Overview
Wolverine Overview
The Problem
The security tool market is crowded and fast-moving. Every vendor describes what they do in their own language, making it nearly impossible to see how products truly stack up against one another. Security leaders, architects, and procurement teams are left relying on marketing claims, spreadsheets, and tribal knowledge to make high-stakes purchasing and rationalization decisions.
How Wolverine Solves It
Wolverine creates a digital twin of your security stack by organizing tools onto a single, consistent knowledge graph so any tool can be understood and compared on the same terms. At its core, Wolverine separates what a tool does from how a specific product does it - capturing underlying capabilities in a vendor-neutral way while preserving each product's distinct features. The normalized taxonomy follows a clear hierarchy: Vendor -> Tool -> Domain -> Category -> Subcategory -> Capability -> Feature -> Threat/Technique This structure turns a scattered market into a clear, queryable picture - making it easy to see where tools overlap, where real gaps exist, and which products genuinely deliver the outcomes your organization needs.
Key Capabilities
- Stack Gap Analysis: Identify overlap, blind spots, and consolidation opportunities across your existing security portfolio.
- Side-by-Side Comparison: Compare tools at the capability level rather than relying on vendor feature lists or marketing language.
- Threat Coverage Mapping: Map your defensive tools against threats and techniques to understand where you are protected and where exposure remains.
- Vendor-Neutral Classification: Every tool is described using the same model, eliminating inconsistency and enabling apples-to-apples evaluation.
Use Case Example
A CISO managing dozens of security tools across endpoint, network, cloud, and identity domains faces an annual budget review. Using Wolverine, the team queries the knowledge graph to visualize which capabilities are duplicated across multiple products and which threat techniques lack any defensive coverage. The result is a prioritized rationalization plan - tools to consolidate, gaps to fill, and a defensible business case for leadership.
Deployment
Wolverine is delivered as a container product on AWS Marketplace. Please refer to the deployment instructions and usage guide provided with the container image for setup details, including supported orchestration platforms and configuration requirements.
Scope and Prerequisites
- Wolverine is a knowledge-graph intelligence product for security tool classification and comparison. It does not perform active scanning, replace a SIEM, or execute automated remediation.
- The taxonomy is maintained and updated by Cyberhill to reflect the evolving security tool landscape.
- Consult the usage instructions for IAM permissions, networking requirements, and resource sizing guidance.
Who It Is For
- Security Leaders (CISOs, VPs of Security): Rationalize tool spend and justify budget decisions with structured evidence.
- Security Architects: Evaluate new products against existing capabilities and threat coverage.
- Procurement Teams: Compare vendors on a level playing field without relying on sales presentations.
About Cyberhill
Wolverine is built by Cyberhill, a team focused on bringing structure and transparency to the security tool ecosystem. For questions, demos, or pilot requests, reach out through the support channel listed on this page, or visit us at https://www.cyberhill.ai
Get Started
Subscribe to Wolverine on AWS Marketplace to begin mapping your security stack. Contact Cyberhill to request a guided demo or sample gap-analysis report.
Highlights
- Stack Gap Analysis: Identify overlap, blind spots, and consolidation opportunities across your security portfolio. Wolverine queries your tool inventory against its normalized knowledge graph to reveal where multiple products cover the same capability and where threat techniques lack any defensive coverage, giving security leaders a prioritized rationalization plan backed by structured evidence rather than guesswork.
- Capability-vs-Feature Separation for True Comparison: Wolverine separates what a tool does (vendor-neutral capabilities) from how a specific product does it (features), enabling genuine side-by-side evaluation. Instead of comparing marketing language, teams compare tools at the same abstraction level, making procurement decisions faster and more defensible across any security domain.
