OHIIHO Between them and you.
HIIH Surface

Every intrusion starts with a decision. See it being made.

Scanners, operators and AI agents all have to choose what to do once they believe they have found a real system. HIIH Surface gives them that system — credible, contained, operated by OHIIHO, separate from your production — and turns what they reveal into intelligence your SOC can act on.

How HIIH works →

01 · OBSERVED IN PRACTICE

What the Surfaces have already revealed.

The proposition comes from observed activity, not a roadmap. Three examples, each published as primary evidence.

Finding family: Access
Access validation, target-side

A controlled appliance-profile exposure revealed repeated credential-validation behavior and “validate-and-leave” patterns.

Read the evidence
Finding family: Engagement
Agentic tradecraft

A monitored workflow showed how agentic assistance changed an operator’s state and speed — not merely the quality of phishing text.

Read the evidence
Finding family: Engagement
Post-access malware behavior

Controlled engagement exposed a ransomware-worm’s payload, timing and propagation sequence for defensive analysis.

Read the evidence
Published reports
17
Detection files released
52
Detection formats
4
YARA · Sigma · Network IDS rules · IOC lists

Public record of OHIIHO Research, counted on 2026-09-26.

Explore the evidence →

02 · WHY NOW

Why target-side evidence matters now.

Exposure outruns patching.

Critical edge-device flaws arrive faster than anyone can patch.

The adversary is no longer only human.

Scanners, access buyers and AI agents hit the same edge — and mean very different things.

Detection tells half the story.

An alert says something happened. It rarely says what the adversary wanted.

03 · THE THIRD SOURCE

Security teams know the adversary from two places. HIIH adds a third.

External threat intelligence

What providers and communities observed across their sources. Broad context — not produced from a Surface deployed for your mission.

Production telemetry

What happens on the systems you operate. Direct relevance — but the adversary is already touching something that matters.

Controlled target-side observation

What hostile actors bring, test and do inside an environment designed for observation. First-party, without making production the experiment.

HIIH complements external intelligence and production telemetry; it replaces neither. Relevance depends on the Surface mission, exposure and placement — broad Internet activity is not automatically targeted activity.

See where HIIH fits →

04 · THE SURFACE

From selected exposure to operational intelligence.

A HIIH Surface is the whole managed system around the engagement: selected exposure through Edge Sensors, early protocol signal from Contact Points, deeper operating-system engagement on Live Hosts, a synthetic operating context, outbound control and an evidence plane with the Surface Console — always separate from production. Observed activity is structured into Findings your team retrieves into the workflows it already runs. Not every deployment includes every interaction depth.

Surface Console — overview tiles: engagement touches and proven evidence over 24 hours, evidence streams
Surface Console · Overview, last 24 h (cropped)

Explore the HIIH Surface →

05 · WHAT YOU RECEIVE

From raw activity to a structured HIIH Finding.

Every engagement is recorded as a timed sequence of what the adversary actually did. Material activity is then structured into a HIIH Finding: context, confidence, supporting material and an operational implication. An alert can be a projection of a Finding — not the end product.

What the Surface records
Action stream Illustrative sequence
  1. T+00:00 Ingress pushes a hidden, randomly named binary into a world-writable temp directory over SSHone SSH session per step; the filename changes with every drop, the hash does not
  2. T+00:05 Ingress launches it detached, output redirected to a hidden sibling logmark-executable, then a detached launch from a temp path: a pre-encryption detection seam
  3. T+00:07 Maneuver starts, then unlinks its own binary, log and lock filegone from disk within seconds, still held open by the running process
  4. T+01:13 Effects encrypts user files and appends a new extension241 files in about 15 seconds in one observed cycle
  5. T+ ··:·· Maneuver fans out SSH brute-force scanning from the same processconcurrent with encryption: by the time files change, the next targets are already being tried
  6. T+01:28 Effects completes the encryption passa zero-byte marker flags the host as already processed; its path, not its hash, is the indicator

Illustrative sequence based on published OHIIHO Research: Catching Sorry-worm in the wild [1/3] ↗. Composite and sanitized; timings from the published session record, untimed steps are ordered, not timed.

