration.py445 except Exception as e:CODE
LOWframework/wazuh/core/configuration.py494 except Exception as e:CODE
LOWframework/wazuh/core/configuration.py540 except Exception as e:CODE
LOWframework/wazuh/core/configuration.py624 except Exception as e:CODE
LOWframework/wazuh/core/configuration.py854 except Exception as e:CODE
LOWframework/wazuh/core/configuration.py1007 except Exception as unhandled_exc:CODE
LOWframework/wazuh/core/configuration.py1035 except Exception as unhandled_exc:CODE
LOWframework/wazuh/core/configuration.py1086 except Exception as e:CODE
LOWframework/wazuh/core/wdb.py433 except Exception as e:CODE
MEDIUMframework/wazuh/core/wdb.py342def send_request_to_wdb(query_lower, step, off, response):CODE
LOWframework/wazuh/core/wazuh_socket.py38 except Exception as e:CODE
LOWframework/wazuh/core/wazuh_socket.py53 except Exception as e:CODE
LOWframework/wazuh/core/wazuh_socket.py61 except Exception as e:CODE
LOWframework/wazuh/core/wazuh_socket.py123 except Exception as e:CODE
MEDIUMframework/wazuh/core/wazuh_socket.py29def _connect(self):CODE
MEDIUMframework/wazuh/core/wazuh_socket.py56def receive(self, header_format="<I", header_size=4):CODE
LOWframework/wazuh/core/agent_tasks.py78 except Exception as e:CODE
LOWframework/wazuh/core/agent_tasks.py145 except Exception as e:CODE
LOWframework/wazuh/core/utils.py866 except Exception as e:CODE
LOWframework/wazuh/core/utils.py1804 except Exception as e:CODE
LOWframework/wazuh/core/pyDaemonModule.py128 except Exception as exc:CODE
LOWframework/wazuh/core/stats.py38 except Exception:CODE
LOWframework/wazuh/core/agent.py817 except Exception as e:CODE
LOWframework/wazuh/core/agent.py885 except Exception:CODE
331 more matches not shown…
Deep Nesting328 hits · 302 pts
SeverityFileLineSnippetContext
LOWtools/manager_benchmark/result_summary.py110CODE
LOWtools/mitre/mitredb.py509CODE
LOWtools/mitre/mitredb.py585CODE
LOWtools/mitre/mitredb.py613CODE
LOWtools/debug/wdb-query.py94CODE
LOWframework/scripts/agent_groups.py336CODE
LOWframework/scripts/agent_upgrade.py147CODE
LOWframework/scripts/cluster_control.py247CODE
LOWframework/scripts/tests/test_wazuh_manager_clusterd.py38CODE
LOWframework/scripts/tests/test_wazuh_manager_clusterd.py154CODE
LOWframework/scripts/tests/test_wazuh_manager_clusterd.py276CODE
LOWframework/wazuh/security.py26CODE
LOWframework/wazuh/security.py258CODE
LOWframework/wazuh/security.py361CODE
LOWframework/wazuh/security.py427CODE
LOWframework/wazuh/security.py533CODE
LOWframework/wazuh/security.py603CODE
LOWframework/wazuh/security.py744CODE
LOWframework/wazuh/security.py781CODE
LOWframework/wazuh/security.py848CODE
LOWframework/wazuh/security.py908CODE
LOWframework/wazuh/security.py959CODE
LOWframework/wazuh/security.py1009CODE
LOWframework/wazuh/security.py1063CODE
LOWframework/wazuh/security.py1139CODE
LOWframework/wazuh/security.py1270CODE
LOWframework/wazuh/stats.py16CODE
LOWframework/wazuh/agent.py199CODE
LOWframework/wazuh/agent.py292CODE
LOWframework/wazuh/agent.py528CODE
LOWframework/wazuh/agent.py641CODE
LOWframework/wazuh/agent.py873CODE
LOWframework/wazuh/agent.py1173CODE
LOWframework/wazuh/rbac/orm.py1153CODE
LOWframework/wazuh/rbac/orm.py1331CODE
LOWframework/wazuh/rbac/orm.py1438CODE
LOWframework/wazuh/rbac/orm.py1525CODE
LOWframework/wazuh/rbac/orm.py1577CODE
LOWframework/wazuh/rbac/orm.py1722CODE
LOWframework/wazuh/rbac/orm.py1863CODE
LOWframework/wazuh/rbac/orm.py2065CODE
LOWframework/wazuh/rbac/orm.py2162CODE
LOWframework/wazuh/rbac/orm.py2204CODE
LOWframework/wazuh/rbac/preprocessor.py19CODE
LOWframework/wazuh/rbac/auth_context.py53CODE
LOWframework/wazuh/rbac/auth_context.py124CODE
LOWframework/wazuh/rbac/auth_context.py240CODE
LOWframework/wazuh/rbac/auth_context.py299CODE
LOWframework/wazuh/rbac/auth_context.py348CODE
LOWframework/wazuh/rbac/auth_context.py385CODE
LOWframework/wazuh/rbac/decorators.py23CODE
LOWframework/wazuh/rbac/decorators.py77CODE
LOWframework/wazuh/rbac/decorators.py223CODE
LOWframework/wazuh/rbac/decorators.py279CODE
LOWframework/wazuh/rbac/decorators.py425CODE
LOWframework/wazuh/rbac/decorators.py629CODE
LOWframework/wazuh/rbac/decorators.py447CODE
LOWframework/wazuh/rbac/decorators.py449CODE
LOWframework/wazuh/rbac/tests/test_orm.py28CODE
LOWframework/wazuh/rbac/tests/test_orm.py336CODE
268 more matches not shown…
Unused Imports280 hits · 274 pts
SeverityFileLineSnippetContext
LOWtools/manager_benchmark/make_report_tables.py14CODE
LOWtools/manager_benchmark/make_report_tables.py14CODE
LOWtools/manager_benchmark/result_summary.py22CODE
LOWframework/scripts/agent_upgrade.py13CODE
LOWframework/scripts/wazuh_manager_clusterd.py9CODE
LOWframework/wazuh/__init__.py10CODE
LOWframework/wazuh/__init__.py10CODE
LOWframework/wazuh/agent.py9CODE
LOWframework/wazuh/rbac/auth_context.py8CODE
LOWframework/wazuh/core/wdb.py12CODE
LOWframework/wazuh/core/results.py5CODE
LOWframework/wazuh/core/utils.py21CODE
LOWframework/wazuh/core/utils.py29CODE
LOWframework/wazuh/core/agent.py25CODE
LOWframework/wazuh/core/cluster/local_server.py10CODE
LOWframework/wazuh/core/cluster/local_server.py14CODE
LOWframework/wazuh/core/cluster/cluster.py19CODE
LOWframework/wazuh/core/cluster/cluster.py19CODE
LOWframework/wazuh/core/cluster/cluster.py19CODE
LOWframework/wazuh/core/cluster/tests/test_local_client.py15CODE
LOWframework/wazuh/core/cluster/tests/test_local_server.py24CODE
LOWframework/wazuh/core/cluster/tests/test_server.py18CODE
LOWframework/wazuh/core/cluster/tests/test_cluster.py14CODE
LOWframework/wazuh/core/tests/test_mitre.py14CODE
LOWframework/wazuh/core/tests/test_agent.py16CODE
LOWframework/wazuh/core/tests/test_configuration.py10CODE
LOWframework/wazuh/core/tests/test_pyDaemonModule.py8CODE
LOWframework/wazuh/core/tests/test_agent_tasks.py7CODE
LOWframework/wazuh/core/tests/test_agent_tasks.py9CODE
LOWframework/wazuh/core/tests/test_manager.py14CODE
LOWframework/wazuh/core/indexer/disconnected_agents.py1CODE
LOWframework/wazuh/core/indexer/tests/test_indexer.py5CODE
LOW…rk/wazuh/core/indexer/tests/test_credential_manager.py7CODE
LOWframework/wazuh/tests/test_agent.py16CODE
LOWframework/wazuh/tests/test_manager.py23CODE
LOWtests/integration/test_syscollector/conftest.py21CODE
LOWtests/integration/test_syscollector/conftest.py23CODE
LOWtests/integration/test_syscollector/conftest.py23CODE
LOWtests/integration/test_syscollector/conftest.py23CODE
LOWtests/integration/test_syscollector/conftest.py23CODE
LOW…/test_configuration/test_syscollector_configuration.py45CODE
LOW…agent_communication/test_agents_switching_protocols.py11CODE
LOW…remoted/test_configurations/test_queue_size_too_big.py10CODE
LOW…ed/test_configurations/test_invalid_connection_port.py10CODE
LOW…est_remoted/test_configurations/test_valid_local_ip.py21CODE
LOW…ed/test_configurations/test_rids_valid_closing_time.py10CODE
LOW…ed/test_configurations/test_rids_valid_closing_time.py12CODE
LOW…ed/test_configurations/test_rids_valid_closing_time.py19CODE
LOW…ed/test_configurations/test_rids_valid_closing_time.py22CODE
LOW…ed/test_configurations/test_rids_valid_closing_time.py23CODE
LOW…t_remoted/test_configurations/test_valid_queue_size.py10CODE
LOW…t_remoted/test_configurations/test_valid_queue_size.py12CODE
LOW…t_remoted/test_configurations/test_valid_queue_size.py19CODE
LOW…t_remoted/test_configurations/test_valid_connection.py10CODE
LOW…est_configurations/test_invalid_connection_protocol.py10CODE
LOW…t_remoted/test_configurations/test_invalid_local_ip.py10CODE
LOW…t_remoted/test_configurations/test_invalid_local_ip.py20CODE
LOW…/test_configurations/test_rids_invalid_closing_time.py10CODE
LOW…/test_configurations/test_rids_invalid_closing_time.py20CODE
LOW…/test_configurations/test_rids_invalid_closing_time.py22CODE
220 more matches not shown…
Docstring Block Structure52 hits · 260 pts
SeverityFileLineSnippetContext
HIGHsrc/build.py18 Process the command line arguments and executes the corresponding argument's utility. Args: - NoneSTRING
HIGHsrc/ci/build_tools.py34 Execute the command 'make clean' in the operating system. Args: - None Returns: - None STRING
HIGHsrc/ci/build_tools.py63 Delete the contents of the external folder. Args: - None Returns: - None Raises: STRING
HIGHsrc/ci/build_tools.py91 Delete a specific folder inside some module. Args: - moduleName(str): Main folder name. - addiSTRING
