Skip to content

Content Library

Security content for validation, hardening, and developer libraries across platforms and compliance standards.

151 items
Showing 151 of 151 items

AWS CIS

Validate IconValidate
active
CIS

AWS CIS Foundations security validation

InSpec
v1.0.0
Amazon Web Services

AWS Foundations CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Amazon Web Services

AWS Foundations CIS - Terraform

Harden IconHarden
active
CIS

Terraform
Amazon Web Services

AWS MSQL 2014 STIG

Validate IconValidate
active
STIG

AWS RDS Microsoft SQL 2014 Server STIG Instance

InSpec
v1.0.0
Amazon Web Services

AWS RDS Best Practices Benchmark

Validate IconValidate
active
Vendor

Validates AWS RDS configuration against vendor best practices

InSpec
v1.0.0
Amazon Web Services

AWS RDS CIS

Validate IconValidate
active
CIS

AWS RDS Infrastructure CIS security validation

InSpec
v1.0.0
Amazon Web Services

AWS RDS MySQL 5.7 CIS

Validate IconValidate
active
CIS

AWS RDS MySQL Enterprise Edition 5.7 CIS security validation

InSpec
v1.0.0
MySQL 5.7

AWS RDS Oracle Database 12c STIG

Validate IconValidate
active
STIG

AWS RDS Oracle Database 12c STIG

InSpec
v1.0.0
Oracle Database 12

AWS RDS PostgreSQL 10+ STIG

Validate IconValidate
active
STIG

AWS RDS PostgreSQL 10+ STIG

InSpec
v1.0.0
PostgreSQL 10

AWS RDS PostgreSQL 9.x STIG

Validate IconValidate
active
STIG

AWS RDS Crunchy Data PostgreSQL 9.x STIG

InSpec
v1.0.0
PostgreSQL 9

AWS S3

Validate IconValidate
active
Vendor

Validates AWS S3 buckets against security best practices

InSpec
v1.0.0
Amazon Web Services

AWS S3 Best Practices Benchmark

Validate IconValidate
active
Vendor

Validates AWS S3 bucket security according to best practices including encryption, access policies, and logging.

InSpec
vn/a
Amazon Web Services

AWS S3 Best Practices Benchmark

Validate IconValidate
active
Vendor

Validates AWS S3 bucket configuration against vendor best practices

InSpec
v1.0.0
Amazon Web Services

AWS S3 Security

Validate IconValidate
active
CIS

Validates AWS S3 bucket security configuration and access controls

InSpec
v1.0.0
Amazon Web Services

Amazon Linux 2 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Amazon Linux 2

Amazon Linux 2023 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Amazon Linux 2023

Apache HTTP Server 2.4 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Apache HTTP Server

Apache HTTP Server 2.4 STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Apache HTTP Server

Apache HTTP Server SRG-Ready

Validate IconValidate
draft
STIG-Ready

Validates Apache HTTP Server configurations against DoD SRG requirements for baseline security controls.

InSpec
v1.0.0
Apache HTTP Server

Apache Server 2.2 STIG

Validate IconValidate
active
STIG

Apache Server 2.2 STIG

InSpec
v1.0.0
Apache HTTP Server

Apache Server 2.4x STIG

Validate IconValidate
active
STIG

Apache Server 2.4x STIG

InSpec
v1.0.0
Apache HTTP Server

Apache Site 2.2 STIG

Validate IconValidate
active
STIG

Apache Site 2.2 STIG

InSpec
v1.0.0
Apache HTTP Server

Apache Site 2.4x STIG

Validate IconValidate
active
STIG

Apache Site 2.4x STIG

InSpec
v1.0.0
Apache HTTP Server

Apache Tomcat 9 STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Apache Tomcat

Apache Tomcat 9.x STIG

Validate IconValidate
active
STIG

Apache Tomcat 9.x STIG

InSpec
v1.0.0
Apache Tomcat

Apache Tomcat CIS - Chef

Harden IconHarden
active
CIS

Chef
Apache Tomcat

Apache Tomcat CIS - MITRE Ansible

Harden IconHarden
active
CIS

Ansible
Apache Tomcat

Apache Web Server Hardening

Harden IconHarden
draft

Ansible playbook for hardening Apache web server configurations according to security best practices.