- Normalized Taxonomy Across the Entire Security Landscape: A single consistent model maps every tool from Vendor to Tool to Domain to Category to Subcategory to Capability to Feature to Threat/Technique. This structured hierarchy turns a fragmented market into a queryable, navigable knowledge graph that security architects and procurement teams can use to evaluate any product on equal terms.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
- Monthly subscription
- $15,000.00/month
Vendor refund policy
Refund requests must be submitted within 30 days of subscription. Contact support@cyberhillpartners.com with your AWS account ID and a description of the issue. We will respond within 5 business days. Refunds are not issued for usage already consumed beyond the refund window. For billing disputes, contact us with your account details.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Cloudformation ECS Deployment
- Amazon ECS
Container image
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
Initial Release of Wolverine
Additional details
Usage instructions
Wolverine runs entirely in your own AWS account and builds its own infrastructure, so no existing servers or networking are needed. Install in the US East (N. Virginia) region, us-east-1. Have a strong administrator password ready, and allow about 30 minutes.
Step 1: Start the installation
After subscribing, choose Continue to Configuration, then Continue to Launch, and select Launch CloudFormation - the AWS service that builds the software for you. Give the installation a short, lowercase name such as "wolverine"; it is used to label Wolverine's activity logs.
Step 2: Fill in the settings
Four settings, only the first required.
- Administrator password (required). Your first Wolverine login. Use a strong, random value and save it in your password manager. It goes directly to your own application and is never shown in the AWS console, kept in the installation history, or sent to Cyberhill - it stays in the account you own.
- Administrator email (optional, defaults to admin@cyberhill.com ). This is also your sign-in username, so use a shared team mailbox such as ops@yourcompany.com rather than one person's address.
- Custom domain and certificate (optional, used together). Leave blank and Wolverine is published at a secure address AWS generates for you, ending in cloudfront.net. To use your own hostname, enter it along with the ARN (unique identifier) of a matching AWS Certificate Manager certificate created in us-east-1, then set DNS in Step 4.
Step 3: Approve and create
Select "I acknowledge that AWS CloudFormation might create IAM resources" and choose Submit. Wolverine creates two IAM roles - the permissions its components use to start up and to reach the Wolverine service. Installation takes 20-30 minutes; follow progress on the Events tab.
Step 4: Sign in
At CREATE_COMPLETE, open the Outputs tab:
- ApplicationURL: where Wolverine runs. Open it and sign in with the email and password from Step 2.
- AdminConsoleURL: the administration area for users and organizations.
- CloudFrontDomainName: if using a custom domain, point your hostname at this with a CNAME or a Route 53 alias record.
- ClusterName and VpcId: the AWS resources running Wolverine, useful if you contact support.
- Logs are in Amazon CloudWatch under /ecs/ plus your installation name.
Step 5: Create your first everyday user
The administrator account manages the system rather than daily work, so create a standard user. In AdminConsoleURL:
- Under Organizations, choose Add and create one for your company.
- Under Users, choose Add. Enter email, name and username, select that organization, and set a password.
- Select Active: an account saved without it cannot sign in.
- Save, reopen the user, and under Permissions add them to the "user" group; this is only available once the account exists. They can now sign in at ApplicationURL. Repeat for each person who needs access. If something goes wrong If installation stops early, AWS removes what it created. On the Events tab, find the earliest CREATE_FAILED row - it names the cause, most often an account limit on VPCs, Elastic IPs or database instances. Raise it in Service Quotas and run the installer again. Otherwise contact support@cyberhillpartners.com .
Support
Vendor support
Contact Support
For questions, troubleshooting, or assistance with Wolverine, contact the Cyberhill support team at support@cyberhillpartners.com .
Scope of Support
The Cyberhill team can assist with product setup and configuration, knowledge graph queries, taxonomy questions, and general usage guidance. If you experience issues with deployment, data accuracy, or need help interpreting results, reach out via email with a description of the issue. ## Getting Started If you are evaluating Wolverine or would like a guided demo before subscribing, contact the same email address to request a discovery call or sample gap-analysis walkthrough.
Refunds and Billing
For billing questions or refund requests related to your AWS Marketplace subscription, contact Cyberhill support with your AWS account details and a description of the concern.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products