HIGHsrc/ci/build_tools.py134 Execute the command 'make clean-internals' in the operating system. Args: - None Returns: STRING
HIGHsrc/ci/build_tools.py163 Execute the command 'make clean-windows' in the operating system. Args: - None Returns: -STRING
HIGHsrc/ci/build_tools.py192 Clean the files generated in some module when it is built. Args: - moduleName(str): Library name to beSTRING
HIGHsrc/ci/build_tools.py224 Configure cmake command with specific configuration based on the parameters passed to the function. Args: STRING
HIGHsrc/ci/build_tools.py280 Get a map with configured folders to be deleted. Args: - None Returns: - DELETE_FOLDER_DISTRING
HIGHsrc/ci/build_tools.py296 Use make command in order to download dependencies and after that build them. Args: - targetName(sSTRING
HIGHsrc/ci/build_tools.py335 Build a library. Args: - moduleName(str): Library to be built. Returns: - None RaiseSTRING
HIGHsrc/ci/build_tools.py369 Build project with flags. Args: - targetName(str): Build type to be built <STRING
HIGHsrc/ci/utils.py51 Get current path. Args: - None Returns: - path(str): Current path. Raises: -STRING
HIGHsrc/ci/utils.py67 Delete logs generates for a module. Args: - moduleName(str): Library to be cleaned. Returns: STRING
HIGHsrc/ci/utils.py107 Find a file in some path. Args: - name(str): File to find. - path(str): Base path to find a fiSTRING
HIGHsrc/ci/utils.py132 Find a folder in some path. Args: - name(str): Folder to find. - path(str): Base path to find STRING
HIGHsrc/ci/utils.py158 Return folders to be analyzed with AStyle coding style analysis tool. Args: - moduleName(str): LibrarySTRING
HIGHsrc/ci/utils.py195 Get directory path for a module. Args: - moduleName(str): Library to get the path of. Returns: STRING
HIGHsrc/ci/utils.py214 Get directory path build for a module. Args: moduleName(str): Library to get the path of. ReturnsSTRING
HIGHsrc/ci/utils.py233 Get valid module list. Args: - None Returns: - MODULE_LIST(array): A list with valid moduSTRING
HIGHsrc/ci/utils.py249 Get valid module list. Args: - None Returns: - MODULE_LIST_STR(str): A list with valid moSTRING
HIGHsrc/ci/utils.py265 Display a red message with the errors. Args: - msg(str): Message to show. Returns: - NoneSTRING
HIGHsrc/ci/utils.py281 Display a formatted green message. Args: - msg(str): Message to show. - module(str): Library uSTRING
HIGHsrc/ci/utils.py302 Display a message formatted from the HEADER_DIR map. Args: - moduleName(str): Library using in the mesSTRING
HIGHsrc/ci/utils.py320 Display a yellow message with some information. Args: - msg(str): Message to show. Returns: STRING
HIGHsrc/ci/utils.py336 Display a message formatted from the HEADER_DIR map. Args: - moduleName(str): Library using in the mesSTRING
HIGHsrc/ci/utils.py354 Read a JSON path and convert to map. Args: - jsonFilePath(str): JSON path. Returns: - jsoSTRING
HIGHsrc/ci/utils.py378 Get root path. Args: - None Returns: - path(str): Root path. Raises: - None STRING
HIGHsrc/ci/utils.py394 Get possible build targets. Args: - None Returns: - TARGET_LIST(array): Target list STRING
HIGHsrc/ci/run_check.py21 Check the coverage for a library being analyzed. Args: - output(str): Message to be shown in the stdouSTRING
HIGHsrc/ci/run_check.py64 Execute Address Sanitizer dynamic analysis tool using the test tool defined for a library. Args: -STRING
HIGHsrc/ci/run_check.py110 Execute AStyle coding style analysis for the library code failing when one or more files need to be modified. STRING
HIGHsrc/ci/run_check.py162 Execute AStyle coding style analysis tool for the library code formatting all needed files. Args: STRING
HIGHsrc/ci/run_check.py195 Execute code coverage for a library unit tests. Args: - moduleName: Library to be analyzed using gcov STRING
HIGHsrc/ci/run_check.py313 Execute cppcheck static analysis in the library code. Args: - moduleName: Library to be analyzed usingSTRING
HIGHsrc/ci/run_check.py419 Execute scan-build for a defined target. Args: - targetName: Target to be analyzed using scan-build anSTRING
HIGHsrc/ci/run_check.py473 Execute test tool for a module with a configuration passed by parameters. Args: - moduleName(str): LibSTRING
HIGHsrc/ci/run_check.py522 Execute test tool for a module with a configuration passed by parameters for Windows OS. Args: - mSTRING
HIGHsrc/ci/run_check.py663 Execute library tests using CTest with labels. Args: - moduleName: Library representing the tests to bSTRING
HIGHsrc/ci/run_check.py730 Results are taken in JSON format after running the test tool and validated using pytest. Args: - mSTRING
HIGHsrc/ci/run_check.py771 Execute all tests with valgrind tool in order to check memory leaks in the library code. Args: - mSTRING
HIGHsrc/ci/tests/syscheckd/test_check_module.py20 Find smokeTests inside the root path and return the complete path. Args: - moduleName(str): Library toSTRING
HIGHsrc/ci/tests/syscheckd/test_check_module.py40 Configure and format logging message. Args: - getModuleName(fixture): Return current module. RetuSTRING
HIGHsrc/ci/tests/syscheckd/test_check_module.py75 Search inside test tool output folder so it returns the root path and the child folders. Args: - sSTRING
HIGHsrc/ci/tests/syscheckd/test_check_module.py97 From directory name and their paths it creates a map in order to have all information in only structure. STRING
HIGHsrc/ci/tests/syscheckd/test_check_module.py122 From directory name and their paths it creates a map in order to have all information in only structure. ASTRING
HIGHsrc/ci/tests/syscheckd/test_check_module.py149 Read file transaction input files and return an array with these information in JSON format. Args: STRING
HIGHsrc/ci/tests/syscheckd/test_check_module.py176 Read registry key transaction input files and return an array with these information in JSON format. Args:STRING
HIGHsrc/ci/tests/syscheckd/test_check_module.py203 Read registry value transaction input files and return an array with these information in JSON format. ArgSTRING
HIGHsrc/ci/tests/syscheckd/test_check_module.py229 Read registry value transaction input files and return an array with these information in JSON format. ArgSTRING
HIGHsrc/ci/tests/syscheckd/test_check_module.py261 Check result of action executed. Args: - result(map): A map with parsed result JSON. - configLSTRING
HIGHsrc/ci/tests/syscheckd/test_check_module.py283 Check result of transaction executed compared than input information. Args: - result(map): A map with STRING
Redundant / Tautological Comments169 hits · 247 pts
SeverityFileLineSnippetContext
LOWtools/get_git_refs.sh148 # Check if HEAD points to a branchCOMMENT
LOWruleset/sca/amazon/cis_amazon_linux_2023.yml42 remediation: "Run the following script to disable squashfs: #!/usr/bin/env bash { l_mname=\"squashfs\" # set module CODE
LOWruleset/sca/amazon/cis_amazon_linux_2023.yml79 remediation: "Run the following script to disable the udf filesystem: #!/usr/bin/env bash { l_mname=\"udf\" # set moCODE
LOWruleset/sca/debian/cis_debian10.yml35 remediation: "Run the following script to disable the cramfs module: If the module is available in the running kerneCODE
LOWruleset/sca/debian/cis_debian10.yml76 remediation: "Run the following script to disable the squashfs module: If the module is available in the running kerCODE
LOWruleset/sca/debian/cis_debian10.yml112 remediation: "Run the following script to disable the udf module: If the module is available in the running kernel: CODE
LOWruleset/sca/debian/cis_debian10.yml1443 remediation: "Run the following script to disable the cramfs module: If the module is available in the running kerneCODE
LOWruleset/sca/debian/cis_debian10.yml2339 remediation: "Run the following script to verify that the banner message is enabled and set: #!/usr/bin/env bash { lCODE
LOWruleset/sca/debian/cis_debian10.yml2485 remediation: "Run the following script to disable automatic mounting of media for all GNOME users: #!/usr/bin/env baCODE
LOWruleset/sca/rocky/cis_rocky_linux_9.yml38 remediation: "Run the following script to disable squashfs: #!/usr/bin/env bash { l_mname=\"squashfs\" # set module CODE
LOWruleset/sca/rocky/cis_rocky_linux_9.yml75 remediation: "Run the following script to disable the udf filesystem: #!/usr/bin/env bash { l_mname=\"udf\" # set moCODE
