Skip to content
View TeamStarWolf's full-sized avatar
👾
Vibing…
👾
Vibing…

Block or report TeamStarWolf

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
TeamStarWolf/README.md

TeamStarWolf

A cybersecurity reference library

About

TeamStarWolf is an open collection of reference material on cybersecurity practice. It covers offensive testing, detection and response, system and cloud hardening, identity, governance and compliance, and specialized areas such as industrial control systems and AI security.

Most of the material is in one of four forms. Reference documents summarize a topic, its terminology, its tooling, and the relevant public frameworks and guidance. How-to guides walk through a specific task step by step. Learning paths suggest an order for studying a discipline and collect training, tools, books, and certifications for it. Framework pages are generated from MITRE data, one page for each ATT&CK technique, group, software entry, campaign, and mitigation, and for each CAPEC, D3FEND, ATLAS, and F3 entry. The library also includes curated lists of tools, reading, and other resources, and Tools Research studies that review security products and their integrations against the vendors' official documentation. Case Studies examine how the threat landscape is changing, with every claim graded by evidence.

Where a published mapping exists, an ATT&CK technique is linked to the NIST SP 800-53 controls that mitigate it, the detection strategies and analytics MITRE publishes for it, the CAPEC attack patterns that reference it (and through them the related CWE weaknesses), and the countermeasures in MITRE D3FEND. These relationships are also published as data files and ATT&CK Navigator layers.

It can be read here on GitHub or on the website, which renders the same files.

Where to start

Goal Start with
Learn a discipline Learning paths, for example Threat Intelligence, Detection Engineering, or Red Teaming
Plan a penetration test Penetration Testing Methodology, Pentest Checklists, Red Team Reference
Write detections or hunt Technique Detection Library, Detection Rules, Threat Hunting, SIEM
Assess ATT&CK coverage Threat-Informed Defense, ATT&CK Matrix Analysis, Priority Gap Analysis, Navigator layers
Respond to an incident Incident Response, IR Playbooks, Digital Forensics
Harden systems and cloud Windows and Linux hardening, Cloud Security, Zero Trust
Manage vulnerabilities Vulnerability Management, Vulnerability Prioritization, CTEM, Triage a CVE, Tools Research
Secure AI and ML systems MITRE ATLAS, AI Security, AI and MCP Security, AI Threats 2026 case study
Use deception MITRE Engage, Honeypots and Deception, Deception Technology
Counter fraud MITRE F3, Social Engineering, Identity Security
Build a career Career Paths, Certifications, Home Lab Setup, Hands-On Labs

The reference index lists the reference documents alphabetically. The website's sidebar groups them by domain.

ATT&CK and related frameworks

Most of these pages restate public MITRE knowledge bases so they can be browsed and cross-referenced in one place. The Threat-Informed Defense reference explains how they fit together.

Reference Contents
Threat-Informed Defense How vulnerabilities, weaknesses, attack patterns, ATT&CK techniques, and countermeasures relate (from CVE to CWE, CAPEC, ATT&CK, and D3FEND), and how to use those relationships to reason about coverage
Framework pages One page for each ATT&CK technique, group, software entry, campaign, and mitigation, and for each CAPEC, D3FEND, ATLAS, and F3 entry, linked to one another
ATT&CK Technique Atlas and technique pages Enterprise techniques by tactic, with the groups, software, mitigations, NIST controls, and detections associated with each
ICS and Mobile atlases ICS and Mobile techniques by tactic, with the groups, software, and mitigations associated with each (no NIST control mappings)
Threat Groups, Software, Campaigns, Mitigations ATT&CK's groups, software, campaigns, and mitigations, with the number of techniques associated with each and example techniques for selected entries. Complete technique lists are in the data files.
Detection Strategies, Data Components ATT&CK's detection strategies and analytics, and the telemetry each relies on
CWE, CAPEC, D3FEND Weaknesses, attack patterns, and defensive countermeasures, linked to ATT&CK where a mapping exists
ATLAS, Engage, F3 MITRE's frameworks for attacks on AI systems, adversary engagement, and financial fraud
EMB3D, FiGHT MITRE's threat models for embedded devices and for 5G networks (FiGHT is covered in the Telecom and 5G reference)

Data

The relationships behind these pages are published as JSONL files in data/ and as ATT&CK Navigator layers, which navigator/index.md lists with a description and a link to open each one in the Navigator. data/EDGES.md describes each relationship file, data/VOCABULARIES.md lists the allowed field values, and data/MANIFEST.json records each file's source, license, row count, and checksum.

