Trust · Adversarial model
Threat matrix
Public-surface threat model for c1bertitans.com — the ENGINE PATH origin, mapped to MITRE ATT&CK (enterprise). Adversary-first. Controls stated as policy — not theater.
Scope and residual risk
In scope: apex website, contact form, static assets, DNS/mail adjacency as they affect the public brand surface. Out of scope here: live enclave SOC, firewall admin, admission PEPs (enclave-only).
This matrix is a design and assurance artifact, not a FedRAMP package and not a claim that every control is perfect on shared hosting. Residual risk is spoken: shared-tenancy limits, mail-on-host, and operator discipline still matter.
Live-origin punch list (2026-09-09).
R-01 cPanel/Webmail on brand DNS — DNS/cert burn (human). Apex paths 404.
R-02 Let’s Encrypt SAN is an asset inventory — next cert apex+www only.
R-03 Guest enrollment /guest-account /enroll/ — 404.
R-04 Trailing-slash 500s — 301 to pretty URL.
R-05 Public PHP mail handler — honeypot + rate limit; residual T1190 until serverless/mailto.
R-06 /board-brief — 404 (no longer fetchable).
R-07 X-Fringe-WAF stripped. R-08 header-only CSP. R-09 probe paths 404 not 403.
R-10 strip Server; role mail not founder. R-11 stay silent on PQ until CBOM.
Ledger: /trust. GodCode register is separate — do not merge.
Framework: MITRE ATT&CK for Enterprise. Technique IDs are reference anchors for architects; control language is CISO-readable.
Adversary matrix
Tactic · Technique · Control
Rows are how an adversary would attack the public property. Columns state what we enforce or design for.
T1595 Active ScanningT1592 Gather Victim Host InfoT1589 Gather Victim IdentityT1583 Acquire InfrastructureT1587 Develop CapabilitiesT1190 Exploit Public-Facing ApplicationT1566 PhishingT1133 External Remote ServicesT1059 Command and Scripting InterpreterT1203 Exploitation for Client Executionobject-src 'none'. Form action limited. No remote font CDNs on hardened pages where possible.T1505 Server Software ComponentT1037 Boot or Logon Init ScriptsT1068 Exploitation for Privilege EscalationT1548 Abuse Elevation Controlpublic_html. No world-writable code. Secrets out of web root. Residual: shared hosting is multi-tenant — VPS when isolation bar rises.T1027 Obfuscated FilesT1036 MasqueradingT1070 Indicator RemovalT1110 Brute ForceT1555 Credentials from Password StoresT1552 Unsecured CredentialsT1083 File and Directory DiscoveryT1046 Network Service Discovery/admin, /wp-*, backup trees, open indexes.T1021 Remote ServicesT1550 Use Alternate Authentication MaterialT1114 Email CollectionT1213 Data from Information RepositoriesT1071 Application Layer ProtocolT1102 Web ServiceT1041 Exfiltration Over C2 ChannelT1567 Exfiltration Over Web Service.sql / .env / dump patterns.T1485 Data DestructionT1491 DefacementT1498 Network Denial of ServiceTechnique IDs are illustrative of the tactic class, not an exhaustive ATT&CK coverage claim. Review cadence: on material site change and at least quarterly for CISO posture.
Lockdown baseline
Public surface controls
TLS · HSTS · apex
HTTPS forced. HSTS with includeSubDomains. www canonicalized to apex. No mixed-content third parties on public pages.
CSP · framing · COOP
Content-Security-Policy, X-Frame-Options DENY, COOP same-origin, nosniff, referrer and permissions policies. HTML no-store cache for deploys.
Minimal attack surface
Static HTML primary. Single POST endpoint for briefings. Block VCS, backups, CMS probes, and sensitive extensions at the edge.
Disclosure · residual risk
security.txt and Trust channel. Residual risk spoken: shared tenancy, mail transport, operator 2FA. Enclave stays off this host.