Ansible
v1.0.0
Apache HTTP Server

Azure CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Microsoft Azure

Azure Security Benchmark

Validate IconValidate
active

Validates Microsoft Azure resources against security best practices

InSpec
v3.0.1
Microsoft Azure

Benchmark Generator

Harden IconHarden
active

Generates structured output from XCCDF benchmark files for various automation tool formats. Used by the Ansible Lockdown project to produce remediation roles from benchmark source data.

Cisco IOS L2 Switch STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Cisco IOS L2 Switch

Cisco IOS Router STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Cisco IOS Router

Debian 11 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Debian 11

Debian 12 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Debian 12

Docker CE CIS

Validate IconValidate
active
CIS

Validates Docker Community Edition installations against CIS Docker Benchmark security requirements

InSpec
v1.1.0
Docker

Docker CE CIS - Chef

Harden IconHarden
active
CIS

Chef
Docker

Docker CE CIS - MITRE Ansible

Harden IconHarden
active
CIS

Ansible
Docker

Docker CIS Hardening

Harden IconHarden
active

Ansible playbook for hardening Docker CE configurations according to CIS Docker Benchmark.

Ansible
v1.0.0
Docker

Docker CIS Hardening Chef

Harden IconHarden
active

Chef cookbook for hardening Docker CE configurations according to CIS Docker Benchmark.

Chef
v1.0.0
Docker

Elasticsearch Hardening - Chef

Harden IconHarden
active
STIG-Ready

Chef
Elasticsearch

GCP CIS Benchmark

Validate IconValidate
active

Validates Google Cloud Platform resources against CIS benchmarks for security and compliance

InSpec
v1.2.0
Google Cloud Platform

GCP PCI-DSS 3.2.1

Validate IconValidate
active
PCI-DSS

Validates GCP infrastructure against PCI-DSS 3.2.1 compliance requirements for payment card data security.

InSpec
v3.2.1
Google Cloud Platform

GKE CIS Benchmark

Validate IconValidate
active

Google Kubernetes Engine CIS Benchmark

InSpec
v1.1.0

GitHub Security

Validate IconValidate
draft

Validates GitHub organization and repository security controls

InSpec
v1.0.0

IIS 8.5 Server STIG

Validate IconValidate
active
STIG

Microsoft IIS 8.5 Server STIG

InSpec
v1.0.0
Microsoft IIS

IIS 8.5 Server STIG - Chef

Harden IconHarden
active
STIG

Chef
Microsoft IIS

IIS 8.5 Site STIG

Validate IconValidate
active
STIG

Microsoft IIS 8.5 Site STIG

InSpec
v1.0.0
Microsoft IIS

IIS 8.5 Site STIG - Chef

Harden IconHarden
active
STIG

Chef
Microsoft IIS

InSpec Runner

Harden IconHarden
active

Containerized InSpec runner for executing compliance profiles in Docker environments. Simplifies running scans without local InSpec installation.

InSpecJS

Validate IconValidate
active

A TypeScript library for parsing and evaluating InSpec results in HDF (Heimdall Data Format). Powers the data layer of Heimdall and other SAF tools.

@mitre/inspecjs

JRE 7 STIG

Validate IconValidate
active
STIG

Oracle Java Runtime Environment 7 Unix STIG

InSpec
v1.0.0

JRE 8 STIG

Validate IconValidate
active
STIG

Oracle Java Runtime Environment 8 Unix STIG

InSpec
v1.0.0

K3s Cluster STIG

Validate IconValidate
active
STIG

K3s Cluster STIG

InSpec
v1.0.0

K3s Node STIG

Validate IconValidate
active
STIG

K3s Node STIG

InSpec
v1.0.0

Kubernetes 1.6.1 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Kubernetes

Kubernetes CIS

Validate IconValidate
beta
CIS

Validates Kubernetes clusters against CIS Kubernetes Benchmark to ensure secure configuration

InSpec
v1.1.0
Kubernetes

Kubernetes CIS Hardening

Harden IconHarden
draft

Terraform configuration for deploying a hardened Kubernetes cluster according to CIS Kubernetes Benchmark.

