Servidor MCP

MacTech STIG

com.mactechsolutionsllc.www/stig
Seguridad Público y accesible MCP 2025-11-25

Qué hace este MCP

Searches DISA STIG hardening rules, retrieves implementation details, and exports assessment checklists.

export_stig_checklist
Export a DISA .ckl checklist
Generate a DISA STIG Viewer checklist (.ckl XML) for a benchmark, optionally filtered by severity and pre-populated with findings. This is the artifact an assessment actually hands over - STIG Viewer opens it, eMASS ingests it, and a POA&M is written from it. Rules you do not supply a status for come out as Not_Reviewed. Call this when the user wants a checklist, a scan result recorded, or evidence to submit, rather than just to read a rule.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['product'], 'properties': {'host_ip': {'type': 'string'}, 'product': {'enum': ['cisco_ios_router_ndm', 'cisco_ios_router_rtr', 'cisco_ios_switch_l2s', 'cisco_ios_switch_ndm', 'cisco_ios_switch_rtr', 'cisco_ise_nac', 'cisco_ise_ndm', 'cisco_nxos_switch_l2s', 'cisco_nxos_switch_ndm', 'cisco_nxos_switch_rtr', 'ubuntu2204', 'rhel8', 'rhel9', 'windows11', 'windows2022'], 'type': 'string', 'description': 'Which benchmark to build the checklist from'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['sv_id', 'status'], 'properties': {'sv_id': {'type': 'string'}, 'status': {'enum': ['Open', 'NotAFinding', 'Not_Applicable', 'Not_Reviewed'], 'type': 'string', 'description': 'Open = failed, NotAFinding = passed, Not_Applicable = out of scope'}, 'comments': {'type': 'string', 'description': 'Assessor justification'}, 'finding_details': {'type': 'string', 'description': 'What was actually observed'}}}, 'description': 'Per-rule results. Anything omitted stays Not_Reviewed - an unreviewed rule must never be reported as passing.'}, 'severity': {'enum': ['high', 'medium', 'low'], 'type': 'string', 'description': 'Limit to one severity, e.g. high for a CAT I-only checklist'}, 'host_fqdn': {'type': 'string'}, 'host_name': {'type': 'string', 'description': 'Asset hostname recorded in the checklist'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['benchmark', 'rule_count', 'status_counts', 'filename', 'note', 'ckl'], 'properties': {'ckl': {'type': 'string', 'description': 'The .ckl XML. Write it to filename rather than pasting it into a reply.'}, 'note': {'type': 'string'}, 'filename': {'type': 'string'}, 'benchmark': {'type': 'string'}, 'rule_count': {'type': 'number'}, 'status_counts': {'type': 'object', 'required': ['Open', 'NotAFinding', 'Not_Applicable', 'Not_Reviewed'], 'properties': {'Open': {'type': 'number'}, 'NotAFinding': {'type': 'number'}, 'Not_Reviewed': {'type': 'number'}, 'Not_Applicable': {'type': 'number'}}, 'additionalProperties': False}}, 'additionalProperties': False}
get_stig_rule
Get one STIG rule in full
Get the complete detail for one DISA STIG rule by its SV id (from search_stig): the requirement discussion, the exact check procedure an assessor runs, the fix text, severity, NIST control mapping, and whether it is SCAP-automatable. Call this when the user needs to implement or verify a specific rule.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['sv_id'], 'properties': {'sv_id': {'type': 'string', 'description': 'Rule id, e.g. "SV-257777r991589_rule" (fragments matched if unique)'}}}
Esquema de salida
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['sv_id', 'nist_id', 'severity', 'severity_category', 'title', 'description', 'check_text', 'fix_text', 'product', 'benchmark', 'category', 'automation_level', 'automation_source'], 'properties': {'sv_id': {'type': 'string'}, 'title': {'type': 'string'}, 'nist_id': {'type': 'string', 'description': 'CCI identifier, e.g. CCI-000366.'}, 'product': {'type': 'string'}, 'category': {'type': 'string'}, 'fix_text': {'type': 'string'}, 'severity': {'type': 'string'}, 'benchmark': {'type': 'string'}, 'check_text': {'type': 'string', 'description': "DISA's own check procedure - quote it rather than paraphrasing."}, 'description': {'type': 'string'}, 'automation_level': {'type': 'string'}, 'automation_source': {'type': 'string'}, 'severity_category': {'type': 'string', 'description': 'CAT I / II / III, the vocabulary assessors use.'}}, 'additionalProperties': False}
list_stig_benchmarks
List covered STIG benchmarks
List the DISA STIG benchmarks this server covers, with versions, rule counts, and severity breakdowns. Call this first when unsure whether a platform is covered.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {}}
search_stig
Search DISA STIG rules
Search DISA STIG hardening rules across RHEL 8, RHEL 9, Windows 11, Windows Server 2022, and Cisco IOS Router NDM benchmarks - by keyword (matched against rule IDs and titles first, then descriptions), filterable by product, severity (high/medium/low, mapping to CAT I/II/III), category, and automation level. Call this when the user asks how to harden one of these platforms, what a STIG requires, or which rules cover a topic like SSH, passwords, or auditing. Returns summaries; use get_stig_rule for full check and fix text.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['query'], 'properties': {'limit': {'type': 'integer', 'maximum': 50, 'minimum': 1, 'description': 'Max results per page (default 20)'}, 'query': {'type': 'string', 'description': 'Keyword or rule id fragment, e.g. "ssh banner" or "SV-257777"'}, 'format': {'enum': ['summary', 'links'], 'type': 'string', 'description': '"summary" (default) returns each rule inline as JSON. "links" returns MCP resource links, which hosts can render as pickable items the user opens on demand. Not smaller - the title and severity you need in order to choose are the bulk of either shape - so choose on how the client presents results, not to save tokens.'}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Skip this many matches. Pass the next_offset from a previous response to reach results beyond the first page.'}, 'product': {'enum': ['cisco_ios_router_ndm', 'cisco_ios_router_rtr', 'cisco_ios_switch_l2s', 'cisco_ios_switch_ndm', 'cisco_ios_switch_rtr', 'cisco_ise_nac', 'cisco_ise_ndm', 'cisco_nxos_switch_l2s', 'cisco_nxos_switch_ndm', 'cisco_nxos_switch_rtr', 'ubuntu2204', 'rhel8', 'rhel9', 'windows11', 'windows2022'], 'type': 'string', 'description': 'Limit to one benchmark'}, 'severity': {'enum': ['high', 'medium', 'low'], 'type': 'string', 'description': 'high=CAT I, medium=CAT II, low=CAT III'}, 'automation': {'enum': ['automated', 'manual_only'], 'type': 'string'}}}
Añadido
export_stig_checklist
17 de September de 2026 a las 12:36
Añadido
list_stig_benchmarks
17 de September de 2026 a las 12:36
Añadido
get_stig_rule
17 de September de 2026 a las 12:36
Añadido
search_stig
17 de September de 2026 a las 12:36