The ATT&CK data files, the technique pages, and the framework pages are built from MITRE ATT&CK v19.2. The technique records also keep a small number of techniques that MITRE has since revoked or renumbered. Some summary pages, including the technique atlases, Threat Group Profiles, and the Priority Gap Analysis, and most Navigator layers were generated from earlier ATT&CK releases and have not yet been regenerated. Each states the version it was built from.

Control mappings from NIST SP 800-53 Rev. 5 to ATT&CK come from the Center for Threat-Informed Defense Mappings Explorer. This library uses the Rev. 5 mapping for ATT&CK v16.1. Not every technique has a control mapping: the CTID mapping does not cover every technique, and techniques added or renumbered after v16.1 have no mapping under their current ID.

The vendor-to-control mappings in CONTROLS_MAPPING.md are this library's own editorial assessments. They are not provided or validated by the vendors, and they should be treated as a starting point for research rather than as evidence of coverage. The vendor, control, and technique model is described in COVERAGE_SCHEMA.md.

Continuous integration validates the JSONL data files, checks the structure of the main Navigator coverage layer, and checks that the figures quoted on the index pages and the data manifest match the data. A scheduled link check reports broken links but does not block changes.

Library by domain

Domain Representative references
Offensive Penetration Testing Methodology, Red Team, Active Directory Attacks, Web Application Testing
Defensive Incident Response, Threat Hunting, SIEM, Detection Rules
Cloud and infrastructure Cloud Security, Container Security, DevSecOps, Supply Chain Security
Identity and cryptography Identity and Access Management, Zero Trust, Active Directory Security, Cryptography
Governance and risk GRC and Compliance, Vulnerability Management, Security Metrics, Threat Modeling
Specialized ICS/OT, Hardware, AI Security, Telecom and 5G
Research and analysis OSINT, Reverse Engineering, Threat Intelligence, Packet Analysis

For study and career development, see Career Paths, Certifications, Interview Preparation, Home Lab Setup, Hands-On Labs, and the reading list.

ATTACK-Navi

ATTACK-Navi is a companion web application for exploring the Enterprise, ICS, and Mobile ATT&CK matrices. It draws on the same public sources as this library, MITRE ATT&CK and D3FEND and the CTID control mappings, which it loads directly in the browser. It also bundles several of this library's Navigator overlays and adds views for detection coverage, threat intelligence, vulnerability exposure, and compliance. It needs no backend, and a live version is hosted on GitHub Pages.

Accuracy and use

The references summarize third-party frameworks, standards, and publications, and they can fall behind upstream changes. Check the primary source before relying on a detail, particularly for version-specific facts, regulatory requirements, and anything you intend to run.

Offensive techniques and tooling are described for authorized testing, education, and defensive research. Do not use them against systems you do not have permission to test.

MITRE ATT&CK, ATLAS, CAPEC, CWE, D3FEND, EMB3D, Engage, F3, and FiGHT are maintained by The MITRE Corporation, and the Mappings Explorer is published by MITRE's Center for Threat-Informed Defense. ATT&CK is a registered trademark of The MITRE Corporation. This project is not affiliated with or endorsed by MITRE.

Contributing and license

Corrections and additions are welcome. See CONTRIBUTING, or open an issue.

Original content is released under the MIT License. Data and text drawn from MITRE and other sources remain under their owners' terms, as described in THIRD_PARTY_NOTICES.md.

Pinned Loading

  1. TeamStarWolf TeamStarWolf Public

    An open, threat-informed cybersecurity reference library — 140 in-depth references, 16 how-to guides, and 47 discipline paths, anchored to MITRE ATT&CK and mapped to real controls, detections, and …

    Python 12 3

  2. ATTACK-Navi ATTACK-Navi Public

    Browser-based MITRE ATT&CK analyst workbench (Angular 19) — 9 routed workspaces, 31 heatmap modes, command palette, MISP/OpenCTI integrations, and grounded threat-intel/exposure/detection/complianc…

    TypeScript 1