MacTech STIG

2,029 DISA STIG rules with official check/fix text, CCI mappings, and .ckl checklist export.

사용해야 할까요

품질 및 안전성

A
설명 품질
100%
스키마 완전성
80%
이름 품질
100%
오염 위험
100%
권한 일치
100%
프로토콜 준수
100%

도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.

컨텍스트 비용

~1,666토큰 (도구 정의)
~3.4 KB일반적인 응답 크기
중간 정도의 주의 영향 (128k 컨텍스트의 1.30%)

이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.

설치

원클릭 설치

`claude_desktop_config.json` 파일에 다음을 추가하세요:

{
  "mcpServers": {
    "stig": {
      "url": "https://www.mactechsolutionsllc.com/api/mcp/stig"
    }
  }
}

원격 엔드포인트

https://www.mactechsolutionsllc.com/api/mcp/stigstreamable-http

할 수 있는 일

도구 목록

도구 (4)

🟢 읽기 전용🟡 쓰기🔴 삭제⚪ 알 수 없음
🟢search_stig(query, product, severity, automation, limit, ...)

Search DISA STIG hardening rules across RHEL 8, RHEL 9, Windows 11, Windows Server 2022, and Cisco IOS Router NDM benchmarks - by keyword (matched against rule IDs and titles first, then descriptions), filterable by product, severity (high/medium/low, mapping to CAT I/II/III), category, and automation level. Call this when the user asks how to harden one of these platforms, what a STIG requires, or which rules cover a topic like SSH, passwords, or auditing. Returns summaries; use get_stig_rule for full check and fix text.

입력 스키마

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "Keyword or rule id fragment, e.g. \"ssh banner\" or \"SV-257777\""
    },
    "product": {
      "description": "Limit to one benchmark",
      "type": "string",
      "enum": [
        "cisco_ios_router_ndm",
        "cisco_ios_router_rtr",
        "cisco_ios_switch_l2s",
        "cisco_ios_switch_ndm",
        "cisco_ios_switch_rtr",
        "cisco_ise_nac",
        "cisco_ise_ndm",
        "cisco_nxos_switch_l2s",
        "cisco_nxos_switch_ndm",
        "cisco_nxos_switch_rtr",
        "ubuntu2204",
        "rhel8",
        "rhel9",
        "windows11",
        "windows2022"
      ]
    },
    "severity": {
      "description": "high=CAT I, medium=CAT II, low=CAT III",
      "type": "string",
      "enum": [
        "high",
        "medium",
        "low"
      ]
    },
    "automation": {
      "type": "string",
      "enum": [
        "automated",
        "manual_only"
      ]
    },
    "limit": {
      "description": "Max results per page (default 20)",
      "type": "integer",
      "minimum": 1,
      "maximum": 50
    },
    "offset": {
      "description": "Skip this many matches. Pass the next_offset from a previous response to reach results beyond the first page.",
      "type": "integer",
      "minimum": 0,
      "maximum": 9007199254740991
    },
    "format": {
      "description": "\"summary\" (default) returns each rule inline as JSON. \"links\" returns MCP resource links, which hosts can render as pickable items the user opens on demand. Not smaller - the title and severity you need in order to choose are the bulk of either shape - so choose on how the client presents results, not to save tokens.",
      "type": "string",
      "enum": [
        "summary",
        "links"
      ]
    }
  },
  "required": [
    "query"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema"
}
🟢get_stig_rule(sv_id)

Get the complete detail for one DISA STIG rule by its SV id (from search_stig): the requirement discussion, the exact check procedure an assessor runs, the fix text, severity, NIST control mapping, and whether it is SCAP-automatable. Call this when the user needs to implement or verify a specific rule.

입력 스키마

{
  "type": "object",
  "properties": {
    "sv_id": {
      "type": "string",
      "description": "Rule id, e.g. \"SV-257777r991589_rule\" (fragments matched if unique)"
    }
  },
  "required": [
    "sv_id"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema"
}

