A cybersecurity reference library
TeamStarWolf is an open collection of reference material on cybersecurity practice. It covers offensive testing, detection and response, system and cloud hardening, identity, governance and compliance, and specialized areas such as industrial control systems and AI security.
Most of the material is in one of four forms. Reference documents summarize a topic, its terminology, its tooling, and the relevant public frameworks and guidance. How-to guides walk through a specific task step by step. Learning paths suggest an order for studying a discipline and collect training, tools, books, and certifications for it. Framework pages are generated from MITRE data, one page for each ATT&CK technique, group, software entry, campaign, and mitigation, and for each CAPEC, D3FEND, ATLAS, and F3 entry. The library also includes curated lists of tools, reading, and other resources, and Tools Research studies that review security products and their integrations against the vendors' official documentation. Case Studies examine how the threat landscape is changing, with every claim graded by evidence.
Where a published mapping exists, an ATT&CK technique is linked to the NIST SP 800-53 controls that mitigate it, the detection strategies and analytics MITRE publishes for it, the CAPEC attack patterns that reference it (and through them the related CWE weaknesses), and the countermeasures in MITRE D3FEND. These relationships are also published as data files and ATT&CK Navigator layers.
It can be read here on GitHub or on the website, which renders the same files.
The reference index lists the reference documents alphabetically. The website's sidebar groups them by domain.
Most of these pages restate public MITRE knowledge bases so they can be browsed and cross-referenced in one place. The Threat-Informed Defense reference explains how they fit together.
| Reference | Contents |
|---|---|
| Threat-Informed Defense | How vulnerabilities, weaknesses, attack patterns, ATT&CK techniques, and countermeasures relate (from CVE to CWE, CAPEC, ATT&CK, and D3FEND), and how to use those relationships to reason about coverage |
| Framework pages | One page for each ATT&CK technique, group, software entry, campaign, and mitigation, and for each CAPEC, D3FEND, ATLAS, and F3 entry, linked to one another |
| ATT&CK Technique Atlas and technique pages | Enterprise techniques by tactic, with the groups, software, mitigations, NIST controls, and detections associated with each |
| ICS and Mobile atlases | ICS and Mobile techniques by tactic, with the groups, software, and mitigations associated with each (no NIST control mappings) |
| Threat Groups, Software, Campaigns, Mitigations | ATT&CK's groups, software, campaigns, and mitigations, with the number of techniques associated with each and example techniques for selected entries. Complete technique lists are in the data files. |
| Detection Strategies, Data Components | ATT&CK's detection strategies and analytics, and the telemetry each relies on |
| CWE, CAPEC, D3FEND | Weaknesses, attack patterns, and defensive countermeasures, linked to ATT&CK where a mapping exists |
| ATLAS, Engage, F3 | MITRE's frameworks for attacks on AI systems, adversary engagement, and financial fraud |
| EMB3D, FiGHT | MITRE's threat models for embedded devices and for 5G networks (FiGHT is covered in the Telecom and 5G reference) |
The relationships behind these pages are published as JSONL files in data/ and as ATT&CK
Navigator layers, which navigator/index.md lists with a description and a link to
open each one in the Navigator. data/EDGES.md describes each relationship file,
data/VOCABULARIES.md lists the allowed field values, and
data/MANIFEST.json records each file's source, license, row count, and checksum.
The ATT&CK data files, the technique pages, and the framework pages are built from MITRE ATT&CK v19.2. The technique records also keep a small number of techniques that MITRE has since revoked or renumbered. Some summary pages, including the technique atlases, Threat Group Profiles, and the Priority Gap Analysis, and most Navigator layers were generated from earlier ATT&CK releases and have not yet been regenerated. Each states the version it was built from.
Control mappings from NIST SP 800-53 Rev. 5 to ATT&CK come from the Center for Threat-Informed Defense Mappings Explorer. This library uses the Rev. 5 mapping for ATT&CK v16.1. Not every technique has a control mapping: the CTID mapping does not cover every technique, and techniques added or renumbered after v16.1 have no mapping under their current ID.
The vendor-to-control mappings in CONTROLS_MAPPING.md are this library's own editorial assessments. They are not provided or validated by the vendors, and they should be treated as a starting point for research rather than as evidence of coverage. The vendor, control, and technique model is described in COVERAGE_SCHEMA.md.
Continuous integration validates the JSONL data files, checks the structure of the main Navigator coverage layer, and checks that the figures quoted on the index pages and the data manifest match the data. A scheduled link check reports broken links but does not block changes.
| Domain | Representative references |
|---|---|
| Offensive | Penetration Testing Methodology, Red Team, Active Directory Attacks, Web Application Testing |
| Defensive | Incident Response, Threat Hunting, SIEM, Detection Rules |
| Cloud and infrastructure | Cloud Security, Container Security, DevSecOps, Supply Chain Security |
| Identity and cryptography | Identity and Access Management, Zero Trust, Active Directory Security, Cryptography |
| Governance and risk | GRC and Compliance, Vulnerability Management, Security Metrics, Threat Modeling |
| Specialized | ICS/OT, Hardware, AI Security, Telecom and 5G |
| Research and analysis | OSINT, Reverse Engineering, Threat Intelligence, Packet Analysis |
For study and career development, see Career Paths, Certifications, Interview Preparation, Home Lab Setup, Hands-On Labs, and the reading list.
ATTACK-Navi is a companion web application for exploring the Enterprise, ICS, and Mobile ATT&CK matrices. It draws on the same public sources as this library, MITRE ATT&CK and D3FEND and the CTID control mappings, which it loads directly in the browser. It also bundles several of this library's Navigator overlays and adds views for detection coverage, threat intelligence, vulnerability exposure, and compliance. It needs no backend, and a live version is hosted on GitHub Pages.
The references summarize third-party frameworks, standards, and publications, and they can fall behind upstream changes. Check the primary source before relying on a detail, particularly for version-specific facts, regulatory requirements, and anything you intend to run.
Offensive techniques and tooling are described for authorized testing, education, and defensive research. Do not use them against systems you do not have permission to test.
MITRE ATT&CK, ATLAS, CAPEC, CWE, D3FEND, EMB3D, Engage, F3, and FiGHT are maintained by The MITRE Corporation, and the Mappings Explorer is published by MITRE's Center for Threat-Informed Defense. ATT&CK is a registered trademark of The MITRE Corporation. This project is not affiliated with or endorsed by MITRE.
Corrections and additions are welcome. See CONTRIBUTING, or open an issue.
Original content is released under the MIT License. Data and text drawn from MITRE and other sources remain under their owners' terms, as described in THIRD_PARTY_NOTICES.md.