What your team retrieves

The same session, structured as a Finding:

HIIH-F-2026-0042Finding family: Engagement Illustrative example
Confidence High
Observed activity
Ransomware-worm execution on a controlled Live Host: staging, self-deletion, file encryption and SSH propagation
Mission relevance
Sector-relevant — qualified by exposure and placement
Why it matters
Shows a detection seam before encryption, and propagation to further hosts starting while files are still being encrypted
Supporting material
Session record, recovered files and their hashes, available to the analyst
Suggested action
Hunt for the published behavioral patterns: a detached launch from a temporary path, a binary that deletes itself, the already-processed marker
Delivery
Surface Console · MCP · API — pull-based

You pull Findings on your terms — through the Surface Console, MCP or the API. STIX 2.1 over TAXII 2.1 is available by engagement.

Surface Console — priority case: a tracked adversary cluster and the next cases in the queue
Surface Console · Priority case
Surface Console — engagement level ladder from Quiet to Disrupt, showing the deepest stage reached today
Surface Console · Engagement level, today (UTC)

Explore HIIH Findings →

06 · CHOOSE THE OPERATIONAL PATH

Deploy the same operating model for different intelligence and security missions.

I need earlier, higher-confidence signal

For SOC, MDR and regulated enterprise. Controlled targets provide early interaction and context your SOC can retrieve.

SOC outcomes & workflows
I need to observe behavior after access — without using production

For SOC L3, CTI, incident response and detection engineering. Live Hosts expose commands, tools, files and behavioral sequence in a controlled environment.

Post-access observation
I want to offer this as a managed service

For MSSP, MDR, integrators and regional operators. Add adversary engagement, Findings and recurring intelligence outputs without asking every client to operate hostile infrastructure.

MSSP & MDR partners
I operate in a regulated or financial environment

For banks, insurers, financial market infrastructure and regulated enterprise. Evaluate HIIH through deployment scope, separation from production, data handling and integration into existing controls.

Financial services

Evaluating OHIIHO as a strategic technology or investment partner? Learn about the company →

07 · MANAGED DEPLOYMENT, SAFETY & TRUST

Designed for hostile activity. Operated under control.

Separate from production

Adversaries interact with the HIIH Surface, not with the systems the organization must protect. HIIH is not necessarily inline and does not claim to intercept every attack before production.

Managed engagement environment

OHIIHO operates the difficult exposure, routing, engagement and evidence layers so the customer or MSSP does not need to build a honeypot program.

Infrastructure-level outbound control

Outbound activity is governed so the engagement environment is not unrestricted attacker infrastructure.

Honest capability boundaries

OHIIHO distinguishes what is delivered, qualified and future. Public claims stay within demonstrated capability.

For eligible government and national-security agencies, OHIIHO Sovereign Programs provide premium counterintelligence capabilities, discussed on request.

Explore Trust & technical truth →

08 · ADVERSARY ENGAGEMENT INTELLIGENCE

Intent is the new IOC.

Definition

Adversary Engagement Intelligence (AEI) — first-hand cyber threat intelligence generated through controlled engagement with real adversaries.

Why intent

Indicators describe artifacts: an address, domain, hash or tool. Behavior reveals choices: what an actor tests, ignores, carries, validates and attempts next. HIIH preserves the behavioral evidence from which an analyst can assess intent.

AI adversaries
AI agents reveal more, not less.

An adversary that reasons through an agent externalizes its choices. Inside a credible target, those choices become observable — timing, enumeration, self-repair, what it reads and what it trusts.

Read the research →

Read the definition →

09 · TALKS

Meet OHIIHO on stage.

NanoSec · Parallel Pulse 2026

Kuala Lumpur · September 28, 2026. Keynote by Laurent Oudot, founder of OHIIHO.

Agenda ↗
GovWare 2026

Singapore · October 13, 2026. Tech talk: Counter-Intelligence Against Agentic AI Attackers.

Session ↗

Start with a Surface and a question worth answering.

HIIH Surface is available through Early Access, in controlled production evaluations with a small number of organizations.

Choose the exposure, engagement depth, evidence and delivery path appropriate to your organization. See how an evaluation works →