Trust · Adversarial model

Threat matrix

Public-surface threat model for c1bertitans.com — the ENGINE PATH origin, mapped to MITRE ATT&CK (enterprise). Adversary-first. Controls stated as policy — not theater.

Scope and residual risk

In scope: apex website, contact form, static assets, DNS/mail adjacency as they affect the public brand surface. Out of scope here: live enclave SOC, firewall admin, admission PEPs (enclave-only).

This matrix is a design and assurance artifact, not a FedRAMP package and not a claim that every control is perfect on shared hosting. Residual risk is spoken: shared-tenancy limits, mail-on-host, and operator discipline still matter.

Live-origin punch list (2026-09-09). R-01 cPanel/Webmail on brand DNS — DNS/cert burn (human). Apex paths 404. R-02 Let’s Encrypt SAN is an asset inventory — next cert apex+www only. R-03 Guest enrollment /guest-account /enroll/ — 404. R-04 Trailing-slash 500s — 301 to pretty URL. R-05 Public PHP mail handler — honeypot + rate limit; residual T1190 until serverless/mailto. R-06 /board-brief — 404 (no longer fetchable). R-07 X-Fringe-WAF stripped. R-08 header-only CSP. R-09 probe paths 404 not 403. R-10 strip Server; role mail not founder. R-11 stay silent on PQ until CBOM. Ledger: /trust. GodCode register is separate — do not merge.

Framework: MITRE ATT&CK for Enterprise. Technique IDs are reference anchors for architects; control language is CISO-readable.

Adversary matrix

Tactic · Technique · Control

Rows are how an adversary would attack the public property. Columns state what we enforce or design for.

Tactic
Techniques (examples)
Adversarial story
Controls (CTO / CISO)
Reconnaissance
T1595 Active Scanning
T1592 Gather Victim Host Info
T1589 Gather Victim Identity
Map the site, discover backup paths, scrape emails and tech stack from headers and noise files.
Directory listing off. Sensitive extensions and VCS paths denied. Minimal server disclosure. Samples disallowed from crawlers. No admin chrome on apex.
Resource Development
T1583 Acquire Infrastructure
T1587 Develop Capabilities
Clone brand pages, register lookalike domains, prep phishing kits against “briefing” language.
Canonical apex + HSTS. Clear brand FQDNs. Security contact published. Users trained via Trust copy: briefings only via official forms/mail.
Initial Access
T1190 Exploit Public-Facing Application
T1566 Phishing
T1133 External Remote Services
Exploit form/PHP handlers; phish staff; hunt for exposed remote admin on the brand domain.
Static-first surface. POST-only form with honeypot, session rate limit, origin check, header-injection hardening. No public SOC/login. Enclave management never on HostGator.
Execution
T1059 Command and Scripting Interpreter
T1203 Exploitation for Client Execution
Inject script into pages or force browser code paths via XSS / hostile third parties.
CSP (self + controlled inline). No third-party analytics scripts. object-src 'none'. Form action limited. No remote font CDNs on hardened pages where possible.
Persistence
T1505 Server Software Component
T1037 Boot or Logon Init Scripts
Web shell, planted PHP, or backdoored include after credential/FTP compromise.
Minimal PHP surface (single mail handler). Deny common webshell path patterns. Least-privilege cPanel. Key-based SSH to host. Change discipline for deploys.
Privilege Escalation
T1068 Exploitation for Privilege Escalation
T1548 Abuse Elevation Control
Shared-host breakout or mis-set file permissions to read other tenants / secrets.
Correct ownership on public_html. No world-writable code. Secrets out of web root. Residual: shared hosting is multi-tenant — VPS when isolation bar rises.
Defense Evasion
T1027 Obfuscated Files
T1036 Masquerading
T1070 Indicator Removal
Hide payloads as images/assets; spoof static filenames; clear logs.
Strict content types. Block backup/sql/env patterns. Log access via host (limited on shared). Integrity of deploy tree via controlled publish path.
Credential Access
T1110 Brute Force
T1555 Credentials from Password Stores
T1552 Unsecured Credentials
Spray cPanel/mail; scrape leaked keys; harvest form-submitted addresses for secondary attacks.
Strong unique passwords + host 2FA recommended. No secrets in repo/web. Form does not echo secrets. Mail headers sanitized. Prefer key auth for SSH.
Discovery
T1083 File and Directory Discovery
T1046 Network Service Discovery
Probe for /admin, /wp-*, backup trees, open indexes.
Indexes off. CMS paths return forbidden/not found. No public directory trees. Samples not in sitemap; robots disallow.
Lateral Movement
T1021 Remote Services
T1550 Use Alternate Authentication Material
From web host toward mail, DNS, or corporate systems using stolen sessions or reused keys.
Separation of duties: this origin ≠ enclave. Distinct credentials. No enclave keys on the public site. Mail treated as separate risk domain.
Collection
T1114 Email Collection
T1213 Data from Information Repositories
Harvest briefing mailboxes; scrape public pages for org intel and architecture hints.
Public copy avoids wire IPs, PSKs, and live topology. Enclave detail stays private. Disclosure channel defined.
Command and Control
T1071 Application Layer Protocol
T1102 Web Service
Use compromised site as C2 beacon host or exfil drop.
No open redirectors. No arbitrary upload. CSP and framing controls. Monitor for unexpected files via change control.
Exfiltration
T1041 Exfiltration Over C2 Channel
T1567 Exfiltration Over Web Service
Pull backup dumps, customer form data, or config from web root.
No customer DB on apex. Form is mail-only, rate-limited. Backups outside web root. Deny .sql / .env / dump patterns.
Impact
T1485 Data Destruction
T1491 Defacement
T1498 Network Denial of Service
Deface brand, wipe content, or flood origin to damage trust.
Versioned local source of truth. Controlled deploy. HSTS/HTTPS. Host-level DDoS residual on shared; escalate hosting when availability bar requires it.

Technique IDs are illustrative of the tactic class, not an exhaustive ATT&CK coverage claim. Review cadence: on material site change and at least quarterly for CISO posture.

Lockdown baseline

Public surface controls

TRANSPORT

TLS · HSTS · apex

HTTPS forced. HSTS with includeSubDomains. www canonicalized to apex. No mixed-content third parties on public pages.

BROWSER

CSP · framing · COOP

Content-Security-Policy, X-Frame-Options DENY, COOP same-origin, nosniff, referrer and permissions policies. HTML no-store cache for deploys.

SURFACE

Minimal attack surface

Static HTML primary. Single POST endpoint for briefings. Block VCS, backups, CMS probes, and sensitive extensions at the edge.

GOVERNANCE

Disclosure · residual risk

security.txt and Trust channel. Residual risk spoken: shared tenancy, mail transport, operator 2FA. Enclave stays off this host.