LOWruleset/sca/rocky/cis_rocky_linux_9.yml1391 remediation: "Run the following script to disable usb-storage: #!/usr/bin/env bash { l_mname=\"usb-storage\" # set mCODE
LOWruleset/sca/rocky/cis_rocky_linux_9.yml2407 remediation: "Run the following script to verify that the banner message is enabled and set: #!/usr/bin/env bash { lCODE
LOWruleset/sca/rocky/cis_rocky_linux_9.yml3432 remediation: "Run the following script to disable tipc: #!/usr/bin/env bash { l_mname=\"tipc\" # set module name # CCODE
LOWruleset/sca/rocky/cis_rocky_linux_10.yml38 remediation: "Run the following script to disable squashfs: #!/usr/bin/env bash { l_mname=\"squashfs\" # set module CODE
LOWruleset/sca/rocky/cis_rocky_linux_10.yml75 remediation: "Run the following script to disable the udf filesystem: #!/usr/bin/env bash { l_mname=\"udf\" # set moCODE
LOWruleset/sca/rocky/cis_rocky_linux_10.yml1391 remediation: "Run the following script to disable usb-storage: #!/usr/bin/env bash { l_mname=\"usb-storage\" # set mCODE
LOWruleset/sca/rocky/cis_rocky_linux_10.yml2407 remediation: "Run the following script to verify that the banner message is enabled and set: #!/usr/bin/env bash { lCODE
LOWruleset/sca/rocky/cis_rocky_linux_10.yml3432 remediation: "Run the following script to disable tipc: #!/usr/bin/env bash { l_mname=\"tipc\" # set module name # CCODE
LOWruleset/sca/almalinux/cis_alma_linux_10.yml39 remediation: "Run the following script to disable squashfs: #!/usr/bin/env bash { l_mname=\"squashfs\" # set module CODE
LOWruleset/sca/almalinux/cis_alma_linux_10.yml77 remediation: "Run the following script to disable the udf filesystem: #!/usr/bin/env bash { l_mname=\"udf\" # set moCODE
LOWruleset/sca/almalinux/cis_alma_linux_10.yml1393 remediation: "Run the following script to disable usb-storage: #!/usr/bin/env bash { l_mname=\"usb-storage\" # set mCODE
LOWruleset/sca/almalinux/cis_alma_linux_10.yml2502 remediation: "Run the following script to verify that the banner message is enabled and set: #!/usr/bin/env bash { lCODE
LOWruleset/sca/almalinux/cis_alma_linux_10.yml2651 remediation: "Run the following script to disable automatic mounting of media for all GNOME users: #!/usr/bin/env baCODE
LOWruleset/sca/almalinux/cis_alma_linux_10.yml3665 remediation: "Run the following script to disable tipc: #!/usr/bin/env bash { l_mname=\"tipc\" # set module name # CCODE
LOWruleset/sca/almalinux/cis_alma_linux_9.yml39 remediation: "Run the following script to disable squashfs: #!/usr/bin/env bash { l_mname=\"squashfs\" # set module CODE
LOWruleset/sca/almalinux/cis_alma_linux_9.yml77 remediation: "Run the following script to disable the udf filesystem: #!/usr/bin/env bash { l_mname=\"udf\" # set moCODE
LOWruleset/sca/almalinux/cis_alma_linux_9.yml1393 remediation: "Run the following script to disable usb-storage: #!/usr/bin/env bash { l_mname=\"usb-storage\" # set mCODE
LOWruleset/sca/almalinux/cis_alma_linux_9.yml2502 remediation: "Run the following script to verify that the banner message is enabled and set: #!/usr/bin/env bash { lCODE
LOWruleset/sca/almalinux/cis_alma_linux_9.yml2651 remediation: "Run the following script to disable automatic mounting of media for all GNOME users: #!/usr/bin/env baCODE
LOWruleset/sca/almalinux/cis_alma_linux_9.yml3665 remediation: "Run the following script to disable tipc: #!/usr/bin/env bash { l_mname=\"tipc\" # set module name # CCODE
LOWframework/scripts/tests/test_cluster_control.py304 # Check if cluster is disabled and first conditionCOMMENT
LOWframework/wazuh/agent.py893 # Check if group existsCOMMENT
LOWframework/wazuh/agent.py948 # Check if the group existsCOMMENT
LOWframework/wazuh/agent.py1005 # Check if agent and group existCOMMENT
LOWframework/wazuh/agent.py1045 # Check if agent existsCOMMENT
LOWframework/wazuh/agent.py1103 # Check if group existsCOMMENT
LOWframework/wazuh/manager.py482 # Check if the configuration is validCOMMENT
LOWframework/wazuh/rbac/orm.py2478 # Check if an upgrade is requiredCOMMENT
LOWframework/wazuh/core/configuration.py336 # Check if we have read the same filters before (we will need to merge them)COMMENT
LOWframework/wazuh/core/configuration.py923 # Check if the group existsCOMMENT
LOWframework/wazuh/core/configuration.py982 # Check if the component is correctCOMMENT
LOWframework/wazuh/core/results.py407 # Check if error is already addedCOMMENT
LOWframework/wazuh/core/utils.py237 # Check if every element in sort['fields'] is in allowed_sort_fieldsCOMMENT
LOWframework/wazuh/core/utils.py1796 # Check if configuration changes are allowedCOMMENT
LOWframework/wazuh/core/agent.py1120 # Check if the group already belongs to the agentCOMMENT
LOWframework/wazuh/core/agent.py1242 # Check if agent exists and the group existsCOMMENT
LOWframework/wazuh/core/manager.py176 # Check if configuration file existsCOMMENT
LOWframework/wazuh/core/cluster/common.py502 # Check if a new message was received.COMMENT
LOWframework/wazuh/core/cluster/master.py511 # Check if an integrity_check has already been performedCOMMENT
LOWframework/wazuh/core/cluster/cluster.py153 # Check if recursive flag is set or root is actually the initial lookup directory.COMMENT
LOWframework/wazuh/tests/test_agent.py883 # Check if the number of affected items matches the number of times `add_group_to_agent` was calledCOMMENT
LOWtests/integration/test_logcollector/conftest.py103 # Write the file statusCOMMENT
LOW…tegration/test_authd/test_api_registration/conftest.py44 # Check if specific values were set or set the defaultsCOMMENT
LOW…est_wazuh_db/test_groups/test_sync_agent_groups_get.py100 # Check if it requires any special configurationCOMMENT
LOW…est_wazuh_db/test_groups/test_sync_agent_groups_get.py105 # Check if it requires the global hash.COMMENT
LOW…st_ambiguous_confs/test_whodata_works_over_realtime.py167 # Write the fileCOMMENT
LOW…_redirection/test_windows_system_folder_redirection.py149 # Write the fileCOMMENT
LOWtests/integration/test_api/conftest.py71 # Check if specific values were set or set the defaultsCOMMENT
LOW…ion/test_api/test_statistics/test_statistics_format.py126 # Check if the API statistics response data meets the expected schema. Raise an exception if not.COMMENT
109 more matches not shown…
Self-Referential Comments59 hits · 184 pts
SeverityFileLineSnippetContext
MEDIUMtools/mitre/mitredb.py758 # Create a database connectionCOMMENT
MEDIUMruleset/sca/debian/cis_debian10.yml148 remediation: "For specific configuration requirements of the /tmp mount for your environment, modify /etc/fstab or tCODE
MEDIUMruleset/sca/sles/16/cis_sles16_linux.yml149 remediation: "Create or update an entry for /tmp in either /etc/fstab OR in a systemd tmp.mount file: If /etc/fstab CODE
MEDIUMruleset/sca/sles/15/cis_sles15_linux.yml149 remediation: "Create or update an entry for /tmp in either /etc/fstab OR in a systemd tmp.mount file: If /etc/fstab CODE
MEDIUMruleset/sca/ubuntu/cis_ubuntu20-04.yml43 remediation: "For specific configuration requirements of the /tmp mount for your environment, modify /etc/fstab or tCODE
MEDIUMframework/wazuh/manager.py485 # Create a backup of the current configuration before attempting to replace itCOMMENT
MEDIUMframework/wazuh/rbac/orm.py1603 # Create a role-policy relationship if both existCOMMENT
MEDIUMframework/wazuh/rbac/orm.py1765 # Create a role-policy relationship if both existCOMMENT
MEDIUMframework/wazuh/rbac/orm.py1946 # Create a rule-role relationship if both existCOMMENT
MEDIUMframework/wazuh/rbac/orm.py2108 # Create the relationshipsCOMMENT
MEDIUMframework/wazuh/core/cluster/master.py324 # Create an event to wait for the response.COMMENT
MEDIUMframework/wazuh/core/cluster/master.py847 # Create a child process to run the task.COMMENT
MEDIUMtests/integration/conftest.py732 # Create the SocketControllersCOMMENT
MEDIUM…ntegration/test_wazuh_db/test_backup/test_db_backup.py159 # Create the database backups and assert they have been created correctlyCOMMENT
MEDIUM…asic_usage/test_orphan_promote_after_config_removal.py192 # Create the realtime-tracked file. inotify queues an "added" event;COMMENT
MEDIUM…es/test_invalid_characters/test_non_utf8_characters.py168 # Create the file with the invalid byte sequence as part of the file nameCOMMENT