출력 스키마

{
  "type": "object",
  "properties": {
    "sv_id": {
      "type": "string"
    },
    "nist_id": {
      "type": "string",
      "description": "CCI identifier, e.g. CCI-000366."
    },
    "severity": {
      "type": "string"
    },
    "severity_category": {
      "type": "string",
      "description": "CAT I / II / III, the vocabulary assessors use."
    },
    "title": {
      "type": "string"
    },
    "description": {
      "type": "string"
    },
    "check_text": {
      "type": "string",
      "description": "DISA's own check procedure - quote it rather than paraphrasing."
    },
    "fix_text": {
      "type": "string"
    },
    "product": {
      "type": "string"
    },
    "benchmark": {
      "type": "string"
    },
    "category": {
      "type": "string"
    },
    "automation_level": {
      "type": "string"
    },
    "automation_source": {
      "type": "string"
    }
  },
  "required": [
    "sv_id",
    "nist_id",
    "severity",
    "severity_category",
    "title",
    "description",
    "check_text",
    "fix_text",
    "product",
    "benchmark",
    "category",
    "automation_level",
    "automation_source"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}
🟢list_stig_benchmarks

List the DISA STIG benchmarks this server covers, with versions, rule counts, and severity breakdowns. Call this first when unsure whether a platform is covered.

입력 스키마

{
  "type": "object",
  "properties": {},
  "$schema": "https://json-schema.org/draft/2020-12/schema"
}
🟢export_stig_checklist(product, severity, host_name, host_ip, host_fqdn, ...)

Generate a DISA STIG Viewer checklist (.ckl XML) for a benchmark, optionally filtered by severity and pre-populated with findings. This is the artifact an assessment actually hands over - STIG Viewer opens it, eMASS ingests it, and a POA&M is written from it. Rules you do not supply a status for come out as Not_Reviewed. Call this when the user wants a checklist, a scan result recorded, or evidence to submit, rather than just to read a rule.

입력 스키마

{
  "type": "object",
  "properties": {
    "product": {
      "type": "string",
      "enum": [
        "cisco_ios_router_ndm",
        "cisco_ios_router_rtr",
        "cisco_ios_switch_l2s",
        "cisco_ios_switch_ndm",
        "cisco_ios_switch_rtr",
        "cisco_ise_nac",
        "cisco_ise_ndm",
        "cisco_nxos_switch_l2s",
        "cisco_nxos_switch_ndm",
        "cisco_nxos_switch_rtr",
        "ubuntu2204",
        "rhel8",
        "rhel9",
        "windows11",
        "windows2022"
      ],
      "description": "Which benchmark to build the checklist from"
    },
    "severity": {
      "description": "Limit to one severity, e.g. high for a CAT I-only checklist",
      "type": "string",
      "enum": [
        "high",
        "medium",
        "low"
      ]
    },
    "host_name": {
      "description": "Asset hostname recorded in the checklist",
      "type": "string"
    },
    "host_ip": {
      "type": "string"
    },
    "host_fqdn": {
      "type": "string"
    },
    "findings": {
      "description": "Per-rule results. Anything omitted stays Not_Reviewed - an unreviewed rule must never be reported as passing.",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "sv_id": {
            "type": "string"
          },
          "status": {
            "type": "string",
            "enum": [
              "Open",
              "NotAFinding",
              "Not_Applicable",
              "Not_Reviewed"
            ],
            "description": "Open = failed, NotAFinding = passed, Not_Applicable = out of scope"
          },
          "finding_details": {
            "description": "What was actually observed",
            "type": "string"
          },
          "comments": {
            "description": "Assessor justification",
            "type": "string"
          }
        },
        "required": [
          "sv_id",
          "status"
        ]
      }
    }
  },
  "required": [
    "product"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema"
}

출력 스키마

{
  "type": "object",
  "properties": {
    "benchmark": {
      "type": "string"
    },
    "rule_count": {
      "type": "number"
    },
    "status_counts": {
      "type": "object",
      "properties": {
        "Open": {
          "type": "number"
        },
        "NotAFinding": {
          "type": "number"
        },
        "Not_Applicable": {
          "type": "number"
        },
        "Not_Reviewed": {
          "type": "number"
        }
      },
      "required": [
        "Open",
        "NotAFinding",
        "Not_Applicable",
        "Not_Reviewed"
      ],
      "additionalProperties": false
    },
    "filename": {
      "type": "string"
    },
    "note": {
      "type": "string"
    },
    "ckl": {
      "type": "string",
      "description": "The .ckl XML. Write it to filename rather than pasting it into a reply."
    }
  },
  "required": [
    "benchmark",
    "rule_count",
    "status_counts",
    "filename",
    "note",
    "ckl"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

커뮤니티

이 서버 평가하기

증거

최근 관측

검증됨버전이 기록되지 않음도구 4개
검증됨버전이 기록되지 않음도구 4개