Skip to content
View TeamStarWolf's full-sized avatar
👾
Vibing…
👾
Vibing…

Block or report TeamStarWolf

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
TeamStarWolf/README.md

🐺 TeamStarWolf

An open, threat-informed cybersecurity reference library

Practitioner-built references for offense, defense, cloud, identity, GRC, and specialized security — anchored to MITRE ATT&CK and mapped to real controls, detections, and tooling.

Reference docs Discipline paths ATT&CK Live docs License: MIT

Reference Index  ·  Discipline Paths  ·  Threat-Informed Defense  ·  Coverage & Data  ·  ATTACK-Navi


About

TeamStarWolf is a free, vendor-neutral knowledge base for working security practitioners. It is not a blog or a link dump — it is a structured library of 122 in-depth reference documents and 47 discipline learning paths that cover the cybersecurity field end to end: how attacks work, how to detect and respond to them, how to harden systems and clouds, how to govern risk, and how to build a career doing it.

Three principles run through everything here:

  • ATT&CK at the center. Adversary behavior is the common language. References map techniques to the controls that mitigate them (NIST 800-53 via CTID), the detections that catch them, and the tests that validate them.
  • Operational, not theoretical. Real commands, real queries, real tooling, and real detection logic — written to be used on an engagement or in a SOC, not just read.
  • Open and practitioner-built. Everything is free, MIT-licensed, and cross-referenced so you can move from a concept to a command to a control in a couple of clicks.

New here? Jump to Start here for goal-based entry points, or browse the full Reference Index.


At a glance

📚 122 reference documents 🧭 47 discipline learning paths 🗺️ 26 ATT&CK Navigator coverage layers
🐉 691 Enterprise + 83 ICS + 124 Mobile techniques 👥 168 threat groups & 784 software profiled 🎬 52 campaigns · 🛡️ 44 mitigations
🔬 691 detection strategies · 1,739 analytics 🧬 969 CWE weaknesses · 615 CAPEC patterns 🛡️ 156 D3FEND countermeasures
💳 123 MITRE F3 fraud techniques (8 tactics) 🔁 CTEM 5-stage exposure loop 🎯 65 multi-platform detection queries
🔗 5,314 control→technique mappings (CTID) 🏢 60+ enterprise vendors mapped to NIST 800-53 📋 106 data components / log sources
🎓 40+ certifications & role roadmaps 🧪 Home-lab & free-training guides 🆓 Free · open source · MIT licensed

Start here

Pick your goal — each path drops you into the right part of the library.

I want to… Start with
Learn a discipline from zero Discipline learning paths → pick a track (e.g. Threat Intelligence, Detection Engineering, Red Teaming)
Run or prep for a pentest Penetration Testing Methodology · Pentest Checklists · Red Team Reference
Build detections & hunt Technique Detection Library · Detection Rules · Threat Hunting · SIEM Reference
Map coverage & find gaps Threat-Informed Defense · ATT&CK Matrix Analysis · Navigator layers
Respond to an incident Incident Response · IR Playbooks · Digital Forensics
Harden systems & cloud Windows / Linux hardening · Cloud Security · Zero Trust
Run an exposure management program CTEM Reference · Vulnerability Management · Priority Gap Analysis
Defend against financial fraud MITRE F3 Fraud Framework · Social Engineering · Identity Security
Break into the field / level up Career Paths · Certifications · Home Lab Setup · Free Training

⭐ Threat-Informed Defense

The flagship of the library: MITRE ATT&CK at the center, enriched with the vulnerability, weakness, detection, and control knowledge that turns a coverage map into decisions. It shares its data model with the ATTACK-Navi workbench, and the mappings below are machine-readable so you can query them, not just read them.

Resource What you get
Threat-Informed Defense Reference The ATT&CK-centric knowledge graph (CVE → CWE → CAPEC → ATT&CK → D3FEND), the open-source data-source stack, and the per-technique coverage-stack model
ATT&CK Matrix Analysis Reference 24 analytic lenses for reading an ATT&CK matrix — mitigation, threat activity, exposure, detection, and composite risk
Technique Detection Library Multi-platform detection queries (Splunk · Elastic · Microsoft · Chronicle · CrowdStrike) keyed to ATT&CK techniques and the NIST controls that mitigate them
ATT&CK Navigator Coverage Layers Live heatmaps of NIST 800-53 R5 control depth and vendor/domain coverage — load the master layer ↗

ATT&CK knowledge base — the full MITRE ATT&CK Enterprise matrix (v18.1), parsed and cross-referenced:

Resource What you get
ATT&CK Technique Atlas All 691 Enterprise techniques by tactic, each scored by threat-group usage, software, ATT&CK mitigations, NIST controls, and detection availability
Technique Detail Pages A full consolidated write-up per technique — description, mitigations, NIST controls, detections, and the groups & software that use it
Threat Group Profiles 168 adversary groups (APTs, eCrime) with aliases, attributed techniques, and tooling
ATT&CK Software Reference 784 malware families & tools with the techniques they implement and the groups that use them
ATT&CK Campaigns Reference 52 intrusion campaigns with active windows, techniques, software, and group attribution
ATT&CK Mitigations Reference All 44 ATT&CK mitigations (M-codes) and the techniques each one addresses
ATT&CK Priority Gap Analysis The most-used, least-covered techniques — where to focus detection and mitigation
ICS ATT&CK Atlas · Mobile ATT&CK Atlas The ICS (83 techniques) and Mobile (124 techniques) ATT&CK matrices, same cross-referenced treatment

Machine-readable datasets  ·  Technique profiles  ·  Group → Technique  ·  Software → Technique  ·  Mitigation → Technique  ·  Groups  ·  Software  ·  Mitigations  ·  Campaigns  ·  ICS datasets  ·  Mobile datasets

Detection engineering — MITRE's own detection guidance, with concrete log sources and tunable logic:

Resource What you get
ATT&CK Detection Strategies 691 detection strategies and 1,739 analytics — per technique, the log sources/channels, detection logic, and tunable parameters to detect it
Technique Detection Library Ready-to-adapt SIEM/EDR queries (Splunk · Elastic · Microsoft · Chronicle · CrowdStrike)
ATT&CK Data Components & Log Sources 106 telemetry categories mapped to the techniques they detect — plan your logging coverage

Completing the knowledge graph — the weakness, attack-pattern, and defense nodes of CVE → CWE → CAPEC → ATT&CK → D3FEND:

Resource What you get
CWE Weakness Reference 969 weakness types (10 pillars, 114 classes) with consequences, mitigations, and a data-driven "most-attacked" ranking
CAPEC Attack Pattern Reference 615 attack patterns — 177 bridging directly to ATT&CK techniques, linked to their CWE weaknesses
D3FEND Countermeasure Reference 156 defensive techniques (7 D3FEND tactics) mapped to the 426 ATT&CK techniques they counter

More datasets  ·  Detection strategies  ·  Analytics  ·  Data components  ·  Technique → D3FEND  ·  CWE  ·  CAPEC

Exposure management & fraud — running the loop, and extending it past the intrusion to where the money leaves:

Resource What you get
CTEM Reference Continuous Threat Exposure Management — Gartner's 5-stage loop (scope → discover → prioritize → validate → mobilize), the EASM/CAASM/BAS/AEV tool landscape, metrics that matter, and a 90-day starting plan wired to this library's data
MITRE F3 Fraud Framework The Fight Fraud Framework123 fraud-actor techniques across 8 tactics (through to Monetization), from MITRE's Center for Threat-Informed Defense · Navigator layer · datasets

📚 Explore the library

Curated highlights by domain — see the full Reference Index for all 122 documents.

🗡️ Offensive Security — adversary tradecraft, end to end

Reconnaissance and initial access through privilege escalation, lateral movement, and exfiltration — mapped to ATT&CK with real tooling, commands, and OPSEC.

Reference Coverage
Penetration Testing Methodology Structured methodology for external, internal, web, and AD engagements
Red Team Reference ROE, C2 frameworks, OPSEC, payload dev, lateral movement tradecraft
Active Directory Attacks Kerberoasting, DCSync, Golden tickets, BloodHound, AD CS attacks
Web Application Pentesting SQLi, XSS, SSRF, JWT attacks, Burp Suite, auth bypass
Social Engineering Reference Phishing, vishing, AiTM, pretexting, campaign ops
Privilege Escalation Reference Windows and Linux privesc with detection and remediation
Exploit Development Reference Buffer overflows, ROP chains, shellcode, pwntools
CTF Methodology Web, forensics, crypto, reversing, pwn — systematic approach and tooling
🛡️ Defensive Security — detect, hunt, respond, investigate

The blue-team lifecycle: detection engineering, hypothesis-driven hunting, incident response, and forensics, with query languages and data-source guidance for the major SIEM/EDR stacks.

