STIG Checker

Read a Department of Defense checklist in plain English, pick the rules to scan, then download a program that runs on your own computer.

Hosted on GitHub Pages · MIT licence

Which computer are you securing?

The matching DISA STIG — the release this project validated — is loaded with its filed plain-English explanations. Servers, Linux and databases stay on the command line.

Loading the catalogue…

Local vs hosted. This page is static: it lists STIGs and explanations this repository already ships. It cannot reach dl.dod.cyber.mil from a browser. The official zip is downloaded later, on your machine, by the scanner (or by python3 -m stigprep fetch), and is checked against the pinned SHA-256 when one is recorded and always against the validated rule count. If that host is blocked, use public.cyber.mil/stigs/downloads.