Practitioner-built references for offense, defense, cloud, identity, GRC, and specialized security — anchored to MITRE ATT&CK and mapped to real controls, detections, and tooling.
Reference Index · Discipline Paths · Threat-Informed Defense · Coverage & Data · ATTACK-Navi
TeamStarWolf is a free, vendor-neutral knowledge base for working security practitioners. It is not a blog or a link dump — it is a structured library of 122 in-depth reference documents and 47 discipline learning paths that cover the cybersecurity field end to end: how attacks work, how to detect and respond to them, how to harden systems and clouds, how to govern risk, and how to build a career doing it.
Three principles run through everything here:
- ATT&CK at the center. Adversary behavior is the common language. References map techniques to the controls that mitigate them (NIST 800-53 via CTID), the detections that catch them, and the tests that validate them.
- Operational, not theoretical. Real commands, real queries, real tooling, and real detection logic — written to be used on an engagement or in a SOC, not just read.
- Open and practitioner-built. Everything is free, MIT-licensed, and cross-referenced so you can move from a concept to a command to a control in a couple of clicks.
New here? Jump to Start here for goal-based entry points, or browse the full Reference Index.
| 📚 122 reference documents | 🧭 47 discipline learning paths | 🗺️ 26 ATT&CK Navigator coverage layers |
| 🐉 691 Enterprise + 83 ICS + 124 Mobile techniques | 👥 168 threat groups & 784 software profiled | 🎬 52 campaigns · 🛡️ 44 mitigations |
| 🔬 691 detection strategies · 1,739 analytics | 🧬 969 CWE weaknesses · 615 CAPEC patterns | 🛡️ 156 D3FEND countermeasures |
| 💳 123 MITRE F3 fraud techniques (8 tactics) | 🔁 CTEM 5-stage exposure loop | 🎯 65 multi-platform detection queries |
| 🔗 5,314 control→technique mappings (CTID) | 🏢 60+ enterprise vendors mapped to NIST 800-53 | 📋 106 data components / log sources |
| 🎓 40+ certifications & role roadmaps | 🧪 Home-lab & free-training guides | 🆓 Free · open source · MIT licensed |
Pick your goal — each path drops you into the right part of the library.
| I want to… | Start with |
|---|---|
| Learn a discipline from zero | Discipline learning paths → pick a track (e.g. Threat Intelligence, Detection Engineering, Red Teaming) |
| Run or prep for a pentest | Penetration Testing Methodology · Pentest Checklists · Red Team Reference |
| Build detections & hunt | Technique Detection Library · Detection Rules · Threat Hunting · SIEM Reference |
| Map coverage & find gaps | Threat-Informed Defense · ATT&CK Matrix Analysis · Navigator layers |
| Respond to an incident | Incident Response · IR Playbooks · Digital Forensics |
| Harden systems & cloud | Windows / Linux hardening · Cloud Security · Zero Trust |
| Run an exposure management program | CTEM Reference · Vulnerability Management · Priority Gap Analysis |
| Defend against financial fraud | MITRE F3 Fraud Framework · Social Engineering · Identity Security |
| Break into the field / level up | Career Paths · Certifications · Home Lab Setup · Free Training |
The flagship of the library: MITRE ATT&CK at the center, enriched with the vulnerability, weakness, detection, and control knowledge that turns a coverage map into decisions. It shares its data model with the ATTACK-Navi workbench, and the mappings below are machine-readable so you can query them, not just read them.
