stig-mcp
Related Servers
Alternatives to stig-mcp
No user-submitted related servers found.
Related Servers
- AlicenseAqualityDmaintenanceEnables AI-native access to the MITRE ATT\&CK framework, allowing LLMs and agents to query techniques, threat groups, software, and generate ATT\&CK Navigator layers for threat intelligence and security workflows.6554 npm5Apache 2.0
- FlicenseNot gradedqualityDmaintenanceEnables querying the MITRE ATT\&CK framework for adversarial tactics, techniques, mitigations, and detection methods through natural language, supporting both ID-based and fuzzy name-based searches.3-
- AlicenseBqualityDmaintenanceEnables cyber defenders to query ATT\&CK techniques, list tactics, map incidents to techniques, look up threat actor groups and mitigations, all via the MCP protocol.5MIT
- FlicenseNot gradedqualityBmaintenanceEnables searching and retrieving DISA STIG rules, listing benchmarks, and exporting STIG checklists.-
- FlicenseNot gradedqualityDmaintenanceProvides search, detail lookup, and gap listing tools for a security control inventory, enabling natural language queries about control status and gaps.-
- AlicenseNot gradedqualityBmaintenanceEnables querying MITRE ATT&CK STIX data, including adversary tactics, techniques, and procedures, via an MCP server connected to the Pipeworx gateway.185 npmMIT
TDQS
Scored across 8 tools
Tools are largely distinct: search_techniques finds ATT&CK techniques, mitigations_for_technique maps a technique, techniques_for_actor maps an actor, and finding_details fetches check/fix text. Minor overlap exists between mitigations_for_technique and techniques_for_actor with include_mitigations, and resolve_system vs list_stigs both surface STIGs, but the descriptions differentiate them well.
All names use snake_case, but the set mixes verb_noun names (search_techniques, resolve_system, list_stigs, install_knowledge_base, check_sources) with noun_phrase names (mitigations_for_technique, techniques_for_actor, finding_details). The pattern is readable but not a single predictable convention.
Eight tools is well within the 3-15 range and each has a clear role: discovery, mapping, detail retrieval, system resolution, STIG listing, and knowledge-base lifecycle. No tool feels redundant or missing from a count perspective.
The surface covers the primary workflow: find technique or actor, get mapped controls/findings, then fetch DISA check/fix text, plus STIG discovery and KB install/check. Some reverse-lookup or bulk-finding operations are absent, such as control-to-technique lookup or all findings for a STIG, but agents can work around these via existing mapping and detail tools.