Reference Coverage
Incident Response Reference NIST/SANS IR frameworks, live response, forensic triage
Threat Hunting Reference Hypothesis-driven hunting, KQL/SPL queries, data sources
SIEM Reference Splunk, Sentinel, QRadar, Elastic — query languages and detection engineering
Digital Forensics Reference Disk, memory, network, and cloud forensics workflows
Malware Analysis Reference Static/dynamic analysis, sandbox, behavioral detection
Purple Team Reference Adversary emulation, Atomic Red Team, detection validation
Detection Rules Reference Sigma, YARA, Suricata rule writing with examples
Network Defense Reference IDS/IPS, firewall policy, network segmentation, NDR
☁️ Cloud & Infrastructure — secure the modern stack

Cloud-native security across AWS/Azure/GCP, containers and Kubernetes, CI/CD and supply chain, and OS-level hardening — attacker techniques paired with the controls that stop them.

Reference Coverage
Cloud Security Reference AWS/Azure/GCP controls, IAM, CSPM, cloud-native threats
Cloud Attack Reference Cloud privilege escalation, lateral movement, exfiltration, persistence
Container Security Reference Docker hardening, Kubernetes security, container escapes
DevSecOps Reference SAST/DAST/SCA, GitHub Actions security, secrets in CI/CD
Supply Chain Security Reference SBOM, Sigstore/cosign, SLSA, dependency security
Network Security Architecture DMZ design, VLAN segmentation, firewall policy
Windows Hardening Reference Sysmon, WEF, Defender, AppControl, GPO, ASR rules
Linux Hardening Reference CIS benchmarks, sysctl, SELinux, auditd, service hardening
🔑 Identity, Access & Cryptography — the new perimeter

Identity is the primary attack surface in cloud-first environments. IAM and PAM architecture, Zero Trust, secrets management, and applied cryptography — with attacker techniques and defensive design side by side.

Reference Coverage
Identity Access Management Reference IAM architecture, MFA, PAM, JIT, SSO
Active Directory Security Reference AD hardening, tiered admin, MDI, Kerberos defense
Zero Trust Reference NIST SP 800-207, CISA ZTMM, microsegmentation, BeyondCorp
Secrets Management Reference Vault, AWS Secrets Manager, rotation, detection
Cryptography Reference Symmetric/asymmetric, TLS, PKI, HSM, quantum-resistant algorithms
Password Security Reference Hash formats, hashcat/John, credential stuffing defense
📋 Governance, Risk & Compliance — run the program

Turning security into a managed program: control frameworks, risk quantification, metrics, threat modeling, and vulnerability management that maps back to ATT&CK and real business risk.

Reference Coverage
GRC Compliance Reference NIST 800-53, ISO 27001, SOC 2, PCI DSS, HIPAA, CMMC
Security Metrics Reference MTTD/MTTR, vulnerability SLAs, SOC KPIs, FAIR model
Threat Modeling Reference STRIDE, PASTA, attack trees, MITRE ATT&CK integration
Vulnerability Management Reference CVSS, EPSS, CISA KEV, VEX, patch prioritization
Privacy Engineering Reference GDPR/CCPA, PbD, data minimization, PIA
Security Architecture Reference Zero trust, defense-in-depth, SABSA, enterprise patterns
🔬 Specialized Domains — beyond the enterprise IT boundary

Where security meets the physical and the emerging: vehicles, industrial control systems, hardware and firmware, mobile, radio, and AI/LLM systems — each with its own threat model and toolchain.

Reference Coverage
Automotive Security Reference CAN bus, ECU, V2X, OTA updates, ISO 21434
ICS/OT Security Reference SCADA, PLC, Purdue model, IEC 62443, OT incident response
Hardware Security Reference TPM, HSM, side-channel attacks, JTAG/SWD, fault injection
Firmware & IoT Security Reference Binwalk, UART/JTAG extraction, firmware emulation
Mobile Security Reference OWASP MASVS, Android/iOS RE, Frida, MDM/MAM
AI Security Reference LLM threat models, prompt injection, adversarial ML, MCP security
SDR & RF Security Reference HackRF, Flipper Zero, sub-GHz analysis, RF attack surface
🔎 Research & Analysis — recon, RE, and traffic

The investigative disciplines: open-source intelligence, reverse engineering, threat intelligence, and the network and protocol analysis skills that underpin both offense and defense.