| Resource | What you get |
|---|---|
| Threat-Informed Defense Reference | The ATT&CK-centric knowledge graph (CVE → CWE → CAPEC → ATT&CK → D3FEND), the open-source data-source stack, and the per-technique coverage-stack model |
| ATT&CK Matrix Analysis Reference | 24 analytic lenses for reading an ATT&CK matrix — mitigation, threat activity, exposure, detection, and composite risk |
| Technique Detection Library | Multi-platform detection queries (Splunk · Elastic · Microsoft · Chronicle · CrowdStrike) keyed to ATT&CK techniques and the NIST controls that mitigate them |
| ATT&CK Navigator Coverage Layers | Live heatmaps of NIST 800-53 R5 control depth and vendor/domain coverage — load the master layer ↗ |
ATT&CK knowledge base — the full MITRE ATT&CK Enterprise matrix (v18.1), parsed and cross-referenced:
| Resource | What you get |
|---|---|
| ATT&CK Technique Atlas | All 691 Enterprise techniques by tactic, each scored by threat-group usage, software, ATT&CK mitigations, NIST controls, and detection availability |
| Technique Detail Pages | A full consolidated write-up per technique — description, mitigations, NIST controls, detections, and the groups & software that use it |
| Threat Group Profiles | 168 adversary groups (APTs, eCrime) with aliases, attributed techniques, and tooling |
| ATT&CK Software Reference | 784 malware families & tools with the techniques they implement and the groups that use them |
| ATT&CK Campaigns Reference | 52 intrusion campaigns with active windows, techniques, software, and group attribution |
| ATT&CK Mitigations Reference | All 44 ATT&CK mitigations (M-codes) and the techniques each one addresses |
| ATT&CK Priority Gap Analysis | The most-used, least-covered techniques — where to focus detection and mitigation |
| ICS ATT&CK Atlas · Mobile ATT&CK Atlas | The ICS (83 techniques) and Mobile (124 techniques) ATT&CK matrices, same cross-referenced treatment |
Machine-readable datasets · Technique profiles · Group → Technique · Software → Technique · Mitigation → Technique · Groups · Software · Mitigations · Campaigns · ICS datasets · Mobile datasets
Detection engineering — MITRE's own detection guidance, with concrete log sources and tunable logic:
| Resource | What you get |
|---|---|
| ATT&CK Detection Strategies | 691 detection strategies and 1,739 analytics — per technique, the log sources/channels, detection logic, and tunable parameters to detect it |
| Technique Detection Library | Ready-to-adapt SIEM/EDR queries (Splunk · Elastic · Microsoft · Chronicle · CrowdStrike) |
| ATT&CK Data Components & Log Sources | 106 telemetry categories mapped to the techniques they detect — plan your logging coverage |
Completing the knowledge graph — the weakness, attack-pattern, and defense nodes of CVE → CWE → CAPEC → ATT&CK → D3FEND:
| Resource | What you get |
|---|---|
| CWE Weakness Reference | 969 weakness types (10 pillars, 114 classes) with consequences, mitigations, and a data-driven "most-attacked" ranking |
| CAPEC Attack Pattern Reference | 615 attack patterns — 177 bridging directly to ATT&CK techniques, linked to their CWE weaknesses |
| D3FEND Countermeasure Reference | 156 defensive techniques (7 D3FEND tactics) mapped to the 426 ATT&CK techniques they counter |
More datasets · Detection strategies · Analytics · Data components · Technique → D3FEND · CWE · CAPEC
Exposure management & fraud — running the loop, and extending it past the intrusion to where the money leaves:
| Resource | What you get |
|---|---|
| CTEM Reference | Continuous Threat Exposure Management — Gartner's 5-stage loop (scope → discover → prioritize → validate → mobilize), the EASM/CAASM/BAS/AEV tool landscape, metrics that matter, and a 90-day starting plan wired to this library's data |
| MITRE F3 Fraud Framework | The Fight Fraud Framework — 123 fraud-actor techniques across 8 tactics (through to Monetization), from MITRE's Center for Threat-Informed Defense · Navigator layer · datasets |
Curated highlights by domain — see the full Reference Index for all 122 documents.
🗡️ Offensive Security — adversary tradecraft, end to end
Reconnaissance and initial access through privilege escalation, lateral movement, and exfiltration — mapped to ATT&CK with real tooling, commands, and OPSEC.
| Reference | Coverage |
|---|---|
| Penetration Testing Methodology | Structured methodology for external, internal, web, and AD engagements |
| Red Team Reference | ROE, C2 frameworks, OPSEC, payload dev, lateral movement tradecraft |
| Active Directory Attacks | Kerberoasting, DCSync, Golden tickets, BloodHound, AD CS attacks |
| Web Application Pentesting | SQLi, XSS, SSRF, JWT attacks, Burp Suite, auth bypass |
| Social Engineering Reference | Phishing, vishing, AiTM, pretexting, campaign ops |
| Privilege Escalation Reference | Windows and Linux privesc with detection and remediation |
| Exploit Development Reference | Buffer overflows, ROP chains, shellcode, pwntools |
| CTF Methodology | Web, forensics, crypto, reversing, pwn — systematic approach and tooling |
🛡️ Defensive Security — detect, hunt, respond, investigate
The blue-team lifecycle: detection engineering, hypothesis-driven hunting, incident response, and forensics, with query languages and data-source guidance for the major SIEM/EDR stacks.
