Which computer are you securing?
The matching DISA STIG — the release this project validated — is loaded with its filed plain-English explanations. Servers, Linux and databases stay on the command line.
Loading the catalogue…
Local vs hosted. This page is static: it lists STIGs and explanations
this repository already ships. It cannot reach
dl.dod.cyber.mil
from a browser. The official zip is downloaded later, on your machine, by
the scanner (or by python3 -m stigprep fetch), and is checked
against the pinned SHA-256 when one is recorded and always against the
validated rule count. If that host is blocked, use
public.cyber.mil/stigs/downloads.
Every rule, in plain English
| Rule | Severity | What it asks of you | Kind |
|---|
Download the local scanner
The zip is a configured copy of this project. Double-click it on the computer you picked. Approval and scanning happen there, not here.
Delete the previous unzipped scanner folder first, then unpack this zip
into a new folder. Windows →
STIG Checker.bat.
Mac → right-click STIG Checker.command → Open.
If Python is missing, the program offers a private copy from python.org.
Read every command, type your name, then scan. A PDF lands in the files folder.