Review STIGs
without the grind.

A cross-platform desktop editor for DoD STIG checklists, built with Go + Wails. It imports Cyber Exchange ZIP/XML packages, tracks review states and evidence, matches your host against the official STIG catalog, and exports CKL and STIG Viewer 3 CKLB files.

Go + WailsWindows · macOS · LinuxCKL + CKLB exportReact/TypeScript UI
01 / WHY IT EXISTS

STIG review is
bookkeeping-heavy.

Reviewing STIGs normally means STIG Viewer plus manual bookkeeping: fragile unsaved work, format churn between JSON, CKL, and CKLB, and matching hosts to the right STIGs by hand. This editor makes the whole loop one keyboard-driven tool.

CYBER EXCHANGE IMPORT

Real packages, direct

Imports STIG XCCDF XML straight from Cyber Exchange ZIP packages — profile selection, resolved values, and readable rendering of rich check and fix content, as a cancellable background job.

REVIEW STATES

Four-state workflow

Open, Closed, Not Applicable, and Not Reviewed — with Findings, Comments, reviewer fields, and backend-authored guidance when evidence is missing or inconsistent.

CKL + CKLB EXPORT

Formats assessors accept

Saves editable checklist JSON and exports classic CKL plus STIG Viewer 3 CKLB 1.0 — with real target-asset metadata carried into every format.

HOST DISCOVERY

Match the right STIGs

Reads local OS and installed-software inventory, matches it against the public DoD Cyber Exchange catalog, and downloads official packages only from dl.dod.cyber.mil.

BATCH EDITING

Keyboard-first review

Multi-rule selection, batch status changes, batch Findings and Comments with explicit Keep, Append, or Replace modes, column sorting, and desktop keyboard shortcuts.

NEVER LOSE A REVIEW

Unsaved-work guards

Dirty-state tracking guards Import, Open, Create, and native window close; atomic private autosaves offer recovery on next launch instead of silently losing an afternoon of review.

02 / WORKFLOW

Discover, import,
review, export.

The editor walks the full checklist lifecycle without leaving the app.

  1. STEP 01

    Discover STIGs for the host

    Read the local OS and installed software, then match against the current public Cyber Exchange catalog.

  2. STEP 02

    Import the package

    Preview XCCDF profiles with their rule counts, then run validation and queue construction with live progress.

  3. STEP 03

    Review with states and evidence

    Work the queue with four review states, findings, comments, and batch actions — sorted and filtered your way.

  4. STEP 04

    Save and export

    Save the editable JSON working copy, then export CKL or CKLB for the ATO package.

STATUSIn active developmentGo + Wails v2Windows · macOS · LinuxReact/TypeScript UIGo tests + race detectorRedistributable synthetic fixtures
03 / GET IN TOUCH

Want a demo?

The repository is private while the editor matures. If you review STIGs for a living and want a walkthrough, email me.

Email me about the editor