Reference Coverage
OSINT Reference Passive recon, Shodan/Censys, GEOINT, SOCMINT, automation
Reverse Engineering Reference Ghidra/IDA/Binary Ninja, dynamic analysis, firmware RE
Threat Intelligence Reference Intel lifecycle, STIX/TAXII, threat actor tracking
Threat Actors Nation-state APTs, ransomware groups, and eCrime actors mapped to ATT&CK
Network Protocols Reference TCP/IP, DNS, TLS, authentication protocols, analysis tools
Packet Analysis Reference Wireshark, tcpdump, Zeek, JA3, attack pattern detection
Network Forensics Reference PCAP forensics, NetFlow, encrypted traffic analysis, cloud

🗺️ Coverage & Data

Machine-readable mappings that connect security vendors → NIST 800-53 controls → ATT&CK techniques, plus the ATT&CK Navigator layers that visualize them. The control→technique bridge is sourced from the authoritative CTID Mappings Explorer (NIST 800-53 R5 → ATT&CK v16.1). See CONTROLS_MAPPING.md and COVERAGE_SCHEMA.md for the model and scores/coverage_gaps.md for gap analysis.

Resource Description
ATT&CK Navigator Layer NIST 800-53 R5 → ATT&CK control-depth heatmap (470 techniques, CTID-sourced) · Load in Navigator ↗
Control → Technique edges NIST 800-53 R5 → ATT&CK mappings, CTID (5,314 edges, 109 controls)
Vendor → Control edges 60+ vendors → NIST 800-53 controls (237 edges)
Vendor → Technique edges Derived vendor → ATT&CK coverage via control join (17K+ edges)
Technique Detection Library Multi-platform detections keyed to techniques + mitigating NIST controls
Group Frequency layer ATT&CK techniques colored by threat-group usage — the most common adversary behaviors
Framework Blind Spots layer The 223 techniques with no NIST 800-53 control mapping — coverage blind spots
Enterprise Security Pipeline End-to-end security lifecycle with vendor mapping across all 6 stages

🎓 Learn & grow

Career & study
Reference Coverage
Career Paths 15+ security roles with skill maps, salary ranges, and cert roadmaps
Certifications Reference 40+ certifications with cost, difficulty, and domain coverage
Interview Prep Questions by role: SOC analyst, pentester, DFIR, cloud security
Home Lab Setup Hardware, hypervisors, network design, detection stacks
Hands-On Labs Free lab environments and CTF platforms mapped to each security domain
Cybersecurity Book List Curated reading organized by discipline and level
Starred Repositories Curated GitHub repos structured around the security technology landscape
Free training platforms
Platform What you get
Antisyphon Training Pay-what-you-can live courses — SOC, pentesting, active defense
Black Hills Information Security Hundreds of free webcasts on every security discipline
TCM Security Academy Practical ethical hacking and SOC content, free tier
PortSwigger Web Security Academy Best free web security training — interactive labs for every major vuln class
Hack The Box Academy Free Student tier — SOC, DFIR, pentesting, and cloud paths
TryHackMe Browser-based labs from beginner to advanced, no local setup required
IppSec HackTheBox walkthroughs with full attack methodology
Blue Team Labs Online Free investigation challenges for detection, forensics, and IR
LetsDefend Free SOC simulator for alert triage and threat analysis
CISA Training Catalog No-cost federal training — ICS/OT, cloud, and IR
Anthropic Courses Free AI and LLM security courses

🛠️ ATTACK-Navi

Deploy to GitHub Pages Docker Build License: MIT

The interactive companion to this library — a MITRE ATT&CK workbench for coverage review, detection engineering, exposure mapping, and threat-intelligence correlation. Supports Enterprise, ICS, and Mobile ATT&CK domains, and consumes the same coverage data published here.

Capability Details
Heatmap modes Coverage, detection, exposure, compliance, and risk — 24 analytic lenses
Live integrations MISP, OpenCTI, EPSS, CISA KEV, NVD, Elastic, Splunk, Sigma, Atomic Red Team, ExploitDB, Nuclei
Data STIX 2.1 import/export, custom technique editing, collection sharing
Deployment Docker or GitHub Pages

Repository  ·  Live Site  ·  Docs


📦 Other projects

Project Description
LimeWire Python desktop audio studio — download, analysis, editing, stem separation, and batch processing
PokeNav Offline-first Pokémon encyclopedia with game-aware browsing and trainer archives

🤝 Contributing & license

Contributions, corrections, and new references are welcome — see CONTRIBUTING and open an issue to suggest a tool, fix content, or propose a new discipline. Released under the MIT License.

Disclaimer. All offensive material is provided for authorized security testing, education, and defensive research only. Use it only against systems you own or have explicit permission to test.

📖 Reference Index · 🧭 Discipline Paths · 🌐 Live Docs

🐺 TeamStarWolf — built for the cybersecurity community.

Pinned Loading

  1. TeamStarWolf TeamStarWolf Public

    GitHub profile README for TeamStarWolf.

    Python 8