🔄 Topic

Building discoverability while keeping public information intentional.


🎯 Goal

Understand how SEO metadata, sitemap generation, and structured data support a real business website.


🛠 What I Did

I reviewed the SEO side of the Farina website: page-specific metadata, Open Graph structure, JSON-LD structured data, sitemap generation, canonical URLs, and robots behavior. For a local business, discoverability matters. People need to find products, firewood services, contact details, and location-related information. The security angle is that public metadata should be intentional. Search engines and attackers both read what the site exposes.

Main areas covered:

  • page titles
  • meta descriptions
  • Open Graph metadata
  • JSON-LD structured data
  • sitemap generation
  • canonical URLs

🔗 Key Cybersecurity Connections

This matters because public metadata becomes reconnaissance material. SEO helps customers, but exposed structure, contact details, technologies, and routes can also help scanners and attackers map the site.


🔍 Investigation Questions

  • What information is intentionally public?
  • Does metadata expose anything unnecessary?
  • Are canonical URLs correct?
  • Does the sitemap include only intended pages?
  • Could stale pages remain discoverable?

🚨 Detection Opportunities

Potential monitoring ideas:

  • unexpected sitemap changes
  • new indexed route
  • metadata changed outside normal workflow
  • robots directives modified
  • public exposure of staging URLs

Example:

project=farina-farm-website
change_type=public_website_update
risk_area=repository_deployment_or_public_input
triage=review_change_intent_and_validate_build

🧭 MITRE ATT&CK Techniques

Possible mappings depending on confirmed behavior:

  • T1592 — Gather Victim Host Information
  • T1595 — Active Scanning
  • T1190 — Exploit Public-Facing Application

🗺 Visual Investigation Diagram

Business content
    ↓ Metadata
    ↓ Sitemap
    ↓ Search engine visibility
    ↓ Public reconnaissance surface

⚠ Challenges

The challenge was seeing SEO as both useful and security-relevant. Visibility is good only when the exposed information is intentional.


📚 What I Learned

I learned that SEO is controlled exposure. The goal is to help customers and search engines without accidentally exposing internal or stale material.


➡ Next Steps

  • Review sitemap output
  • Check canonical URLs
  • Keep metadata accurate
  • Avoid exposing staging or internal URLs

🧠 Reflection

This was useful because it turned a real project into security-aware learning without pretending that every task was a pure cybersecurity lab.


🧩 Lessons Learned

What worked

Connecting SEO to public exposure.

What broke

Thinking of SEO as unrelated to security.

Why it broke

Anything public can be used for reconnaissance.

Fix / takeaway

Make public metadata intentional and reviewable.


📈 Skill Progression Context

This supports cybersecurity progression because reconnaissance is a real attacker phase, and defenders need to understand what their own systems reveal publicly.


😄 TL;DR

SEO is visibility; visibility must be intentional.