VulcanSTIG-Ready Security Guidance
Streamline the creation of STIG documentation and InSpec validation profiles
Streamline the creation of STIG documentation and InSpec validation profiles
Manage the complete workflow between vendors and sponsors for STIG creation
Write and test validation code locally or across SSH, AWS, and Docker targets
Track control status, revision history, and relationships between requirements
Multiple authors can work on control sets with built-in review workflows
Look up related controls across all published STIGs for consistency
Database encryption, flexible authentication with OIDC, LDAP, and GitHub
# Clone the repository
git clone https://github.com/mitre/vulcan.git
cd vulcan
# Generate secure configuration
./setup-docker-secrets.sh
# Start the application stack (Vulcan + PostgreSQL)
docker compose upSee the Quick Start guide for the compose-file-only setup and first steps.
Current Version
v2.4.2 - Released August 2026
Full SRG-component export and spreadsheet re-import parity with STIG components, a project-page component lock indicator, and session-timeout fixes (restored the 1-hour default; corrected VULCAN_SESSION_TIMEOUT suffix parsing). View Release Notes →
Vulcan bridges the gap between security requirements and practical implementation, enabling organizations to:
Vulcan is a core component of the MITRE Security Automation Framework (SAF), a comprehensive suite of tools designed to automate security validation and compliance checking.
Compliance automation framework
Security results visualization
Command-line security tools