Terraform
v1.0.0
Kubernetes

Kubernetes Cluster STIG

Validate IconValidate
active
STIG

Kubernetes Cluster STIG

InSpec
v1.0.0
Kubernetes

Kubernetes Node STIG

Validate IconValidate
active
STIG

Kubernetes Node STIG

InSpec
v1.0.0
Kubernetes

Kubernetes STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Kubernetes

MSQL 2014 Database STIG

Validate IconValidate
active
STIG

Microsoft SQL Server 2014 Database STIG

InSpec
v1.0.0

MSQL 2014 Instance STIG

Validate IconValidate
active
STIG

Microsoft SQL Server 2014 Database STIG

InSpec
v1.0.0

MongoDB Enterprise Advanced STIG - Chef

Harden IconHarden
active
STIG

Chef
MongoDB

MongoDB STIG

Validate IconValidate
active
STIG

MongoDB STIG

InSpec
v1.0.0
MongoDB

NGINX Hardening - Chef

Harden IconHarden
draft
STIG-Ready

Work-in-progress NGINX hardening cookbook

Chef
NGINX

NGINX SRG-Ready

Validate IconValidate
active
STIG-Ready

Validates NGINX web server configurations against DoD SRG requirements for enhanced security posture.

InSpec
v1.0.0
NGINX

NGINX STIG Ready Baseline

Validate IconValidate
active
STIG

NGINX STIG Ready Baseline

InSpec
v1.0.0
NGINX

NGINX STIG-Ready - MITRE Ansible

Harden IconHarden
active
STIG-Ready

Ansible
NGINX

OHDF Converters

Normalize IconNormalize
active

Convert security tool output from various formats (Burp Suite, Fortify, Nessus, OWASP ZAP, Prisma, Sonarqube, and more) into OHDF (Open Heimdall Data Format) for unified visualization.

@mitre/hdf-converters

Oracle Database 12c STIG

Validate IconValidate
active
STIG

Oracle Database 12c STIG

InSpec
v1.0.0
Oracle Database 12

Oracle Database 19c CIS

Validate IconValidate
active

Oracle Database 19c CIS Benchmark validation

InSpec
v1.0.0
Oracle Database 19

Oracle Java RE 8 STIG - Chef

Harden IconHarden
active
STIG

Chef
Oracle Java RE 8

Oracle MySQL 5.7 CIS

Validate IconValidate
active

Oracle MySQL Enterprise Edition 5.7 CIS security validation

InSpec
v1.0.0
MySQL 5.7

Oracle MySQL 8.0 STIG

Validate IconValidate
active
STIG

Oracle MySQL 8.0 STIG Baseline

InSpec
v1.0.0
MySQL 8.0

PostgreSQL 10+ STIG

Validate IconValidate
active
STIG

PostgreSQL 10+ STIG

InSpec
v1.0.0
PostgreSQL 10

PostgreSQL 12 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
PostgreSQL 12

PostgreSQL 9 STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
PostgreSQL 9

PostgreSQL 9.x STIG

Validate IconValidate
active
STIG

Crunchy Data PostgreSQL 9.x STIG

InSpec
v1.0.0
PostgreSQL 9

Red Hat 6 STIG

Validate IconValidate
active
STIG

Red Hat 6 STIG

InSpec
v1.0.0
Red Hat Enterprise Linux 6

Red Hat 7 STIG

Validate IconValidate
active
STIG

Red Hat 7 STIG

InSpec
v1.0.0
Red Hat Enterprise Linux 7

Red Hat 8 STIG

Validate IconValidate
active
STIG

Red Hat 8 STIG

InSpec
v1.0.0
Red Hat Enterprise Linux 8

Red Hat CVE Scan

Validate IconValidate
active

Scans Red Hat Enterprise Linux systems for known CVE vulnerabilities

InSpec
v1.0.0
Red Hat Enterprise Linux

Red Hat Enterprise Linux 10 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Red Hat Enterprise Linux 10

Red Hat Enterprise Linux 6 STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Red Hat Enterprise Linux 6

Red Hat Enterprise Linux 7 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Red Hat Enterprise Linux 7

Red Hat Enterprise Linux 7 STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Red Hat Enterprise Linux 7

Red Hat Enterprise Linux 7 STIG - MITRE Ansible

Harden IconHarden
active
STIG

Ansible
Red Hat Enterprise Linux 7

Red Hat Enterprise Linux 8 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Red Hat Enterprise Linux 8

