The STIG MCP Server
1,406 DISA STIG hardening rules — RHEL 8/9, Windows 11, Windows Server 2022, Cisco IOS Router NDM — with real check and fix text, searchable from your AI assistant. Free, no login.
Connect it
Claude Code
claude mcp add --transport http mactech-stig https://www.mactechsolutionsllc.com/api/mcp/stigAny MCP client (JSON config)
{
"mcpServers": {
"mactech-stig": {
"url": "https://www.mactechsolutionsllc.com/api/mcp/stig"
}
}
}What it can do
search_stig
Keyword search across all five benchmarks — rule IDs and titles first, then descriptions — filterable by product, severity (CAT I/II/III), and SCAP automatability.
“Which RHEL 9 CAT I rules cover SSH configuration?”
get_stig_rule
One rule in full: requirement discussion, the exact check procedure an assessor runs, the fix text, and the NIST control mapping.
“Give me the full check and fix for SV-257777.”
list_stig_benchmarks
Coverage map: the five benchmarks with versions, rule counts, and severity breakdowns.
“Is Windows Server 2022 covered, and at what STIG version?”
Frequently asked questions
What is the MacTech STIG MCP server?
A free Model Context Protocol server that gives AI assistants searchable access to DISA Security Technical Implementation Guide (STIG) rules: the requirement discussion, the exact check procedure, the fix text, severity category (CAT I/II/III), NIST control mapping, and whether the rule is SCAP-automatable.
Which STIG benchmarks are covered?
Five benchmarks, 1,406 rules total: RHEL 8 (v2r5), RHEL 9 (v2r6), Windows 11 (v2r5), Windows Server 2022 (v2r6), and Cisco IOS Router NDM (v3r5). For technologies outside this set, DISA publishes the full STIG library at public.cyber.mil/stigs.
Why use this instead of asking the AI directly?
STIG rule IDs, check commands, and fix procedures are exactly the kind of detail language models garble from memory — a hallucinated registry path or sysctl key wastes an afternoon. This server returns the actual benchmark text, so the commands your assistant quotes are the real ones.
Does it require authentication or store anything?
No auth, free, stateless. We keep daily aggregate counts only (connections, tool names, client application names) — no payloads, no raw IPs, no user agents.
Also from MacTech: the CMMC / NIST 800-171 server and the Federal Market server. MacTech Solutions is an SDVOSB that hardens and certifies defense-contractor environments — talk to us.