| Reference | Coverage |
|---|---|
| Incident Response Reference | NIST/SANS IR frameworks, live response, forensic triage |
| Threat Hunting Reference | Hypothesis-driven hunting, KQL/SPL queries, data sources |
| SIEM Reference | Splunk, Sentinel, QRadar, Elastic — query languages and detection engineering |
| Digital Forensics Reference | Disk, memory, network, and cloud forensics workflows |
| Malware Analysis Reference | Static/dynamic analysis, sandbox, behavioral detection |
| Purple Team Reference | Adversary emulation, Atomic Red Team, detection validation |
| Detection Rules Reference | Sigma, YARA, Suricata rule writing with examples |
| Network Defense Reference | IDS/IPS, firewall policy, network segmentation, NDR |
☁️ Cloud & Infrastructure — secure the modern stack
Cloud-native security across AWS/Azure/GCP, containers and Kubernetes, CI/CD and supply chain, and OS-level hardening — attacker techniques paired with the controls that stop them.
| Reference | Coverage |
|---|---|
| Cloud Security Reference | AWS/Azure/GCP controls, IAM, CSPM, cloud-native threats |
| Cloud Attack Reference | Cloud privilege escalation, lateral movement, exfiltration, persistence |
| Container Security Reference | Docker hardening, Kubernetes security, container escapes |
| DevSecOps Reference | SAST/DAST/SCA, GitHub Actions security, secrets in CI/CD |
| Supply Chain Security Reference | SBOM, Sigstore/cosign, SLSA, dependency security |
| Network Security Architecture | DMZ design, VLAN segmentation, firewall policy |
| Windows Hardening Reference | Sysmon, WEF, Defender, AppControl, GPO, ASR rules |
| Linux Hardening Reference | CIS benchmarks, sysctl, SELinux, auditd, service hardening |
🔑 Identity, Access & Cryptography — the new perimeter
Identity is the primary attack surface in cloud-first environments. IAM and PAM architecture, Zero Trust, secrets management, and applied cryptography — with attacker techniques and defensive design side by side.
| Reference | Coverage |
|---|---|
| Identity Access Management Reference | IAM architecture, MFA, PAM, JIT, SSO |
| Active Directory Security Reference | AD hardening, tiered admin, MDI, Kerberos defense |
| Zero Trust Reference | NIST SP 800-207, CISA ZTMM, microsegmentation, BeyondCorp |
| Secrets Management Reference | Vault, AWS Secrets Manager, rotation, detection |
| Cryptography Reference | Symmetric/asymmetric, TLS, PKI, HSM, quantum-resistant algorithms |
| Password Security Reference | Hash formats, hashcat/John, credential stuffing defense |
📋 Governance, Risk & Compliance — run the program
Turning security into a managed program: control frameworks, risk quantification, metrics, threat modeling, and vulnerability management that maps back to ATT&CK and real business risk.
| Reference | Coverage |
|---|---|
| GRC Compliance Reference | NIST 800-53, ISO 27001, SOC 2, PCI DSS, HIPAA, CMMC |
| Security Metrics Reference | MTTD/MTTR, vulnerability SLAs, SOC KPIs, FAIR model |
| Threat Modeling Reference | STRIDE, PASTA, attack trees, MITRE ATT&CK integration |
| Vulnerability Management Reference | CVSS, EPSS, CISA KEV, VEX, patch prioritization |
| Privacy Engineering Reference | GDPR/CCPA, PbD, data minimization, PIA |
| Security Architecture Reference | Zero trust, defense-in-depth, SABSA, enterprise patterns |
🔬 Specialized Domains — beyond the enterprise IT boundary
Where security meets the physical and the emerging: vehicles, industrial control systems, hardware and firmware, mobile, radio, and AI/LLM systems — each with its own threat model and toolchain.
| Reference | Coverage |
|---|---|
| Automotive Security Reference | CAN bus, ECU, V2X, OTA updates, ISO 21434 |
| ICS/OT Security Reference | SCADA, PLC, Purdue model, IEC 62443, OT incident response |
| Hardware Security Reference | TPM, HSM, side-channel attacks, JTAG/SWD, fault injection |
| Firmware & IoT Security Reference | Binwalk, UART/JTAG extraction, firmware emulation |
| Mobile Security Reference | OWASP MASVS, Android/iOS RE, Frida, MDM/MAM |
| AI Security Reference | LLM threat models, prompt injection, adversarial ML, MCP security |
| SDR & RF Security Reference | HackRF, Flipper Zero, sub-GHz analysis, RF attack surface |
🔎 Research & Analysis — recon, RE, and traffic
The investigative disciplines: open-source intelligence, reverse engineering, threat intelligence, and the network and protocol analysis skills that underpin both offense and defense.