MEDIUM…m/test_files/test_report_changes/test_large_changes.py188 # Create the file and and capture the event.COMMENT
MEDIUM…es/test_report_changes/test_report_changes_and_diff.py180 # Create the file and and capture the event.COMMENT
MEDIUM…_files/test_report_changes/test_report_deleted_diff.py170 # Create the file and and capture the event.COMMENT
MEDIUMpackages/macos/package_files/preinstall.sh172# Creating the groupCOMMENT
MEDIUMpackages/macos/package_files/preinstall.sh187# Creating the userCOMMENT
MEDIUMpackages/externals/external_sources.sh3# This file is sourced by packages/externals/build_external.sh inside the packageCOMMENT
MEDIUMapi/test/integration/conftest.py327 """This function is responsible for setting up the Docker environment necessary for every test.STRING
MEDIUMwodles/gcloud/tests/test_subscriber.py124 # Create a large list of fake messagesCOMMENT
MEDIUMwodles/azure/tests/db/test_orm.py60 # Create the tablesCOMMENT
MEDIUMwodles/aws/subscribers/s3_log_handler.py147 # Define the regex pattern for invalid CSV header charactersCOMMENT
MEDIUMsrc/init/darwin-addusers.sh72# Creating the groups.COMMENT
MEDIUMsrc/init/darwin-addusers.sh82# Creating the users.COMMENT
MEDIUM…ared_modules/indexer_connector/qa/test_efficacy_log.py485 # Create the index and try to insert a document with old mapping, this should fail and the element queue in the persCOMMENT
MEDIUM…ared_modules/indexer_connector/qa/test_efficacy_log.py589 # Create the index and try to insert a document with old mapping, this should fail and the element queue in the persCOMMENT
MEDIUM…ty_scanner/testtool/versionMatcher/version_verifier.sh103 # Define the callback function based on the Linux distributionCOMMENT
MEDIUMsrc/engine/tools/devContainer/e2e/init.sh324 # Create the output directory if it doesn't exist (This never happens on devContainer context)COMMENT
MEDIUM…s/engine-suite/src/engine_private/cmds/ns/import_ns.py28 # Create the api requestCOMMENT
MEDIUM…ools/engine-suite/src/engine_private/cmds/cm/delete.py16 # Create the api requestCOMMENT
MEDIUM…/tools/engine-suite/src/engine_private/cmds/cm/list.py15 # Create the api requestCOMMENT
MEDIUM…gine-suite/src/engine_private/cmds/cm/policy_upsert.py29 # Create the api requestCOMMENT
MEDIUM…gine-suite/src/engine_private/cmds/cm/policy_delete.py15 # Create the api requestCOMMENT
MEDIUM…e/tools/engine-suite/src/engine_private/cmds/cm/get.py16 # Create the api requestCOMMENT
MEDIUM…ools/engine-suite/src/engine_private/cmds/cm/upsert.py30 # Create the api requestCOMMENT
MEDIUM…ine-suite/src/engine_public/cmds/cm/policy_validate.py26 # Create the api requestCOMMENT
MEDIUM…tools/engine-suite/src/engine_public/cmds/cm/upsert.py30 # Create the api requestCOMMENT
MEDIUM…ls/engine-suite/src/engine_test/cmds/session_reload.py21 # Create the requestCOMMENT
MEDIUM…tools/engine-suite/src/engine_test/cmds/session_get.py20 # Create the requestCOMMENT
MEDIUM…ngine-suite/src/engine_test/cmds/session_delete_all.py19 # Create the requestCOMMENT
MEDIUM…ngine-suite/src/engine_test/cmds/session_delete_all.py32 # Create the list of sessions to deleteCOMMENT
MEDIUM…ls/engine-suite/src/engine_test/cmds/session_delete.py21 # Create the requestCOMMENT
MEDIUM…ools/engine-suite/src/engine_test/cmds/session_list.py19 # Create the requestCOMMENT
MEDIUM…tools/engine-suite/src/engine_test/cmds/session_add.py22 # Create the requestCOMMENT
MEDIUM…tools/engine-suite/src/engine_test/conf/integration.py110 # Create a new instance with the extracted valuesCOMMENT
MEDIUM…ne/tools/engine-suite/src/engine_router/cmds/update.py21 # Create the requestCOMMENT
MEDIUM…ne/tools/engine-suite/src/engine_router/cmds/delete.py18 # Create the requestCOMMENT
MEDIUM…ne/tools/engine-suite/src/engine_router/cmds/ingest.py18 # Create the requestCOMMENT
MEDIUM…gine/tools/engine-suite/src/engine_router/cmds/list.py18 # Create the requestCOMMENT
MEDIUM…ngine/tools/engine-suite/src/engine_router/cmds/add.py21 # Create the requestCOMMENT
MEDIUM…ne/tools/engine-suite/src/engine_router/cmds/reload.py20 # Create the requestCOMMENT
MEDIUM…ngine/tools/engine-suite/src/engine_router/cmds/get.py19 # Create the requestCOMMENT
MEDIUM…ngine/test/integration_tests/tester/steps/api_steps.py247 # Create the session pointing to namespaceId == policy_nameCOMMENT
MEDIUM…ngine/test/integration_tests/router/steps/api_steps.py239 # Create the route pointing to namespaceId == policy_nameCOMMENT
MEDIUMsrc/engine/test/acceptance_test/setup_dependencies.sh194 # Create the virtual environment (idempotent: skips if it already exists)COMMENT
Cross-Language Confusion29 hits · 179 pts
SeverityFileLineSnippetContext
HIGHframework/wazuh/core/wdb.py258 if v == "(null)":CODE
HIGHframework/wazuh/core/wdb.py283 if '"(null)"' in string:CODE
HIGHframework/wazuh/core/wdb.py284 # To prevent empty dictionaries, clean data if there was any `"(null)"` within the stringCOMMENT
HIGHframework/wazuh/core/cluster/common.py1179 # Regex to find any character different to '\x00' (null) inside a string.COMMENT
HIGHframework/wazuh/core/cluster/common.py581 self.push(msg)CODE
HIGHframework/wazuh/core/cluster/common.py910 self.push(msg)CODE
HIGHframework/wazuh/core/cluster/common.py1170 Expected length of bytearray. If any bytearray has this length and its content is null, it will be deleted.STRING
HIGHframework/wazuh/core/cluster/tests/test_common.py549 handler.push(b"message")CODE
HIGHframework/wazuh/core/tests/test_wdb.py162 Tests '(null)' values are removed from the resulting dictionarySTRING
HIGHframework/wazuh/core/tests/test_wdb.py165 nulls_string = b' [{"a": "a", "b": "(null)", "c": [1, 2, 3], "d": {"e": "(null)"}}]'CODE
HIGHframework/wazuh/core/tests/test_wdb.py273 '[{"key1": "value1"}, {"invalid": "(null)"}]',CODE
HIGHframework/wazuh/core/indexer/states_components.py148 if (ctx._source.wazuh == null) { ctx._source.wazuh = [:]; }CODE
HIGHframework/wazuh/core/indexer/states_components.py149 if (ctx._source.wazuh.agent == null) { ctx._source.wazuh.agent = [:]; }CODE
HIGHframework/wazuh/core/indexer/states_components.py151 if (ctx._source.wazuh.agent.groups != null && ctx._source.wazuh.agent.groups == params.groups) {CODE
HIGHframework/wazuh/core/indexer/states_components.py158 if (ctx._source.state == null) { ctx._source.state = [:]; }CODE
HIGHframework/wazuh/core/indexer/states_components.py246 if (ctx._source.wazuh == null) { ctx._source.wazuh = [:]; }CODE
HIGHframework/wazuh/core/indexer/states_components.py247 if (ctx._source.wazuh.agent == null) { ctx._source.wazuh.agent = [:]; }CODE
HIGHframework/wazuh/core/indexer/states_components.py248 if (ctx._source.wazuh.cluster == null) { ctx._source.wazuh.cluster = [:]; }CODE
HIGHframework/wazuh/core/indexer/states_components.py255 if (ctx._source.state == null) { ctx._source.state = [:]; }CODE
HIGH…e/tools/engine-metrics/src/engine_metrics/templates.py114 if (meta && meta.category) return meta.category;CODE
HIGH…e/tools/engine-metrics/src/engine_metrics/templates.py131 if (meta && meta.unit && UNIT_AXIS[meta.unit]) return UNIT_AXIS[meta.unit];CODE
HIGH…e/tools/engine-metrics/src/engine_metrics/templates.py219 charts[chartId] = { type: metricType, prevValue: null };CODE
HIGH…e/tools/engine-metrics/src/engine_metrics/templates.py227 if (c.prevValue === null) { c.prevValue = rawValue; return; }CODE
HIGH…e/tools/engine-metrics/src/engine_metrics/templates.py248 const ts = new Date(data.timestamp || undefined);CODE
HIGH…e/tools/engine-metrics/src/engine_metrics/templates.py248 const ts = new Date(data.timestamp || undefined);CODE
HIGH…e/tools/engine-metrics/src/engine_metrics/templates.py251 if (data.name && infoEl.dataset.set !== '1') {CODE
HIGH…e/tools/engine-metrics/src/engine_metrics/templates.py266 pushPoint(chartId, ts, m.value || 0);CODE
HIGH…e/tools/engine-metrics/src/engine_metrics/templates.py277 pushPoint(chartId, ts, m.value || 0);CODE
HIGHsrc/engine/tools/devContainer/scripts/monitor.py544 "'pkill -9 -f %s && service wazuh-manager restart' before re-running.",CODE
Structural Annotation Overuse97 hits · 166 pts
SeverityFileLineSnippetContext
LOW…asic_usage/test_orphan_promote_after_config_removal.py188 # Step 1: agent is up via daemons_handler. The baseline scan hasCOMMENT
