Skip to content
View TeamStarWolf's full-sized avatar
👾
Vibing…
👾
Vibing…

Block or report TeamStarWolf

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
TeamStarWolf/README.md
STARWOLF64

🐺 TeamStarWolf

An open, threat-informed cybersecurity reference library

Practitioner-built references for offense, defense, cloud, identity, GRC, and specialized security — anchored to MITRE ATT&CK and mapped to real controls, detections, and tooling.

Reference docs How-to guides Discipline paths ATT&CK Live docs License: MIT

🌐 Live Site  ·  Reference Index  ·  Discipline Paths  ·  Threat-Informed Defense  ·  ATTACK-Navi

This README is the GitHub view — the live site opens on a faster navigation homepage (HOME.md).


About

TeamStarWolf is a free, vendor-neutral knowledge base for working security practitioners. It is not a blog or a link dump — it is a structured library of 140 in-depth reference documents, 16 step-by-step how-to guides, and 47 discipline learning paths that cover the cybersecurity field end to end: how attacks work, how to detect and respond to them, how to harden systems and clouds, how to govern risk, and how to build a career doing it.

  • ATT&CK at the center — techniques mapped to the controls that mitigate them (CTID), the detections that catch them, and the tests that validate them.
  • Operational, not theoretical — real commands, queries, tooling, and detection logic, written to be used on an engagement or in a SOC.
  • Open and practitioner-built — free, MIT-licensed, and cross-referenced so you can move from a concept to a command to a control in a couple of clicks.

What's inside

TeamStarWolf covers the cybersecurity field end to end — offense, defense, cloud, identity, GRC, AI, and specialized domains — as in-depth references, step-by-step how-to guides, and discipline learning paths.

Everything is built on MITRE ATT&CK and cross-referenced the way you actually work: each adversary technique is linked to the controls that mitigate it (NIST 800-53), the detections that catch it, the weaknesses and attack patterns behind it (CWE and CAPEC), and the countermeasures that stop it (D3FEND). That model extends across the full MITRE stack — ATLAS for AI threats, Engage for deception, F3 for fraud, EMB3D for embedded devices, FiGHT for 5G — and ships as machine-readable coverage data and ATT&CK Navigator layers you can query, not just read.

Free, open, and MIT-licensed. No signup, no tracking.


Start here

Pick your goal — each path drops you into the right part of the library.

I want to… Start with
Learn a discipline from zero Discipline learning paths → pick a track (e.g. Threat Intelligence, Detection Engineering, Red Teaming)
Run or prep for a pentest Penetration Testing Methodology · Pentest Checklists · Red Team Reference
Build detections & hunt Technique Detection Library · Detection Rules · Threat Hunting · SIEM Reference
Map coverage & find gaps Threat-Informed Defense · ATT&CK Matrix Analysis · Navigator layers
Respond to an incident Incident Response · IR Playbooks · Digital Forensics
Harden systems & cloud Windows / Linux hardening · Cloud Security · Zero Trust
Run an exposure management program CTEM Reference · Vulnerability Management · Priority Gap Analysis
Secure AI/ML systems MITRE ATLAS · AI Security · AI & MCP Security
Run deception / active defense MITRE Engage · Honeypot & Deception · Deception Technology
Defend against financial fraud MITRE F3 Fraud Framework · Social Engineering · Identity Security
Break into the field / level up Career Paths · Certifications · Home Lab Setup · Free Training

⭐ Threat-Informed Defense

The flagship of the library: MITRE ATT&CK at the center, enriched with the vulnerability, weakness, detection, and control knowledge that turns a coverage map into decisions. It shares its data model with the ATTACK-Navi workbench, and the mappings below are machine-readable so you can query them, not just read them.

Resource What you get
Threat-Informed Defense Reference The ATT&CK-centric knowledge graph (CVE → CWE → CAPEC → ATT&CK → D3FEND), the open-source data-source stack, and the per-technique coverage-stack model
ATT&CK Matrix Analysis Reference 24 analytic lenses for reading an ATT&CK matrix — mitigation, threat activity, exposure, detection, and composite risk
Technique Detection Library Multi-platform detection queries (Splunk · Elastic · Microsoft · Chronicle · CrowdStrike) keyed to ATT&CK techniques and the NIST controls that mitigate them
ATT&CK Navigator Coverage Layers Live heatmaps of NIST 800-53 R5 control depth and vendor/domain coverage — load the master layer ↗

ATT&CK knowledge base & the rest of the MITRE stack — parsed, cross-referenced, one row per node:

Resource What you get
ATT&CK Technique Atlas All 691 Enterprise techniques scored by group usage, software, mitigations, NIST controls, and detection availability
Technique Detail Pages A full consolidated write-up per technique
Threat Group Profiles 168 adversary groups with aliases, attributed techniques, and tooling
ATT&CK Software Reference 784 malware families & tools and the techniques they implement
ATT&CK Campaigns Reference 52 intrusion campaigns with active windows, techniques, and attribution
ATT&CK Mitigations Reference All 44 mitigations (M-codes) and the techniques each one addresses
ATT&CK Priority Gap Analysis The most-used, least-covered techniques
ICS & Mobile Atlases The 83-technique ICS and 124-technique Mobile matrices, same treatment
ATT&CK Detection Strategies 691 strategies and 1,739 analytics with log sources and tunable logic
Data Components & Log Sources 106 telemetry categories mapped to the techniques they detect
CWE Weakness Reference 969 weakness types with consequences and mitigations
CAPEC Attack Pattern Reference 615 attack patterns, 177 bridging directly to ATT&CK
D3FEND Countermeasure Reference 156 countermeasures mapped to the 426 techniques they counter
MITRE ATLAS Reference 170 AI-attack techniques across 16 tactics, plus 35 mitigations
MITRE Engage Reference 31 deception activities with 793 mappings to ATT&CK techniques
CTEM Reference Gartner's 5-stage exposure loop, the tool landscape, and a 90-day plan
MITRE F3 Fraud Framework 123 fraud-actor techniques across 8 tactics, through to Monetization

Machine-readable datasets  ·  Technique profiles  ·  Group → Technique  ·  Software → Technique  ·  Mitigation → Technique  ·  Groups  ·  Software  ·  Mitigations  ·  Campaigns  ·  Detection strategies  ·  Analytics  ·  Data components  ·  Technique → D3FEND  ·  CWE  ·  CAPEC

Coverage edges & layers — the vendor → control → technique bridge, sourced from the authoritative CTID Mappings Explorer (NIST 800-53 R5 → ATT&CK v16.1). See CONTROLS_MAPPING.md and COVERAGE_SCHEMA.md for the model and scores/coverage_gaps.md for gap analysis.

Resource Description
Control → Technique · Vendor → Control · Vendor → Technique NIST 800-53 R5 → ATT&CK edges (5,314, CTID) · 60+ vendors → controls (237 edges) · derived vendor coverage (17K+ edges)
Framework Blind Spots layer The 223 techniques with no NIST 800-53 control mapping — coverage blind spots
Enterprise Security Pipeline End-to-end security lifecycle with vendor mapping across all 6 stages

📁 Repo layout

Path Contents
data/ JSONL datasets — every mapping in the library, machine-readable
navigator/ ATT&CK Navigator layers (28)
detections/ Detection strategies + the multi-platform query library
techniques/ Per-technique detail pages
disciplines/ 47 learning paths + the paths hub
scores/ Gap analyses

📚 Library map

Flagships by domain — the Reference Index lists all 140 documents, and the live site browses every domain in two clicks.

Domain Flagship references
🗡️ Offensive Pentest Methodology · Red Team · AD Attacks · Web App Pentesting full index →
🛡️ Defensive Incident Response · Threat Hunting · SIEM · Detection Rules full index →
☁️ Cloud & Infrastructure Cloud Security · Container Security · DevSecOps · Supply Chain full index →
🔑 Identity, Access & Crypto IAM · Zero Trust · AD Security · Cryptography full index →
📋 GRC GRC Compliance · Vulnerability Management · Security Metrics · Threat Modeling full index →
🔬 Specialized Domains ICS/OT · Hardware · AI Security · Telecom & 5G full index →
🔎 Research & Analysis OSINT · Reverse Engineering · Threat Intelligence · Packet Analysis full index →

🎓 Learn & grow

Reference Coverage
Career Paths 15+ security roles with skill maps, salary ranges, and cert roadmaps
Certifications Reference 40+ certifications with cost, difficulty, and domain coverage
Interview Prep Questions by role: SOC analyst, pentester, DFIR, cloud security
Home Lab Setup Hardware, hypervisors, network design, detection stacks
Hands-On Labs Free lab environments and CTF platforms mapped to each security domain
Cybersecurity Book List Curated reading organized by discipline and level
Starred Repositories Curated GitHub repos structured around the security technology landscape

Free training platforms — Antisyphon, Black Hills, PortSwigger, HTB Academy, TryHackMe, LetsDefend, and more — live in Hands-On Labs and Resources.


🛠️ ATTACK-Navi

The interactive companion to this library — a MITRE ATT&CK workbench for coverage review, detection engineering, exposure mapping, and threat-intelligence correlation across the Enterprise, ICS, and Mobile domains, consuming the same coverage data published here.

Capability Details
Heatmap modes Coverage, detection, exposure, compliance, and risk — 24 analytic lenses
Live integrations MISP, OpenCTI, EPSS, CISA KEV, NVD, Elastic, Splunk, Sigma, Atomic Red Team, ExploitDB, Nuclei
Data STIX 2.1 import/export, custom technique editing, collection sharing
Deployment Docker or GitHub Pages

Repository  ·  Live Site  ·  Docs


🤝 Contributing, projects & license

Other projects: LimeWire — Python desktop audio studio · PokeNav — offline-first Pokémon encyclopedia.

Contributions, corrections, and new references are welcome — see CONTRIBUTING and open an issue to suggest a tool, fix content, or propose a new discipline. Released under the MIT License.

Disclaimer. All offensive material is provided for authorized security testing, education, and defensive research only.

🌐 Live Site · 📖 Reference Index · 🧭 Discipline Paths

🐺 TeamStarWolf — built for the cybersecurity community.

Pinned Loading

  1. TeamStarWolf TeamStarWolf Public

    An open, threat-informed cybersecurity reference library — 140 in-depth references, 16 how-to guides, and 47 discipline paths, anchored to MITRE ATT&CK and mapped to real controls, detections, and …

    Python 11 1