MacTech STIG

2,029 DISA STIG rules with official check/fix text, CCI mappings, and .ckl checklist export.

¿Debería usar esto?

Calidad y seguridad

A
Calidad de la descripción
100%
Integridad del esquema
80%
Calidad de los nombres
100%
Riesgo de envenenamiento
100%
Coincidencia de permisos
100%
Cumplimiento del protocolo
100%

Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.

Costo de contexto

~1,666Tokens (definiciones de herramientas)
~3.4 KBTamaño de respuesta típico
Impacto moderado en la atención (1.30% del contexto de 128k)

Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.

Instalar

Instalación con un clic

Agrega esto a tu archivo `claude_desktop_config.json`:

{
  "mcpServers": {
    "stig": {
      "url": "https://www.mactechsolutionsllc.com/api/mcp/stig"
    }
  }
}

Puntos de conexión remotos

https://www.mactechsolutionsllc.com/api/mcp/stigstreamable-http

Qué puede hacer

Inventario de herramientas

Herramientas (4)

🟢 Solo lectura🟡 Escritura🔴 Eliminación⚪ Desconocido
🟢search_stig(query, product, severity, automation, limit, ...)

Search DISA STIG hardening rules across RHEL 8, RHEL 9, Windows 11, Windows Server 2022, and Cisco IOS Router NDM benchmarks - by keyword (matched against rule IDs and titles first, then descriptions), filterable by product, severity (high/medium/low, mapping to CAT I/II/III), category, and automation level. Call this when the user asks how to harden one of these platforms, what a STIG requires, or which rules cover a topic like SSH, passwords, or auditing. Returns summaries; use get_stig_rule for full check and fix text.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "Keyword or rule id fragment, e.g. \"ssh banner\" or \"SV-257777\""
    },
    "product": {
      "description": "Limit to one benchmark",
      "type": "string",
      "enum": [
        "cisco_ios_router_ndm",
        "cisco_ios_router_rtr",
        "cisco_ios_switch_l2s",
        "cisco_ios_switch_ndm",
        "cisco_ios_switch_rtr",
        "cisco_ise_nac",
        "cisco_ise_ndm",
        "cisco_nxos_switch_l2s",
        "cisco_nxos_switch_ndm",
        "cisco_nxos_switch_rtr",
        "ubuntu2204",
        "rhel8",
        "rhel9",
        "windows11",
        "windows2022"
      ]
    },
    "severity": {
      "description": "high=CAT I, medium=CAT II, low=CAT III",
      "type": "string",
      "enum": [
        "high",
        "medium",
        "low"
      ]
    },
    "automation": {
      "type": "string",
      "enum": [
        "automated",
        "manual_only"
      ]
    },
    "limit": {
      "description": "Max results per page (default 20)",
      "type": "integer",
      "minimum": 1,
      "maximum": 50
    },
    "offset": {
      "description": "Skip this many matches. Pass the next_offset from a previous response to reach results beyond the first page.",
      "type": "integer",
      "minimum": 0,
      "maximum": 9007199254740991
    },
    "format": {
      "description": "\"summary\" (default) returns each rule inline as JSON. \"links\" returns MCP resource links, which hosts can render as pickable items the user opens on demand. Not smaller - the title and severity you need in order to choose are the bulk of either shape - so choose on how the client presents results, not to save tokens.",
      "type": "string",
      "enum": [
        "summary",
        "links"
      ]
    }
  },
  "required": [
    "query"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema"
}
🟢get_stig_rule(sv_id)

Get the complete detail for one DISA STIG rule by its SV id (from search_stig): the requirement discussion, the exact check procedure an assessor runs, the fix text, severity, NIST control mapping, and whether it is SCAP-automatable. Call this when the user needs to implement or verify a specific rule.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "sv_id": {
      "type": "string",
      "description": "Rule id, e.g. \"SV-257777r991589_rule\" (fragments matched if unique)"
    }
  },
  "required": [
    "sv_id"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema"
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "sv_id": {
      "type": "string"
    },
    "nist_id": {
      "type": "string",
      "description": "CCI identifier, e.g. CCI-000366."
    },
    "severity": {
      "type": "string"
    },
    "severity_category": {
      "type": "string",
      "description": "CAT I / II / III, the vocabulary assessors use."
    },
    "title": {
      "type": "string"
    },
    "description": {
      "type": "string"
    },
    "check_text": {
      "type": "string",
      "description": "DISA's own check procedure - quote it rather than paraphrasing."
    },
    "fix_text": {
      "type": "string"
    },
    "product": {
      "type": "string"
    },
    "benchmark": {
      "type": "string"
    },
    "category": {
      "type": "string"
    },
    "automation_level": {
      "type": "string"
    },
    "automation_source": {
      "type": "string"
    }
  },
  "required": [
    "sv_id",
    "nist_id",
    "severity",
    "severity_category",
    "title",
    "description",
    "check_text",
    "fix_text",
    "product",
    "benchmark",
    "category",
    "automation_level",
    "automation_source"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}
🟢list_stig_benchmarks