LOW…asic_usage/test_orphan_promote_after_config_removal.py201 # Step 2: stop the agent, drop the realtime <directories> rule fromCOMMENT
LOWdocs/guide/migration/agent-groups-migration.md257### Step 1: Export from 4.xCOMMENT
LOWdocs/guide/migration/agent-groups-migration.md274### Step 2: Restore on 5.xCOMMENT
LOWdocs/guide/migration/agent-groups-migration.md293### Step 3: Configure the group on one agent onlyCOMMENT
LOWdocs/guide/migration/agent-groups-migration.md320### Step 4: Enroll the agentsCOMMENT
LOWdocs/guide/migration/agent-groups-migration.md330### Step 5: VerifyCOMMENT
LOWdocs/guide/migration/agent-groups-migration.md362### Step 6: Assign the remaining agent manuallyCOMMENT
LOWdocs/guide/migration/remote-agent-upgrade.md251### Step 1: Upgrade to v4.14.xCOMMENT
LOWdocs/guide/migration/remote-agent-upgrade.md278### Step 2: Upgrade to v5.0.0COMMENT
LOWdocs/guide/migration/rules-4x-to-5x.md159### Step 1: Inventory your 4.x rulesCOMMENT
LOWdocs/guide/migration/rules-4x-to-5x.md177### Step 2: Map rule identificationCOMMENT
LOWdocs/guide/migration/rules-4x-to-5x.md187### Step 3: Map severity levelsCOMMENT
LOWdocs/guide/migration/rules-4x-to-5x.md211### Step 4: Rewrite detection logicCOMMENT
LOWdocs/guide/migration/rules-4x-to-5x.md448### Step 5: Assign rules to an integrationCOMMENT
LOWdocs/guide/migration/rules-4x-to-5x.md496### Step 6: Migrate metadataCOMMENT
LOWdocs/guide/migration/rules-4x-to-5x.md518### Step 7: Migrate MITRE ATT&CK mappingsCOMMENT
LOWdocs/guide/migration/rules-4x-to-5x.md558### Step 8: Migrate compliance mappingsCOMMENT
LOWdocs/guide/migration/rules-4x-to-5x.md607### Step 9: Migrate tags and groupsCOMMENT
LOWdocs/guide/migration/rules-4x-to-5x.md628### Step 10: Handle rules that cannot be directly migratedCOMMENT
LOWdocs/guide/migration/rules-4x-to-5x.md715### Step 11: Deploy and testCOMMENT
LOW…ef/modules/utils/schema-validator/integration-guide.md20### Step 1: Include HeadersCOMMENT
LOW…ef/modules/utils/schema-validator/integration-guide.md28### Step 2: Initialize During Module StartupCOMMENT
LOW…ef/modules/utils/schema-validator/integration-guide.md52### Step 3: Create Helper Function for ValidationCOMMENT
LOW…ef/modules/utils/schema-validator/integration-guide.md101### Step 4: Validate Before Sending DataCOMMENT
LOW…ef/modules/utils/schema-validator/integration-guide.md130### Step 5: Implement Batch DeletionCOMMENT
LOW…ef/modules/utils/schema-validator/integration-guide.md204### Step 1: Include HeadersCOMMENT
LOW…ef/modules/utils/schema-validator/integration-guide.md212### Step 2: Initialize During Module StartupCOMMENT
LOW…ef/modules/utils/schema-validator/integration-guide.md232### Step 3: Validate Before Sending DataCOMMENT
LOW…ef/modules/utils/schema-validator/integration-guide.md270### Step 4: Implement Batch DeletionCOMMENT
LOW…s/ref/modules/utils/sync-protocol/integration-guide.md17### Step 1: Include Required HeadersCOMMENT
LOW…s/ref/modules/utils/sync-protocol/integration-guide.md34### Step 2: Initialize the ProtocolCOMMENT
LOW…s/ref/modules/utils/sync-protocol/integration-guide.md84### Step 3: Persist Module DataCOMMENT
LOW…s/ref/modules/utils/sync-protocol/integration-guide.md235### Step 4: Process Manager ResponsesCOMMENT
LOW…s/ref/modules/utils/sync-protocol/integration-guide.md261### Step 5: Trigger SynchronizationCOMMENT
LOWdocs/ref/modules/fim/architecture.md506#### Step 1: Database Entry Count CheckCOMMENT
LOWdocs/ref/modules/fim/architecture.md534#### Step 2: Data Clean NotificationCOMMENT
LOWdocs/ref/modules/fim/architecture.md562#### Step 3: Database CleanupCOMMENT
LOW…c/remoted/remoted_module/src/endpoints/authGateway.cpp145 // Step 6: feed the exact body bytes (enforces the max-body cap).COMMENT
LOW…c/remoted/remoted_module/src/endpoints/authGateway.cpp157 // Step 7: finalize + constant-time MAC comparison.COMMENT
LOWsrc/remoted/remoted_module/src/auth/authMiddleware.cpp211 // Step 1: protocol version. An empty value here must mean "absent orCOMMENT
LOWsrc/remoted/remoted_module/src/auth/authMiddleware.cpp223 // Step 2: parse Authorization.COMMENT
LOWsrc/remoted/remoted_module/src/auth/authMiddleware.cpp242 // Step 3: timestamp window.COMMENT
LOWsrc/remoted/remoted_module/src/auth/authMiddleware.cpp252 // Step 4: look up the agent key. parseAuthorization() already guarantees parsed->agentId isCOMMENT
LOWsrc/remoted/remoted_module/src/auth/authMiddleware.cpp300 // Step 5: initialize AES-CMAC with the canonical prefix. The timestamp and the agent id areCOMMENT
LOWsrc/remoted/src/legacy_task_delivery.c390 // Step 1: lock_restart (execd, plain-text protocol)COMMENT
LOWsrc/remoted/src/legacy_task_delivery.c397 // Step 2: openCOMMENT
LOWsrc/remoted/src/legacy_task_delivery.c410 // Step 3: write, chunked at a fixed 32KB (LEGACY_TASK_WPK_CHUNK_SIZE) -- a wire-protocolCOMMENT
LOWsrc/remoted/src/legacy_task_delivery.c461 // Step 4: closeCOMMENT
LOWsrc/remoted/src/legacy_task_delivery.c473 // Step 5: sha1 -- compare the agent-reported hash against the expected oneCOMMENT
LOWsrc/remoted/src/legacy_task_delivery.c499 // Step 6: upgradeCOMMENT
LOW…dules/sync_protocol/tests/test_agent_sync_protocol.cpp3243 // Step 1: Clear all DataContextCOMMENT
LOW…dules/sync_protocol/tests/test_agent_sync_protocol.cpp3249 // Step 2: Fetch pending DataValue items (onlyDataValues=true)COMMENT
LOW…sync_protocol/tests/test_sync_protocol_integration.cpp255 // Step 1: Persist DataValue itemsCOMMENT
LOW…sync_protocol/tests/test_sync_protocol_integration.cpp264 // Step 2: Persist DataContext itemsCOMMENT
LOW…sync_protocol/tests/test_sync_protocol_integration.cpp273 // Step 3: Verify we have both typesCOMMENT
LOW…sync_protocol/tests/test_sync_protocol_integration.cpp277 // Step 4: Clear all DataContextCOMMENT
LOW…sync_protocol/tests/test_sync_protocol_integration.cpp280 // Step 5: Fetch only DataValuesCOMMENT
LOW…les/agent_info/agent_info_impl/src/agent_info_impl.cpp1891 // Step 2: Calculate new versionCOMMENT
LOW…les/agent_info/agent_info_impl/src/agent_info_impl.cpp1899 // Step 3: Set new version on all modulesCOMMENT
37 more matches not shown…
Verbosity Indicators55 hits · 105 pts
SeverityFileLineSnippetContext
LOW…asic_usage/test_orphan_promote_after_config_removal.py188 # Step 1: agent is up via daemons_handler. The baseline scan hasCOMMENT
LOW…asic_usage/test_orphan_promote_after_config_removal.py201 # Step 2: stop the agent, drop the realtime <directories> rule fromCOMMENT
LOW…c/remoted/remoted_module/src/endpoints/authGateway.cpp145 // Step 6: feed the exact body bytes (enforces the max-body cap).COMMENT
LOW…c/remoted/remoted_module/src/endpoints/authGateway.cpp157 // Step 7: finalize + constant-time MAC comparison.COMMENT
LOWsrc/remoted/remoted_module/src/auth/authMiddleware.cpp211 // Step 1: protocol version. An empty value here must mean "absent orCOMMENT
LOWsrc/remoted/remoted_module/src/auth/authMiddleware.cpp223 // Step 2: parse Authorization.COMMENT
LOWsrc/remoted/remoted_module/src/auth/authMiddleware.cpp242 // Step 3: timestamp window.COMMENT
LOWsrc/remoted/remoted_module/src/auth/authMiddleware.cpp252 // Step 4: look up the agent key. parseAuthorization() already guarantees parsed->agentId isCOMMENT
LOWsrc/remoted/remoted_module/src/auth/authMiddleware.cpp300 // Step 5: initialize AES-CMAC with the canonical prefix. The timestamp and the agent id areCOMMENT
LOWsrc/remoted/src/legacy_task_delivery.c390 // Step 1: lock_restart (execd, plain-text protocol)COMMENT
LOWsrc/remoted/src/legacy_task_delivery.c397 // Step 2: openCOMMENT
LOWsrc/remoted/src/legacy_task_delivery.c410 // Step 3: write, chunked at a fixed 32KB (LEGACY_TASK_WPK_CHUNK_SIZE) -- a wire-protocolCOMMENT
LOWsrc/remoted/src/legacy_task_delivery.c461 // Step 4: closeCOMMENT
LOWsrc/remoted/src/legacy_task_delivery.c473 // Step 5: sha1 -- compare the agent-reported hash against the expected oneCOMMENT
LOWsrc/remoted/src/legacy_task_delivery.c499 // Step 6: upgradeCOMMENT
LOW…dules/sync_protocol/tests/test_agent_sync_protocol.cpp3243 // Step 1: Clear all DataContextCOMMENT
LOW…dules/sync_protocol/tests/test_agent_sync_protocol.cpp3249 // Step 2: Fetch pending DataValue items (onlyDataValues=true)COMMENT
LOW…sync_protocol/tests/test_sync_protocol_integration.cpp255 // Step 1: Persist DataValue itemsCOMMENT
LOW…sync_protocol/tests/test_sync_protocol_integration.cpp264 // Step 2: Persist DataContext itemsCOMMENT
