The STIG MCP Server

1,406 DISA STIG hardening rules — RHEL 8/9, Windows 11, Windows Server 2022, Cisco IOS Router NDM — with real check and fix text, searchable from your AI assistant. Free, no login.

Connect it

Claude Code

claude mcp add --transport http mactech-stig https://www.mactechsolutionsllc.com/api/mcp/stig

Any MCP client (JSON config)

{
  "mcpServers": {
    "mactech-stig": {
      "url": "https://www.mactechsolutionsllc.com/api/mcp/stig"
    }
  }
}

What it can do

search_stig

Keyword search across all five benchmarks — rule IDs and titles first, then descriptions — filterable by product, severity (CAT I/II/III), and SCAP automatability.

“Which RHEL 9 CAT I rules cover SSH configuration?”

get_stig_rule

One rule in full: requirement discussion, the exact check procedure an assessor runs, the fix text, and the NIST control mapping.

“Give me the full check and fix for SV-257777.”

list_stig_benchmarks

Coverage map: the five benchmarks with versions, rule counts, and severity breakdowns.

“Is Windows Server 2022 covered, and at what STIG version?”

Frequently asked questions

What is the MacTech STIG MCP server?

A free Model Context Protocol server that gives AI assistants searchable access to DISA Security Technical Implementation Guide (STIG) rules: the requirement discussion, the exact check procedure, the fix text, severity category (CAT I/II/III), NIST control mapping, and whether the rule is SCAP-automatable.

Which STIG benchmarks are covered?

Five benchmarks, 1,406 rules total: RHEL 8 (v2r5), RHEL 9 (v2r6), Windows 11 (v2r5), Windows Server 2022 (v2r6), and Cisco IOS Router NDM (v3r5). For technologies outside this set, DISA publishes the full STIG library at public.cyber.mil/stigs.

Why use this instead of asking the AI directly?

STIG rule IDs, check commands, and fix procedures are exactly the kind of detail language models garble from memory — a hallucinated registry path or sysctl key wastes an afternoon. This server returns the actual benchmark text, so the commands your assistant quotes are the real ones.

Does it require authentication or store anything?

No auth, free, stateless. We keep daily aggregate counts only (connections, tool names, client application names) — no payloads, no raw IPs, no user agents.

Also from MacTech: the CMMC / NIST 800-171 server and the Federal Market server. MacTech Solutions is an SDVOSB that hardens and certifies defense-contractor environments — talk to us.