Red Hat Enterprise Linux 8 STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Red Hat Enterprise Linux 8

Red Hat Enterprise Linux 9 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Red Hat Enterprise Linux 9

Red Hat Enterprise Linux 9 STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Red Hat Enterprise Linux 9

Red Hat Jboss EAP 6.3 STIG

Validate IconValidate
active
STIG

Red Hat Jboss Enterprise Application Server 6.3 STIG

InSpec
v1.0.0
Red Hat Enterprise Linux 6

RedHat Enterprise Linux 9

Validate IconValidate
active
STIG

InSpec Profile for RHEL9

InSpec
v2.4.0
Red Hat Enterprise Linux 9

STIG XCCDF XML Library

Harden IconHarden
active

A TypeScript library for parsing and manipulating DISA STIG XCCDF XML files. Used to extract control metadata from STIGs for profile generation.

@mitre/stig-xccdf-xml-library

SUSE Linux Enterprise 15 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
SUSE Linux Enterprise 15

TS InSpec Objects

Validate IconValidate
active

TypeScript type definitions and utilities for working with InSpec profile and result objects. Provides strongly-typed interfaces for the InSpec data model.

@mitre/ts-inspec-objects

Tomcat 7 CIS

Validate IconValidate
beta
CIS

Apache Tomcat 7 CIS security validation (Beta)

InSpec
v1.0.0
Apache Tomcat

Tomcat 8 CIS

Validate IconValidate
beta
CIS

Apache Tomcat 8 CIS security validation (Beta)

