VulcanSTIG-Ready Security Guidance
Streamline the creation of STIG documentation and InSpec validation profiles
Streamline the creation of STIG documentation and InSpec validation profiles
Manage the complete workflow between vendors and sponsors for STIG creation
Write and test validation code locally or across SSH, AWS, and Docker targets
Track control status, revision history, and relationships between requirements
Multiple authors can work on control sets with built-in review workflows
Look up related controls across all published STIGs for consistency
Database encryption, flexible authentication with OIDC, LDAP, and GitHub
docker pull mitre/vulcan:latest
docker run -p 3000:3000 mitre/vulcan:latest# Clone the repository
git clone https://github.com/mitre/vulcan.git
cd vulcan
# Generate secure configuration
./setup-docker-secrets.sh
# Start the application stack
docker compose upCurrent Version
v2.3.7 - Released May 2026
Component-level comments via polymorphic reviews, project-aggregate disposition matrix CSV export, "Comment" toolbar button rename, replies allowed on active threads after a comment period closes. View Release Notes →
Vulcan bridges the gap between security requirements and practical implementation, enabling organizations to:
Vulcan is a core component of the MITRE Security Automation Framework (SAF), a comprehensive suite of tools designed to automate security validation and compliance checking.
Compliance automation framework
Security results visualization
Command-line security tools