LOW…sync_protocol/tests/test_sync_protocol_integration.cpp273 // Step 3: Verify we have both typesCOMMENT
LOW…sync_protocol/tests/test_sync_protocol_integration.cpp277 // Step 4: Clear all DataContextCOMMENT
LOW…sync_protocol/tests/test_sync_protocol_integration.cpp280 // Step 5: Fetch only DataValuesCOMMENT
LOW…les/agent_info/agent_info_impl/src/agent_info_impl.cpp1891 // Step 2: Calculate new versionCOMMENT
LOW…les/agent_info/agent_info_impl/src/agent_info_impl.cpp1899 // Step 3: Set new version on all modulesCOMMENT
LOW…les/agent_info/agent_info_impl/src/agent_info_impl.cpp1974 // Step 2: Get versions, calculate new version, and set it on all modulesCOMMENT
LOW…les/agent_info/agent_info_impl/src/agent_info_impl.cpp1983 // Step 3: Trigger flush while still paused.COMMENT
LOW…les/agent_info/agent_info_impl/src/agent_info_impl.cpp1993 // Step 4: Resume all modules immediately. The pause window is now minimized to:COMMENT
LOW…les/agent_info/agent_info_impl/src/agent_info_impl.cpp2000 // Step 5: Wait for flush completion before handing the new version to the manager.COMMENT
LOW…les/agent_info/agent_info_impl/src/agent_info_impl.cpp1834 // Step 1: Get version from each moduleCOMMENT
LOW…les/agent_info/agent_info_impl/src/agent_info_impl.cpp1953 // Step 1: Pause all coordination modulesCOMMENT
LOW…les/agent_info/agent_info_impl/src/agent_info_impl.cpp2023 // Step 6: Build indices list based on enabled modules and synchronize.COMMENT
LOWsrc/wazuh_modules/syscollector/src/syscollectorImp.cpp2770 // Step 0: Clear any existing DataContext from previous scansCOMMENT
LOWsrc/wazuh_modules/syscollector/src/syscollectorImp.cpp2774 // Step 1: Fetch pending DataValue items from syscollector_vd_sync.dbCOMMENT
LOWsrc/wazuh_modules/syscollector/src/syscollectorImp.cpp2782 // Step 2: Build exclusion sets - IDs of items already submitted as DataValueCOMMENT
LOWsrc/wazuh_modules/syscollector/src/syscollectorImp.cpp2791 // Step 3: Determine what DataContext tables are needed based on platform rulesCOMMENT
LOWsrc/wazuh_modules/syscollector/src/syscollectorImp.cpp2809 // Step 4: Fetch and submit DataContext for each required tableCOMMENT
LOWsrc/wazuh_modules/syscollector/src/syscollectorImp.cpp3694 // Step 1: Generate stateful DELETE events for each excess recordCOMMENT
LOWsrc/wazuh_modules/syscollector/src/syscollectorImp.cpp3726 // Step 2: Reset sync flag to 0 for these recordsCOMMENT
LOWsrc/wazuh_modules/syscollector/src/syscollectorImp.cpp5016 // Step 1: Delete all rows in a transactionCOMMENT
LOWsrc/wazuh_modules/syscollector/src/syscollectorImp.cpp5045 // Step 2: Re-insert rows with new sync value in a transaction to force commitCOMMENT
LOWsrc/logcollector/src/logcollector.c1533 /* Because Windows cache's files, we need to check if the fileCOMMENT
LOWsrc/engine/test/acceptance_test/acceptance_test.sh434 # Step 1: Stop managerCOMMENT
LOWsrc/engine/test/acceptance_test/acceptance_test.sh437 # Step 2: Start analysisdCOMMENT
LOWsrc/engine/test/acceptance_test/acceptance_test.sh440 # Step 3: Wait for engine readyCOMMENT
LOWsrc/engine/test/acceptance_test/acceptance_test.sh443 # Step 4: Start resource monitorCOMMENT
LOWsrc/engine/test/acceptance_test/acceptance_test.sh446 # Step 5: Grace period before benchmarkCOMMENT
LOWsrc/engine/test/acceptance_test/acceptance_test.sh466 # Step 7: Grace period after benchmarkCOMMENT
LOWsrc/engine/test/acceptance_test/acceptance_test.sh470 # Step 8: Stop monitor & analysisdCOMMENT
LOWsrc/engine/source/api/cmcrud/src/handlers.cpp439 // Step 1: Import into temp namespace (validates structure).COMMENT
LOWsrc/engine/source/api/cmcrud/src/handlers.cpp449 // Step 2: If has integrations, post a tester entry to validateCOMMENT
LOWsrc/engine/source/api/cmcrud/src/handlers.cpp470 // Step 3: Decide what to do with the persistent test session.COMMENT
LOWsrc/engine/source/iockvdb/src/manager.cpp422 // Step 1: Atomically transfer instance from source to targetCOMMENT
LOWsrc/engine/source/iockvdb/src/manager.cpp426 // Step 2: Enqueue old target instance for safe deletionCOMMENT
LOWsrc/engine/source/router/src/router.cpp169 // Step 1: Create new environment WITHOUT any lockCOMMENT
LOWsrc/engine/source/router/src/router.cpp181 // Step 2: Atomically swap the environmentCOMMENT
AI Slop Vocabulary38 hits · 82 pts
SeverityFileLineSnippetContext
MEDIUM…r_benchmark/sample_payloads/dumps/sca_full_ubuntu.json1{"metadata":{"module":"sca","mode":"ModuleFull","option":"Sync","indices":["wazuh-states-sca"]},"items":[{"seq":0,"operaCODE
MEDIUM…r_benchmark/sample_payloads/dumps/sca_full_ubuntu.json1{"metadata":{"module":"sca","mode":"ModuleFull","option":"Sync","indices":["wazuh-states-sca"]},"items":[{"seq":0,"operaCODE
MEDIUM…r_benchmark/sample_payloads/dumps/sca_full_ubuntu.json1{"metadata":{"module":"sca","mode":"ModuleFull","option":"Sync","indices":["wazuh-states-sca"]},"items":[{"seq":0,"operaCODE
MEDIUM…_benchmark/sample_payloads/dumps/sca_full_windows.json1{"metadata":{"module":"sca","mode":"ModuleFull","option":"Sync","indices":["wazuh-states-sca"]},"items":[{"seq":0,"operaCODE
MEDIUM…_benchmark/sample_payloads/dumps/sca_full_windows.json1{"metadata":{"module":"sca","mode":"ModuleFull","option":"Sync","indices":["wazuh-states-sca"]},"items":[{"seq":0,"operaCODE
MEDIUM…_benchmark/sample_payloads/dumps/sca_full_windows.json1{"metadata":{"module":"sca","mode":"ModuleFull","option":"Sync","indices":["wazuh-states-sca"]},"items":[{"seq":0,"operaCODE
MEDIUM…_benchmark/sample_payloads/dumps/sca_full_windows.json1{"metadata":{"module":"sca","mode":"ModuleFull","option":"Sync","indices":["wazuh-states-sca"]},"items":[{"seq":0,"operaCODE
MEDIUM…_benchmark/sample_payloads/dumps/sca_full_windows.json1{"metadata":{"module":"sca","mode":"ModuleFull","option":"Sync","indices":["wazuh-states-sca"]},"items":[{"seq":0,"operaCODE
MEDIUM…r_benchmark/sample_payloads/dumps/sca_full_centos.json1{"metadata":{"module":"sca","mode":"ModuleFull","option":"Sync","indices":["wazuh-states-sca"]},"items":[{"seq":0,"operaCODE
MEDIUM…r_benchmark/sample_payloads/dumps/sca_full_centos.json1{"metadata":{"module":"sca","mode":"ModuleFull","option":"Sync","indices":["wazuh-states-sca"]},"items":[{"seq":0,"operaCODE
MEDIUM…r_benchmark/sample_payloads/dumps/sca_full_centos.json1{"metadata":{"module":"sca","mode":"ModuleFull","option":"Sync","indices":["wazuh-states-sca"]},"items":[{"seq":0,"operaCODE
MEDIUMruleset/sca/windows/cis_win2012_non_r2.yml3499 # 2.3.17.5 (L1) Ensure 'User Account Control: Only elevate UIAccess applications that are installed in secure locationCOMMENT
MEDIUMruleset/sca/windows/cis_win2012_non_r2.yml8057 # 18.6.11.3 (L1) Ensure 'Require domain users to elevate when setting a network's location' is set to 'Enabled'. (AutoCOMMENT
MEDIUMruleset/sca/windows/cis_win2012_non_r2.yml8143 remediation: "To establish the recommended configuration, set the following Registry value to 0xff (255) (DWORD): HKCODE
MEDIUMruleset/sca/windows/cis_win2012_non_r2.yml12050 impact: "Users can't access OneDrive from the OneDrive app and file picker. Windows Store apps can't access OneDriveCODE
MEDIUMruleset/sca/windows/cis_win2012_non_r2.yml13746 description: 'This policy setting specifies whether computers in your environment will receive security updates fromCODE
MEDIUMruleset/sca/windows/cis_win2012r2.yml3223 # 2.3.17.5 (L1) Ensure 'User Account Control: Only elevate UIAccess applications that are installed in secure locationCOMMENT
MEDIUMruleset/sca/windows/cis_win2012r2.yml7675 # 18.6.11.3 (L1) Ensure 'Require domain users to elevate when setting a network's location' is set to 'Enabled'. (AutoCOMMENT
MEDIUMruleset/sca/windows/cis_win2012r2.yml7720 remediation: "To establish the recommended configuration, set the following Registry value to 0xff (255) (DWORD): HKCODE
MEDIUMruleset/sca/windows/cis_win2012r2.yml11824 impact: "Users can't access OneDrive from the OneDrive app and file picker. Windows Store apps can't access OneDriveCODE
MEDIUMruleset/sca/windows/cis_win2012r2.yml13670 description: 'This policy setting specifies whether computers in your environment will receive security updates fromCODE
MEDIUMframework/wazuh/core/mitre.py878 """This function loads the MITRE data in order to speed up the use of the Framework function.STRING