List the DISA STIG benchmarks this server covers, with versions, rule counts, and severity breakdowns. Call this first when unsure whether a platform is covered.

Esquema de entrada

{
  "type": "object",
  "properties": {},
  "$schema": "https://json-schema.org/draft/2020-12/schema"
}
🟢export_stig_checklist(product, severity, host_name, host_ip, host_fqdn, ...)

Generate a DISA STIG Viewer checklist (.ckl XML) for a benchmark, optionally filtered by severity and pre-populated with findings. This is the artifact an assessment actually hands over - STIG Viewer opens it, eMASS ingests it, and a POA&M is written from it. Rules you do not supply a status for come out as Not_Reviewed. Call this when the user wants a checklist, a scan result recorded, or evidence to submit, rather than just to read a rule.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "product": {
      "type": "string",
      "enum": [
        "cisco_ios_router_ndm",
        "cisco_ios_router_rtr",
        "cisco_ios_switch_l2s",
        "cisco_ios_switch_ndm",
        "cisco_ios_switch_rtr",
        "cisco_ise_nac",
        "cisco_ise_ndm",
        "cisco_nxos_switch_l2s",
        "cisco_nxos_switch_ndm",
        "cisco_nxos_switch_rtr",
        "ubuntu2204",
        "rhel8",
        "rhel9",
        "windows11",
        "windows2022"
      ],
      "description": "Which benchmark to build the checklist from"
    },
    "severity": {
      "description": "Limit to one severity, e.g. high for a CAT I-only checklist",
      "type": "string",
      "enum": [
        "high",
        "medium",
        "low"
      ]
    },
    "host_name": {
      "description": "Asset hostname recorded in the checklist",
      "type": "string"
    },
    "host_ip": {
      "type": "string"
    },
    "host_fqdn": {
      "type": "string"
    },
    "findings": {
      "description": "Per-rule results. Anything omitted stays Not_Reviewed - an unreviewed rule must never be reported as passing.",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "sv_id": {
            "type": "string"
          },
          "status": {
            "type": "string",
            "enum": [
              "Open",
              "NotAFinding",
              "Not_Applicable",
              "Not_Reviewed"
            ],
            "description": "Open = failed, NotAFinding = passed, Not_Applicable = out of scope"
          },
          "finding_details": {
            "description": "What was actually observed",
            "type": "string"
          },
          "comments": {
            "description": "Assessor justification",
            "type": "string"
          }
        },
        "required": [
          "sv_id",
          "status"
        ]
      }
    }
  },
  "required": [
    "product"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema"
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "benchmark": {
      "type": "string"
    },
    "rule_count": {
      "type": "number"
    },
    "status_counts": {
      "type": "object",
      "properties": {
        "Open": {
          "type": "number"
        },
        "NotAFinding": {
          "type": "number"
        },
        "Not_Applicable": {
          "type": "number"
        },
        "Not_Reviewed": {
          "type": "number"
        }
      },
      "required": [
        "Open",
        "NotAFinding",
        "Not_Applicable",
        "Not_Reviewed"
      ],
      "additionalProperties": false
    },
    "filename": {
      "type": "string"
    },
    "note": {
      "type": "string"
    },
    "ckl": {
      "type": "string",
      "description": "The .ckl XML. Write it to filename rather than pasting it into a reply."
    }
  },
  "required": [
    "benchmark",
    "rule_count",
    "status_counts",
    "filename",
    "note",
    "ckl"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

Comunidad

Califica este servidor

Evidencia

Observaciones recientes

verificadoversión no registrada4 herramientas
verificadoversión no registrada4 herramientas