| Reference | Coverage |
|---|---|
| OSINT Reference | Passive recon, Shodan/Censys, GEOINT, SOCMINT, automation |
| Reverse Engineering Reference | Ghidra/IDA/Binary Ninja, dynamic analysis, firmware RE |
| Threat Intelligence Reference | Intel lifecycle, STIX/TAXII, threat actor tracking |
| Threat Actors | Nation-state APTs, ransomware groups, and eCrime actors mapped to ATT&CK |
| Network Protocols Reference | TCP/IP, DNS, TLS, authentication protocols, analysis tools |
| Packet Analysis Reference | Wireshark, tcpdump, Zeek, JA3, attack pattern detection |
| Network Forensics Reference | PCAP forensics, NetFlow, encrypted traffic analysis, cloud |
Machine-readable mappings that connect security vendors → NIST 800-53 controls → ATT&CK techniques, plus the ATT&CK Navigator layers that visualize them. The control→technique bridge is sourced from the authoritative CTID Mappings Explorer (NIST 800-53 R5 → ATT&CK v16.1). See CONTROLS_MAPPING.md and COVERAGE_SCHEMA.md for the model and scores/coverage_gaps.md for gap analysis.
| Resource | Description |
|---|---|
| ATT&CK Navigator Layer | NIST 800-53 R5 → ATT&CK control-depth heatmap (470 techniques, CTID-sourced) · Load in Navigator ↗ |
| Control → Technique edges | NIST 800-53 R5 → ATT&CK mappings, CTID (5,314 edges, 109 controls) |
| Vendor → Control edges | 60+ vendors → NIST 800-53 controls (237 edges) |
| Vendor → Technique edges | Derived vendor → ATT&CK coverage via control join (17K+ edges) |
| Technique Detection Library | Multi-platform detections keyed to techniques + mitigating NIST controls |
| Group Frequency layer | ATT&CK techniques colored by threat-group usage — the most common adversary behaviors |
| Framework Blind Spots layer | The 223 techniques with no NIST 800-53 control mapping — coverage blind spots |
| Enterprise Security Pipeline | End-to-end security lifecycle with vendor mapping across all 6 stages |
Career & study
| Reference | Coverage |
|---|---|
| Career Paths | 15+ security roles with skill maps, salary ranges, and cert roadmaps |
| Certifications Reference | 40+ certifications with cost, difficulty, and domain coverage |
| Interview Prep | Questions by role: SOC analyst, pentester, DFIR, cloud security |
| Home Lab Setup | Hardware, hypervisors, network design, detection stacks |
| Hands-On Labs | Free lab environments and CTF platforms mapped to each security domain |
| Cybersecurity Book List | Curated reading organized by discipline and level |
| Starred Repositories | Curated GitHub repos structured around the security technology landscape |
Free training platforms
| Platform | What you get |
|---|---|
| Antisyphon Training | Pay-what-you-can live courses — SOC, pentesting, active defense |
| Black Hills Information Security | Hundreds of free webcasts on every security discipline |
| TCM Security Academy | Practical ethical hacking and SOC content, free tier |
| PortSwigger Web Security Academy | Best free web security training — interactive labs for every major vuln class |
| Hack The Box Academy | Free Student tier — SOC, DFIR, pentesting, and cloud paths |
| TryHackMe | Browser-based labs from beginner to advanced, no local setup required |
| IppSec | HackTheBox walkthroughs with full attack methodology |
| Blue Team Labs Online | Free investigation challenges for detection, forensics, and IR |
| LetsDefend | Free SOC simulator for alert triage and threat analysis |
| CISA Training Catalog | No-cost federal training — ICS/OT, cloud, and IR |
| Anthropic Courses | Free AI and LLM security courses |
The interactive companion to this library — a MITRE ATT&CK workbench for coverage review, detection engineering, exposure mapping, and threat-intelligence correlation. Supports Enterprise, ICS, and Mobile ATT&CK domains, and consumes the same coverage data published here.
| Capability | Details |
|---|---|
| Heatmap modes | Coverage, detection, exposure, compliance, and risk — 24 analytic lenses |
| Live integrations | MISP, OpenCTI, EPSS, CISA KEV, NVD, Elastic, Splunk, Sigma, Atomic Red Team, ExploitDB, Nuclei |
| Data | STIX 2.1 import/export, custom technique editing, collection sharing |
| Deployment | Docker or GitHub Pages |
Repository · Live Site · Docs
| Project | Description |
|---|---|
| LimeWire | Python desktop audio studio — download, analysis, editing, stem separation, and batch processing |
| PokeNav | Offline-first Pokémon encyclopedia with game-aware browsing and trainer archives |
Contributions, corrections, and new references are welcome — see CONTRIBUTING and open an issue to suggest a tool, fix content, or propose a new discipline. Released under the MIT License.
Disclaimer. All offensive material is provided for authorized security testing, education, and defensive research only. Use it only against systems you own or have explicit permission to test.
📖 Reference Index · 🧭 Discipline Paths · 🌐 Live Docs
🐺 TeamStarWolf — built for the cybersecurity community.