MEDIUMframework/wazuh/core/cluster/tests/test_worker.py196 """Mock method in order to obtain a particular output."""STRING
MEDIUMframework/wazuh/core/cluster/tests/test_worker.py232 """Mock method in order to obtain a particular output."""STRING
MEDIUMframework/wazuh/tests/data/schema_mitre_test.sql259INSERT INTO mitigation VALUES('course-of-action--aeff5887-8f9e-48d5-a523-9b395e2ce80a','Credential Dumping Mitigation',rCODE
MEDIUMframework/wazuh/tests/data/schema_mitre_test.sql518INSERT INTO use VALUES('relationship--dc10e96f-1d3c-4ab9-8df6-acdc8238ec6c','intrusion-set--bef4c620-0787-42a8-a96d-b7ebCODE
MEDIUM…/workflows/5_testintegration_inventory-sync-server.yml48 # The QA harness: --serve boots the real server (and would boot the realCOMMENT
MEDIUMwodles/aws/tests/test_guardduty.py155 """Test 'send_event' method makes the necessary calls in order to send the event to Analysisd."""STRING
MEDIUMwodles/aws/tests/test_vpcflow.py173 """Test 'iter_regions_and_accounts' method makes the necessary calls in order to process the bucket's files.STRING
MEDIUMwodles/aws/tests/test_aws_bucket.py609 """Test 'iter_regions_and_accounts' method makes the necessary calls in order to process the bucket's files."""STRING
MEDIUMwodles/aws/tests/test_aws_bucket.py631 """Test 'send_event' method makes the necessary calls in order to send an event to Analysisd."""STRING
MEDIUMwodles/aws/tests/test_aws_bucket.py791 """Test 'check_bucket' method makes the necessary method calls in order to verify that the bucket is not empty."""STRING
MEDIUMwodles/aws/tests/test_aws_bucket.py1131 """Test 'iter_regions_and_accounts' method makes the necessary calls in order to process the bucket's files."""STRING
MEDIUMwodles/aws/tests/test_cloudwatchlogs.py82 """Test 'get_alerts' method makes the expected calls in order to fetch the events and send them to Analysisd.STRING
MEDIUMwodles/aws/tests/test_cloudwatchlogs.py126 """Test 'remove_aws_log_stream' method makes the necessary calls in order to remove the specified log streamSTRING
MEDIUM…ed/remoted_module/test/unit/statelessEndpoint_test.cpp169 // full pipeline, but validatePayloadIdentity() must still be robust to it on its own contract.COMMENT
MEDIUMsrc/client-agent/https_client/demo/mock_manager.py13# Not production code; a demo harness only.COMMENT
MEDIUMsrc/engine/test/acceptance_test/acceptance_test.sh3# acceptance_test.sh – Engine benchmark harnessCOMMENT
AI Structural Patterns71 hits · 70 pts
SeverityFileLineSnippetContext
LOWframework/scripts/tests/test_agent_groups.py376CODE
LOWframework/wazuh/security.py70CODE
LOWframework/wazuh/security.py300CODE
LOWframework/wazuh/security.py472CODE
LOWframework/wazuh/security.py651CODE
LOWframework/wazuh/mitre.py32CODE
LOWframework/wazuh/mitre.py79CODE
LOWframework/wazuh/mitre.py124CODE
LOWframework/wazuh/mitre.py171CODE
LOWframework/wazuh/mitre.py218CODE
LOWframework/wazuh/mitre.py265CODE
LOWframework/wazuh/agent.py384CODE
LOWframework/wazuh/agent.py445CODE
LOWframework/wazuh/agent.py641CODE
LOWframework/wazuh/agent.py722CODE
LOWframework/wazuh/agent.py1173CODE
LOWframework/wazuh/manager.py143CODE
LOWframework/wazuh/core/results.py330CODE
LOWframework/wazuh/core/results.py347CODE
LOWframework/wazuh/core/utils.py71CODE
LOWframework/wazuh/core/mitre.py41CODE
LOWframework/wazuh/core/mitre.py184CODE
LOWframework/wazuh/core/mitre.py239CODE
LOWframework/wazuh/core/mitre.py294CODE
LOWframework/wazuh/core/mitre.py350CODE
LOWframework/wazuh/core/mitre.py436CODE
LOWframework/wazuh/core/mitre.py493CODE
LOWframework/wazuh/core/mitre.py576CODE
LOWframework/wazuh/core/mitre.py685CODE
LOWframework/wazuh/core/mitre.py784CODE
LOWframework/wazuh/core/agent.py1338CODE
LOWframework/wazuh/core/agent.py1488CODE
LOWframework/wazuh/core/agent.py69CODE
LOWframework/wazuh/core/agent.py362CODE
LOWframework/wazuh/core/agent.py1074CODE
LOWframework/wazuh/core/agent.py1013CODE
LOWframework/wazuh/core/cluster/server.py466CODE
LOWframework/wazuh/core/cluster/control.py15CODE
LOWframework/wazuh/core/cluster/dapi/dapi.py48CODE
LOWapi/api/middlewares.py385CODE
LOWapi/api/controllers/cluster_controller.py56CODE
LOWapi/api/controllers/cluster_controller.py379CODE
LOWapi/api/controllers/agent_controller.py27CODE
LOWapi/api/controllers/agent_controller.py98CODE
LOWapi/api/controllers/agent_controller.py430CODE
LOWapi/api/controllers/agent_controller.py514CODE
LOWapi/api/controllers/agent_controller.py734CODE
LOWapi/api/controllers/agent_controller.py798CODE
LOWapi/api/controllers/agent_controller.py976CODE
LOWapi/api/controllers/agent_controller.py1281CODE
LOWapi/api/controllers/agent_controller.py1330CODE
LOWapi/api/controllers/agent_controller.py1380CODE
LOWapi/api/controllers/security_controller.py195CODE
LOWapi/api/controllers/security_controller.py389CODE
LOWapi/api/controllers/security_controller.py547CODE
LOWapi/api/controllers/security_controller.py705CODE
LOWapi/api/controllers/mitre_controller.py47CODE
LOWapi/api/controllers/mitre_controller.py106CODE
LOWapi/api/controllers/mitre_controller.py168CODE
LOWapi/api/controllers/mitre_controller.py228CODE
11 more matches not shown…
Hallucination Indicators5 hits · 50 pts
SeverityFileLineSnippetContext
CRITICAL…ger_benchmark/tool_simulator/internal/runner/runner.go343 ki := r.scn.Defaults.Control.KeepaliveInterval.D()CODE
CRITICAL…ager_benchmark/tool_simulator/internal/runner/agent.go119 interval := a.r.scn.Defaults.Control.KeepaliveInterval.D()CODE
CRITICAL…ager_benchmark/tool_simulator/internal/runner/agent.go204 repeatUntil := a.r.scn.Pacing.RepeatUntil.D()CODE
CRITICALwodles/azure/azure_services/storage.py15from azure.core.exceptions import AzureError, ClientAuthenticationError, HttpResponseError, ResourceExistsError, \CODE
CRITICALwodles/azure/tests/azure_services/test_storage.py18from azure.core.exceptions import AzureError, ClientAuthenticationError, HttpResponseError, ResourceModifiedErrorCODE
Fake / Example Data50 hits · 48 pts
SeverityFileLineSnippetContext
LOWframework/wazuh/core/tests/test_configuration.py492 configuration.write_ossec_conf(new_conf="placeholder")CODE
LOWwodles/gcloud/tests/test_subscriber.py138 pubsub.subscriber.pull.side_effect = google_exceptions.DeadlineExceeded("placeholder")CODE
LOWwodles/gcloud/tests/test_bucket.py331 mock_client.get_bucket.side_effect = google_exception("placeholder")CODE
LOWwodles/aws/tests/test_aws_bucket.py1420 result = instance.load_information_from_file('fake_key')CODE
LOWwodles/aws/tests/test_aws_bucket.py1440 instance.load_information_from_file('fake_key')CODE
LOWsrc/remoted/remoted_module/tools/send_agent_json.py219 fake_id, fake_key = "999999", bytes(32) # an id that (almost certainly) isn't enrolledCODE
LOWsrc/remoted/remoted_module/tools/send_agent_json.py220 return _auth_header(fake_id, fake_key, "1", "POST", target, int(time.time()), body), bodyCODE
LOWsrc/remoted/remoted_module/tools/send_stateless.py155 fake_id, fake_key = "999999", bytes(32) # an id that (almost certainly) isn't enrolledCODE
LOWsrc/remoted/remoted_module/tools/send_stateless.py156 headers = _auth_header(fake_id, fake_key, "1", "POST", target, int(time.time()), body)CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp102 {"name", "John Doe"},CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp108 {"address", {{"street", "123 Main St"}, {"city", "New York"}}}CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp121 nlohmann::json message = {{"name", "John Doe"}, {"age", "not a number"}};CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp134 nlohmann::json message = {{"name", "John Doe"}, {"age", "30"}};CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp147 nlohmann::json message = {{"name", "John Doe"}, {"age", 30.5}};CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp162 {"name", "John Doe"}, {"age", 30}, {"extra_field", "not allowed"}CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp179 {"name", "John Doe"}, {"age", 30}, {"extra_field", nullptr}CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp195 {"name", "John Doe"},CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp197 {"address", {{"street", "123 Main St"}, {"city", "New York"}, {"extra", nullptr}}}CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp213 {"name", "John