New:Introducing Socket Scanning for VS Code Marketplace Extensions.Learn more →
Get Started

stig-mcp

Package Overview
Dependencies
Maintainers
1
Versions
5
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

stig-mcp

MCP server: MITRE ATT&CK® -> NIST 800-53r5 -> DISA STIG fix/check steps, mitigations and detections

Source
pipPyPI
Version
0.2.0
Weekly downloads
527
Maintainers
1
Weekly downloads
 
Created

stig-mcp

Local MCP server that maps MITRE ATT&CK® techniques (and actors) to the NIST 800-53r5 controls that mitigate them, with the DISA STIG fix and check steps for the systems under consideration, severity-ordered, and ATT&CK's own mitigations and detections where ATT&CK publishes them.

Prerequisite

stig-mcp is published on PyPI and runs through uvx, which comes with uv. Install uv, then check that uvx --version runs in a new terminal. Restart VS Code or Claude Code after installing uv so it sees the new PATH.

Quick start

VS Code (GitHub Copilot)

  • Click this badge. VS Code opens and offers to install stig-mcp; choose Install.

    Install in VS Code

  • Open Copilot Chat and set the mode dropdown to Agent. MCP tools are not available in Ask or Edit mode.

  • Ask: Install the stig-mcp knowledge base. This is a one-time download of about 6 MB. Allow the tool when VS Code asks.

If that doesn't work, see troubleshooting or setting up VS Code by hand.

Claude Code

  • Inside a Claude Code session (2.1.275 or later), run:

    /plugin install stig-mcp --marketplace jeneric/STIG-MCP
    
  • Ask: Install the stig-mcp knowledge base. This is a one-time download of about 6 MB. Allow the tool when Claude Code asks.

If that doesn't work, see troubleshooting or setting up Claude Code by hand.

Example prompts

With the knowledge base installed, try:

  • What DISA STIG steps mitigate T1078 on Windows 11?
  • Which ATT&CK techniques does APT29 use?
  • Which STIG benchmarks apply to RHEL 9?
  • What can I detect of APT29 on Windows Server 2022 with Security and Sysmon logs?

More example prompts are in the user guide, with how to get more out of it and how to make sure the agent answers from the server.

Other MCP clients

Use this only if you are not using VS Code or Claude Code. Any client that launches a local (stdio) MCP server works with this configuration, shown in the common mcpServers shape:

{
  "mcpServers": {
    "stig-mcp": {
      "command": "uvx",
      "args": ["stig-mcp"],
      "env": { "UV_SYSTEM_CERTS": "true", "UV_NATIVE_TLS": "true" }
    }
  }
}

The two environment variables let uv download stig-mcp behind a TLS-inspecting proxy. They are harmless on most other hosts; that section names the one exception. Then ask the agent to install the stig-mcp knowledge base, as in the quick start.

docs/install.md has the details:

What this server fetches

  • The MCP server contacts nothing unless check_sources or install_knowledge_base is called. Then it sends HTTPS GET requests to api.github.com (this repository's release listing) and github.com (/jeneric/STIG-MCP/releases/download/...), which redirects to release-assets.githubusercontent.com or objects.githubusercontent.com. Any other URL, a redirect included, is refused. Nothing is uploaded, and there is no telemetry. install_knowledge_base given a file path and its SHA-256 requests nothing at all.
  • stig-mcp-install-kb contacts the same hosts, and nothing at all with --file.
  • stig-mcp-fetch, used only to build the knowledge base yourself, downloads from raw.githubusercontent.com and api.github.com (MITRE ATT&CK, the CTID mapping, the NIST 800-53 catalog) and from dl.dod.cyber.mil (DISA).

PRIVACY.md states what each of these requests sends and what is stored locally.

Documentation

  • docs/install.md: installation details for every client, where the data lives, and troubleshooting.
  • docs/user-guide.md: for a person talking to an LLM that has this server wired in.
  • docs/operations.md: for whoever installs, builds and maintains the knowledge base.
  • SECURITY.md: reporting a vulnerability, and what is in scope.
  • CONTRIBUTING.md: working from a source checkout, running the tests, and the project's conventions.
  • RELEASING.md: for the maintainer, publishing the package to PyPI and the MCP Registry.
  • PRIVACY.md: what the server and the fetch tool contact, and what is stored locally.

Third-party content

The knowledge base aggregates MITRE ATT&CK, CTID mapping, DISA STIG, DISA CCI list, and NIST OSCAL content. See NOTICE for attribution and licensing obligations and licenses/apache-2.0.txt for the Apache 2.0 license text that notice requires.

Development

Developed with the assistance of Claude Code (Anthropic). All changes were reviewed and tested by the maintainer.

FAQs

Related posts