InSpec
v1.0.0
Apache Tomcat

Ubuntu 16.04 STIG

Validate IconValidate
active
STIG

Canonical Ubuntu 16.04 STIG

InSpec
v1.0.0
Ubuntu 16.04

Ubuntu 16.04 STIG - Chef

Harden IconHarden
active
STIG

Chef
Ubuntu 16.04

Ubuntu 18.04 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Ubuntu 18.04

Ubuntu 18.04 STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Ubuntu 18.04

Ubuntu 20.04 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Ubuntu 20.04

Ubuntu 20.04 STIG

Validate IconValidate
active
STIG

Canonical Ubuntu 20.04 STIG

InSpec
v1.0.0
Ubuntu 20.04

Ubuntu 20.04 STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Ubuntu 20.04

Ubuntu 22.04 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Ubuntu 22.04

Ubuntu 22.04 STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Ubuntu 22.04

Ubuntu 24.04 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Ubuntu 24.04

Ubuntu 24.04 STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Ubuntu 24.04

VMware Aria Automation 8.x STIG

Validate IconValidate
active
STIG

VMware Aria Automation 8.x STIG Readiness Guide Chef InSpec Profile

InSpec
v1.0.0

VMware Aria Operations 8.x STIG

Validate IconValidate
active
STIG

VMware Aria Operations 8.x STIG Readiness Guide Chef InSpec Profile

InSpec
v1.0.0

VMware Cloud Director 10.4 STIG

Validate IconValidate
active
STIG

VMware Cloud Director 10.4 STIG Readiness Guide Chef InSpec Profile

InSpec
v1.0.0

VMware Cloud Foundation 4.5 STIG

Validate IconValidate
active
STIG

VMware Cloud Foundation 4.5 STIG Readiness Guide Chef InSpec Profile

InSpec
v1.0.0

VMware Cloud Foundation 5.0 STIG

Validate IconValidate
active
STIG

VMware Cloud Foundation 5.0 STIG Readiness Guide Chef InSpec Profile

InSpec
v1.0.0

VMware ESXI 6.5 STIG

Validate IconValidate
active
STIG

VMware ESXI 6.5 STIG

InSpec
v1.0.0

VMware ESXI 6.7 STIG

Validate IconValidate
active
STIG

VMware ESXI 6.7 STIG

InSpec
v1.0.0

VMware Horizon 8.0 STIG

Validate IconValidate
active
STIG

VMware Horizon 8.0 STIG Readiness Guide Chef InSpec Profile

InSpec
v1.0.0

VMware Identity Manager 3.3.x STIG

Validate IconValidate
active
STIG

VMware Identity Manager 3.3.x STIG Readiness Guide Chef InSpec Profile

InSpec
v1.0.0

VMware NSX 4.x STIG

Validate IconValidate
active
STIG

VMware NSX 4.x STIG Readiness Guide Chef InSpec Profile

InSpec
v1.0.0

VMware NSX-T 3.x STIG

Validate IconValidate
active
STIG

VMware NSX-T 3.x STIG Chef InSpec Profile

InSpec
v1.0.0

VMware Photon OS 3.0 STIG

Validate IconValidate
active
STIG

VMware Photon OS 3.0 STIG Readiness Guide Chef InSpec Profile

InSpec
v1.0.0

VMware Photon OS 4.0 STIG

Validate IconValidate
active
STIG

VMware Photon OS 4.0 STIG Readiness Guide Chef InSpec Profile

InSpec
v1.0.0

VMware Photon OS 5.0 STIG

Validate IconValidate
active
STIG

VMware Photon OS 5.0 STIG Readiness Guide Chef InSpec Profile

InSpec
v1.0.0

VMware VCSA 6.7 STIG

Validate IconValidate
active
STIG

VMware vCenter Server Appliance 6.7 STIG

InSpec
v1.0.0

VMware VCSA 7.0 STIG Readiness Guide

Validate IconValidate
active
STIG

VMware vCenter Service Appliance version 7.0 STIG Readiness Guide

InSpec
v1.0.0

VMware vSphere 7.0 STIG

Validate IconValidate
active
STIG

VMware vSphere 7.0 STIG Chef InSpec Profile

InSpec
v1.0.0

VMware vSphere 7.0 STIG Readiness Guide

Validate IconValidate
active
STIG

VMware vSphere(ESXi,vCenter,VMs) 7.0 STIG Readiness Guide

InSpec
v1.0.0

VMware vSphere VM 6.7 STIG

Validate IconValidate
active
STIG

VMware vSphere Virtual Machines version 6.7 STIG

InSpec
v1.0.0

VMware vSphere vCenter 7.0 STIG

Validate IconValidate
active
STIG

VMware vSphere vCenter Appliance 7.0 STIG Chef InSpec Profile

InSpec
v1.0.0

VMware vSphere vCenter 8.0 STIG

Validate IconValidate
active
STIG

VMware vSphere vCenter Appliance 8.0 STIG Readiness Guide Chef InSpec Profile

InSpec
v1.0.0

Windows 10 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Windows 10

Windows 10 STIG

Validate IconValidate
active
STIG

Microsoft Windows 10 STIG v1r19

InSpec
v1.0.0
Windows 10

Windows 10 STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Windows 10

Windows 11 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Windows 11

Windows 11 STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Windows 11

Windows 2012 STIG

Validate IconValidate
active
STIG

Microsoft Windows 2012r2 Member Server STIG

InSpec
v1.0.0
Windows 2012

Windows 2016 STIG

Validate IconValidate
active
STIG

Microsoft Windows Server 2016 STIG

InSpec
v1.0.0
Windows 2016

Windows 2019 STIG

Validate IconValidate
active
STIG

Microsoft Windows Server 2019 STIG

InSpec
v1.0.0
Windows 2019

Windows Firewall Advanced Security STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Windows Firewall Advanced Security

Windows Server 2012 R2 STIG - Chef

Harden IconHarden
active
STIG

Chef
Windows 2012

Windows Server 2016 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Windows 2016

Windows Server 2016 STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Windows 2016

Windows Server 2016 STIG - Chef

Harden IconHarden
active
STIG

Chef
Windows 2016

Windows Server 2019 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Windows 2019

Windows Server 2019 STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Windows 2019

Windows Server 2022 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Windows Server 2022

Windows Server 2022 STIG - Ansible Lockdown

Harden IconHarden
active
STIG

Ansible
Windows Server 2022

Windows Server 2025 CIS - Ansible Lockdown

Harden IconHarden
active
CIS

Ansible
Windows Server 2025

eMASS Checklist Updater

Harden IconHarden
active

Translates findings between eMASS Checklist (CKL) versions. Useful when migrating between STIG versions while preserving existing findings.

eMASS Client

Visualize IconVisualize
active

Client libraries for the eMASS (Enterprise Mission Assurance Support Service) REST API. Enables programmatic access to eMASS for security authorization workflows.

emass_client