Server data from the Official MCP Registry
MCP server mapping MITRE ATT&CK® -> NIST 800-53r5 -> DISA STIG fix/check steps
About
MCP server mapping MITRE ATT&CK® -> NIST 800-53r5 -> DISA STIG fix/check steps
Security Report
Valid MCP server (1 strong, 1 medium validity signals). 1 code issue detected. No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry. 1 finding(s) downgraded by scanner intelligence.
4 files analyzed · 2 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: STIG_MCP_DATA
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-jeneric-stig-mcp": {
"env": {
"STIG_MCP_DATA": "your-stig-mcp-data-here"
},
"args": [
"stig-mcp"
],
"command": "uvx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
stig-mcp
Local MCP server that maps MITRE ATT&CK® techniques (and actors) to the NIST 800-53r5 controls that mitigate them, with the DISA STIG fix and check steps for the systems under consideration, severity-ordered.
Prerequisite
stig-mcp is published on PyPI and runs through uvx,
which comes with uv.
Install uv, then check that
uvx --version runs in a new terminal. Restart VS Code or Claude Code after installing uv
so it sees the new PATH.
Quick start
VS Code (GitHub Copilot)
-
Click this badge. VS Code opens and offers to install stig-mcp; choose Install.
-
Open Copilot Chat and set the mode dropdown to Agent. MCP tools are not available in Ask or Edit mode.
-
Ask:
Install the stig-mcp knowledge base.This is a one-time download of about 6 MB. Allow the tool when VS Code asks.
If that doesn't work, see troubleshooting or setting up VS Code by hand.
Claude Code
-
Inside a Claude Code session (2.1.275 or later), run:
/plugin install stig-mcp --marketplace jeneric/STIG-MCP -
Ask:
Install the stig-mcp knowledge base.This is a one-time download of about 6 MB. Allow the tool when Claude Code asks.
If that doesn't work, see troubleshooting or setting up Claude Code by hand.
Example prompts
With the knowledge base installed, try:
What DISA STIG steps mitigate T1078 on Windows 11?Which ATT&CK techniques does APT29 use?Which STIG benchmarks apply to RHEL 9?
More example prompts are in the user guide, with how to get more out of it and how to make sure the agent answers from the server.
Other MCP clients
Use this only if you are not using VS Code or Claude Code. Any client that launches a local
(stdio) MCP server works with this configuration, shown in the common mcpServers shape:
{
"mcpServers": {
"stig-mcp": {
"command": "uvx",
"args": ["stig-mcp"],
"env": { "UV_SYSTEM_CERTS": "true", "UV_NATIVE_TLS": "true" }
}
}
}
The two environment variables let uv download stig-mcp behind a TLS-inspecting proxy. They are harmless on most other hosts; that section names the one exception. Then ask the agent to install the stig-mcp knowledge base, as in the quick start.
docs/install.md has the details:
- manual VS Code and Claude Code setup
- running from a source checkout
- installing the knowledge base without an agent or without network access
- where the data lives
- troubleshooting
What this server fetches
- The MCP server contacts nothing unless
check_sourcesorinstall_knowledge_baseis called. Then it sends HTTPS GET requests toapi.github.com(this repository's release listing) andgithub.com(/jeneric/STIG-MCP/releases/download/...), which redirects torelease-assets.githubusercontent.comorobjects.githubusercontent.com. Any other URL, a redirect included, is refused. Nothing is uploaded, and there is no telemetry.install_knowledge_basegiven a file path and its SHA-256 requests nothing at all. stig-mcp-install-kbcontacts the same hosts, and nothing at all with--file.stig-mcp-fetch, used only to build the knowledge base yourself, downloads fromraw.githubusercontent.comandapi.github.com(MITRE ATT&CK, the CTID mapping, the NIST 800-53 catalog) and fromdl.dod.cyber.mil(DISA).
PRIVACY.md states what each of these requests sends and what is stored locally.
Documentation
- docs/install.md: installation details for every client, where the data lives, and troubleshooting.
- docs/user-guide.md: for a person talking to an LLM that has this server wired in.
- docs/operations.md: for whoever installs, builds and maintains the knowledge base.
- SECURITY.md: reporting a vulnerability, and what is in scope.
- CONTRIBUTING.md: working from a source checkout, running the tests, and the project's conventions.
- RELEASING.md: for the maintainer, publishing the package to PyPI and the MCP Registry.
- PRIVACY.md: what the server and the fetch tool contact, and what is stored locally.
Third-party content
The knowledge base aggregates MITRE ATT&CK, CTID mapping, DISA STIG, DISA CCI list, and NIST OSCAL content. See NOTICE for attribution and licensing obligations and licenses/apache-2.0.txt for the Apache 2.0 license text that notice requires.
Development
Developed with the assistance of Claude Code (Anthropic). All changes were reviewed and tested by the maintainer.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Worldmonitor
Freeby Koala73 · Developer Tools
Live markets, conflicts, country risk, chokepoints, energy, and China decision signals. 86 tools.
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
