Practitioner-built references for offense, defense, cloud, identity, GRC, and specialized security — anchored to MITRE ATT&CK and mapped to real controls, detections, and tooling.
🌐 Live Site · Reference Index · Discipline Paths · Threat-Informed Defense · ATTACK-Navi
This README is the GitHub view — the live site opens on a faster navigation homepage (HOME.md).
TeamStarWolf is a free, vendor-neutral knowledge base for working security practitioners. It is not a blog or a link dump — it is a structured library of 140 in-depth reference documents, 16 step-by-step how-to guides, and 47 discipline learning paths that cover the cybersecurity field end to end: how attacks work, how to detect and respond to them, how to harden systems and clouds, how to govern risk, and how to build a career doing it.
- ATT&CK at the center — techniques mapped to the controls that mitigate them (CTID), the detections that catch them, and the tests that validate them.
- Operational, not theoretical — real commands, queries, tooling, and detection logic, written to be used on an engagement or in a SOC.
- Open and practitioner-built — free, MIT-licensed, and cross-referenced so you can move from a concept to a command to a control in a couple of clicks.
TeamStarWolf covers the cybersecurity field end to end — offense, defense, cloud, identity, GRC, AI, and specialized domains — as in-depth references, step-by-step how-to guides, and discipline learning paths.
Everything is built on MITRE ATT&CK and cross-referenced the way you actually work: each adversary technique is linked to the controls that mitigate it (NIST 800-53), the detections that catch it, the weaknesses and attack patterns behind it (CWE and CAPEC), and the countermeasures that stop it (D3FEND). That model extends across the full MITRE stack — ATLAS for AI threats, Engage for deception, F3 for fraud, EMB3D for embedded devices, FiGHT for 5G — and ships as machine-readable coverage data and ATT&CK Navigator layers you can query, not just read.
Free, open, and MIT-licensed. No signup, no tracking.
Pick your goal — each path drops you into the right part of the library.
The flagship of the library: MITRE ATT&CK at the center, enriched with the vulnerability, weakness, detection, and control knowledge that turns a coverage map into decisions. It shares its data model with the ATTACK-Navi workbench, and the mappings below are machine-readable so you can query them, not just read them.
| Resource | What you get |
|---|---|
| Threat-Informed Defense Reference | The ATT&CK-centric knowledge graph (CVE → CWE → CAPEC → ATT&CK → D3FEND), the open-source data-source stack, and the per-technique coverage-stack model |
| ATT&CK Matrix Analysis Reference | 24 analytic lenses for reading an ATT&CK matrix — mitigation, threat activity, exposure, detection, and composite risk |
| Technique Detection Library | Multi-platform detection queries (Splunk · Elastic · Microsoft · Chronicle · CrowdStrike) keyed to ATT&CK techniques and the NIST controls that mitigate them |
| ATT&CK Navigator Coverage Layers | Live heatmaps of NIST 800-53 R5 control depth and vendor/domain coverage — load the master layer ↗ |
ATT&CK knowledge base & the rest of the MITRE stack — parsed, cross-referenced, one row per node:
| Resource | What you get |
|---|---|
| ATT&CK Technique Atlas | All 691 Enterprise techniques scored by group usage, software, mitigations, NIST controls, and detection availability |
| Technique Detail Pages | A full consolidated write-up per technique |
| Threat Group Profiles | 168 adversary groups with aliases, attributed techniques, and tooling |
| ATT&CK Software Reference | 784 malware families & tools and the techniques they implement |
| ATT&CK Campaigns Reference | 52 intrusion campaigns with active windows, techniques, and attribution |
| ATT&CK Mitigations Reference | All 44 mitigations (M-codes) and the techniques each one addresses |
| ATT&CK Priority Gap Analysis | The most-used, least-covered techniques |
| ICS & Mobile Atlases | The 83-technique ICS and 124-technique Mobile matrices, same treatment |
| ATT&CK Detection Strategies | 691 strategies and 1,739 analytics with log sources and tunable logic |
| Data Components & Log Sources | 106 telemetry categories mapped to the techniques they detect |
| CWE Weakness Reference | 969 weakness types with consequences and mitigations |
| CAPEC Attack Pattern Reference | 615 attack patterns, 177 bridging directly to ATT&CK |
| D3FEND Countermeasure Reference | 156 countermeasures mapped to the 426 techniques they counter |
| MITRE ATLAS Reference | 170 AI-attack techniques across 16 tactics, plus 35 mitigations |
| MITRE Engage Reference | 31 deception activities with 793 mappings to ATT&CK techniques |
| CTEM Reference | Gartner's 5-stage exposure loop, the tool landscape, and a 90-day plan |
| MITRE F3 Fraud Framework | 123 fraud-actor techniques across 8 tactics, through to Monetization |
Machine-readable datasets · Technique profiles · Group → Technique · Software → Technique · Mitigation → Technique · Groups · Software · Mitigations · Campaigns · Detection strategies · Analytics · Data components · Technique → D3FEND · CWE · CAPEC
Coverage edges & layers — the vendor → control → technique bridge, sourced from the authoritative CTID Mappings Explorer (NIST 800-53 R5 → ATT&CK v16.1). See CONTROLS_MAPPING.md and COVERAGE_SCHEMA.md for the model and scores/coverage_gaps.md for gap analysis.