Doe"},CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp215 {"address", {{"street", "123 Main St"}, {"city", "New York"}, {"extra", "not allowed"}}}CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp229 nlohmann::json message = {{"name", "John Doe"},CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp231 {"address", {{"street", "123 Main St"}, {"city", "New York"}}}CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp245 nlohmann::json message = {{"name", "John Doe"}, {"age", 30}, {"created_at", 1735468800000}};CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp258 nlohmann::json message = {{"name", "John Doe"}, {"age", 30}, {"created_at", 1735468800}};CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp271 nlohmann::json message = {{"name", "John Doe"}, {"age", 30}, {"created_at", "2025-12-29T10:00:00.000Z"}};CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp284 nlohmann::json message = {{"name", "John Doe"}, {"age", 30}, {"created_at", "123"}};CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp297 nlohmann::json message = {{"name", "John Doe"}, {"age", 30}, {"created_at", true}};CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp331 {"name", "John Doe"},CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp346 std::string messageStr = R"({"name": "John Doe", "age": 30, "email": "john@example.com"})";CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp358 std::string messageStr = R"({"name": "John Doe", "age": 30,})";CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp398 nlohmann::json message = {{"name", nlohmann::json::array({"John Doe", "Jane Doe"})}, {"age", 30}};CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp398 nlohmann::json message = {{"name", nlohmann::json::array({"John Doe", "Jane Doe"})}, {"age", 30}};CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp424 nlohmann::json message = {{"name", "John Doe"}, {"age", nlohmann::json::array({30, 31, 32})}};CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp439 {"name", "John Doe"},CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp490 nlohmann::json message = {{"name", "John Doe"}, {"age", nlohmann::json::array({30, "invalid"})}};CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp504 nlohmann::json message = {{"name", "John Doe"}, {"is_active", "true"}};CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp517 nlohmann::json message = {{"name", "John Doe"}, {"is_active", "false"}};CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp530 nlohmann::json message = {{"name", "John Doe"}, {"is_active", 1}};CODE
LOW…odules/schema_validator/tests/schemaValidator_test.cpp543 nlohmann::json message = {{"name", "John Doe"}, {"is_active", "yes"}};CODE
LOWsrc/unit_tests/syscheckd/test_run_realtime.c212 node->key = "dummy_key";CODE
LOWsrc/unit_tests/syscheckd/test_run_realtime.c526 const char *dummy_key = "1";CODE
LOWsrc/unit_tests/syscheckd/test_run_realtime.c532 __real_OSHash_Add_ex(syscheck.realtime->dirtb, dummy_key, (void *) path);CODE
LOWsrc/unit_tests/syscheckd/test_run_realtime.c540 expect_string(__wrap_OSHash_Get_ex, key, dummy_key);CODE
LOWsrc/unit_tests/syscheckd/test_run_realtime.c829 expect_string(__wrap_OSHash_Delete_ex, key, "dummy_key");CODE
LOWsrc/unit_tests/syscheckd/test_run_realtime.c922 expect_string(__wrap_OSHash_Delete_ex, key, "dummy_key");CODE
LOWsrc/engine/source/yml/test/src/unit/yml_test.cpp80 "street": "123 Main St",CODE
LOWsrc/engine/source/yml/test/src/unit/yml_test.cpp101 street: "123 Main St"CODE
LOWsrc/engine/source/yml/test/src/unit/yml_test.cpp146 "street": "123 Main St",CODE
LOWsrc/engine/source/yml/test/src/unit/yml_test.cpp183 "street": "123 Main St",CODE
LOWsrc/engine/source/yml/test/src/unit/yml_test.cpp213 "street": "123 Main St",CODE
Example Usage Blocks10 hits · 16 pts
SeverityFileLineSnippetContext
LOWtools/purge_wazuh.sh5# Usage:COMMENT
LOWtools/manager_benchmark/cleanup_agents.sh11# Usage:COMMENT
LOWtools/manager_benchmark/run_matrix.sh10# Usage:COMMENT
LOWtools/manager_benchmark/run_benchmark.sh15# Usage:COMMENT
LOWtools/manager_benchmark/scrape_metrics.sh17# Usage:COMMENT
LOWtools/manager_benchmark/prepare_manager.sh22# Usage:COMMENT
LOWsrc/engine/tools/devContainer/scripts/pr-clang.sh8# Usage:COMMENT
LOW…/tools/devContainer/scripts/clean-unused-containers.sh15# Usage:COMMENT
LOW…gine/tools/devContainer/scripts/toggle_event_dumper.sh4# Usage:COMMENT
LOWsrc/engine/internal_packages/debs/SPECS/build_venv.sh10# Usage:COMMENT
Modern Structural Boilerplate17 hits · 16 pts
SeverityFileLineSnippetContext
LOWframework/wazuh/core/wdb_http.py208 async def set_agents_sync(self, agents_sync: dict) -> None:CODE
LOWtests/integration/conftest.py196def set_wazuh_configuration(request: pytest.FixtureRequest, test_configuration: dict) -> None:CODE
LOWtests/integration/test_api/test_rbac/conftest.py12def set_security_resources(wait_for_api_start, test_metadata: dict) -> None:CODE
LOWtests/integration/test_aws/conftest.py773def set_test_sqs_queue(metadata: dict, sqs_manager, s3_client) -> None:CODE
LOWtests/integration/test_aws/configurator.py76 def _set_session_id(self) -> None:CODE
LOWwodles/gcloud/tests/test_exceptions.py16logger = logging.getLogger(__name__)CODE
LOWwodles/gcloud/tests/test_access_logs.py18logger = logging.getLogger(__name__)CODE
LOWwodles/azure/tests/test_db_utils.py18logger = logging.getLogger(__name__)CODE
LOWwodles/azure/tests/test_azure_logs.py21logger = logging.getLogger(__name__)CODE
LOWwodles/tests/test_utils.py14logger = logging.getLogger(__name__)CODE
LOWwodles/tests/test_aws_tools.py15logger = logging.getLogger(__name__)CODE
LOWwodles/tests/test_docker_listener.py16logger = logging.getLogger(__name__)CODE
LOWwodles/aws/buckets_s3/__init__.py15__all__ = [CODE
LOWwodles/aws/subscribers/__init__.py10__all__ = [CODE
LOWwodles/aws/services/__init__.py9__all__ = [CODE
LOW…e/tools/engine-schema/src/engine_schema/cmds/_types.py26def update_types_file(mappings_wrapper: Dict[str, Any], output_path: Union[Path, str]) -> None:CODE
LOW…e/test/engine-test-utils/src/engine_handler/handler.py49 def _set_env(self) -> None:CODE
Magic Placeholder Names3 hits · 15 pts
SeverityFileLineSnippetContext
HIGHdocs/guide/migration/integratord-notifications.md193 <api_key>YOUR_API_KEY</api_key>CODE
HIGHdocs/guide/migration/integratord-notifications.md202 <api_key>YOUR_API_KEY</api_key>CODE
HIGHdocs/guide/migration/virustotal-migration.md19 <api_key>YOUR_API_KEY</api_key>CODE
Overly Generic Function Names8 hits · 11 pts
SeverityFileLineSnippetContext
LOWframework/wazuh/core/tests/test_decorators.py9 def test_function():CODE
LOWframework/wazuh/core/tests/test_decorators.py21 def test_function(a, b, c=0):CODE
LOWframework/wazuh/core/tests/test_decorators.py32 async def test_function():CODE
LOWframework/wazuh/core/tests/test_decorators.py46 async def test_function(a, b):CODE
LOWframework/wazuh/core/tests/test_decorators.py58 def test_function():CODE
LOWframework/wazuh/core/tests/test_decorators.py68 def test_function():CODE
LOWwodles/gcloud/integration.py79 def process_data(self):CODE
LOWwodles/gcloud/buckets/bucket.py233 def process_data(self):CODE
TODO Padding7 hits · 10 pts
SeverityFileLineSnippetContext
LOWsrc/shared_modules/utils/socketWrapper.hpp467 // TODO: Handle errorCOMMENT
LOWsrc/shared_modules/utils/socketWrapper.hpp472 // TODO: Handle errorCOMMENT
LOWsrc/shared_modules/utils/socketWrapper.hpp616 // TODO: Handle errorCOMMENT
LOWsrc/shared_modules/utils/socketWrapper.hpp621 // TODO: Handle errorCOMMENT
LOWsrc/shared_modules/utils/socketWrapper.hpp775 // TODO: Handle errorCOMMENT
LOWsrc/shared_modules/utils/socketWrapper.hpp780 // TODO: Handle errorCOMMENT
LOWsrc/engine/source/base/include/base/utils/ipUtils.hpp32// TODO: implementCOMMENT
Modern AI Meta-Vocabulary4 hits · 10 pts
SeverityFileLineSnippetContext
MEDIUM.github/workflows/5_testunit_contentmanager.yml73 # module's orchestration layer (contentModule, contentModuleFacade, actionOrchestrator,COMMENT
MEDIUMsrc/remoted/remoted_module/README.md1245└── deferredForwarder.hpp/.cpp# limiter + client + per-endpoint post-processing pool orchestrationCODE
MEDIUMsrc/engine/test/acceptance_test/README.md10├── acceptance_test.sh # Main orchestration scriptCODE
MEDIUMsrc/engine/source/README.md162## Startup & dependency injection (`main.cpp`)COMMENT