| Resource | Description |
|---|---|
| Control → Technique · Vendor → Control · Vendor → Technique | NIST 800-53 R5 → ATT&CK edges (5,314, CTID) · 60+ vendors → controls (237 edges) · derived vendor coverage (17K+ edges) |
| Framework Blind Spots layer | The 223 techniques with no NIST 800-53 control mapping — coverage blind spots |
| Enterprise Security Pipeline | End-to-end security lifecycle with vendor mapping across all 6 stages |
| Path | Contents |
|---|---|
data/ |
JSONL datasets — every mapping in the library, machine-readable |
navigator/ |
ATT&CK Navigator layers (28) |
detections/ |
Detection strategies + the multi-platform query library |
techniques/ |
Per-technique detail pages |
disciplines/ |
47 learning paths + the paths hub |
scores/ |
Gap analyses |
Flagships by domain — the Reference Index lists all 140 documents, and the live site browses every domain in two clicks.
| Domain | Flagship references | |
|---|---|---|
| 🗡️ Offensive | Pentest Methodology · Red Team · AD Attacks · Web App Pentesting | full index → |
| 🛡️ Defensive | Incident Response · Threat Hunting · SIEM · Detection Rules | full index → |
| ☁️ Cloud & Infrastructure | Cloud Security · Container Security · DevSecOps · Supply Chain | full index → |
| 🔑 Identity, Access & Crypto | IAM · Zero Trust · AD Security · Cryptography | full index → |
| 📋 GRC | GRC Compliance · Vulnerability Management · Security Metrics · Threat Modeling | full index → |
| 🔬 Specialized Domains | ICS/OT · Hardware · AI Security · Telecom & 5G | full index → |
| 🔎 Research & Analysis | OSINT · Reverse Engineering · Threat Intelligence · Packet Analysis | full index → |
| Reference | Coverage |
|---|---|
| Career Paths | 15+ security roles with skill maps, salary ranges, and cert roadmaps |
| Certifications Reference | 40+ certifications with cost, difficulty, and domain coverage |
| Interview Prep | Questions by role: SOC analyst, pentester, DFIR, cloud security |
| Home Lab Setup | Hardware, hypervisors, network design, detection stacks |
| Hands-On Labs | Free lab environments and CTF platforms mapped to each security domain |
| Cybersecurity Book List | Curated reading organized by discipline and level |
| Starred Repositories | Curated GitHub repos structured around the security technology landscape |
Free training platforms — Antisyphon, Black Hills, PortSwigger, HTB Academy, TryHackMe, LetsDefend, and more — live in Hands-On Labs and Resources.
The interactive companion to this library — a MITRE ATT&CK workbench for coverage review, detection engineering, exposure mapping, and threat-intelligence correlation across the Enterprise, ICS, and Mobile domains, consuming the same coverage data published here.
| Capability | Details |
|---|---|
| Heatmap modes | Coverage, detection, exposure, compliance, and risk — 24 analytic lenses |
| Live integrations | MISP, OpenCTI, EPSS, CISA KEV, NVD, Elastic, Splunk, Sigma, Atomic Red Team, ExploitDB, Nuclei |
| Data | STIX 2.1 import/export, custom technique editing, collection sharing |
| Deployment | Docker or GitHub Pages |
Repository · Live Site · Docs
Other projects: LimeWire — Python desktop audio studio · PokeNav — offline-first Pokémon encyclopedia.
Contributions, corrections, and new references are welcome — see CONTRIBUTING and open an issue to suggest a tool, fix content, or propose a new discipline. Released under the MIT License.
Disclaimer. All offensive material is provided for authorized security testing, education, and defensive research only.
🌐 Live Site · 📖 Reference Index · 🧭 Discipline Paths
🐺 TeamStarWolf — built for the cybersecurity community.



