Every intrusion starts with a decision. See it being made.
Scanners, operators and AI agents all have to choose what to do once they believe they have found a real system. HIIH Surface gives them that system — credible, contained, operated by OHIIHO, separate from your production — and turns what they reveal into intelligence your SOC can act on.
What the Surfaces have already revealed.
The proposition comes from observed activity, not a roadmap. Three examples, each published as primary evidence.
A controlled appliance-profile exposure revealed repeated credential-validation behavior and “validate-and-leave” patterns.
A monitored workflow showed how agentic assistance changed an operator’s state and speed — not merely the quality of phishing text.
Controlled engagement exposed a ransomware-worm’s payload, timing and propagation sequence for defensive analysis.
- Published reports
- 17
- Detection files released
- 52
- Detection formats
- 4
- YARA · Sigma · Network IDS rules · IOC lists
Public record of OHIIHO Research, counted on 2026-09-26.
Why target-side evidence matters now.
Critical edge-device flaws arrive faster than anyone can patch.
Scanners, access buyers and AI agents hit the same edge — and mean very different things.
An alert says something happened. It rarely says what the adversary wanted.
Security teams know the adversary from two places. HIIH adds a third.
What providers and communities observed across their sources. Broad context — not produced from a Surface deployed for your mission.
What happens on the systems you operate. Direct relevance — but the adversary is already touching something that matters.
What hostile actors bring, test and do inside an environment designed for observation. First-party, without making production the experiment.
HIIH complements external intelligence and production telemetry; it replaces neither. Relevance depends on the Surface mission, exposure and placement — broad Internet activity is not automatically targeted activity.
From selected exposure to operational intelligence.
A HIIH Surface is the whole managed system around the engagement: selected exposure through Edge Sensors, early protocol signal from Contact Points, deeper operating-system engagement on Live Hosts, a synthetic operating context, outbound control and an evidence plane with the Surface Console — always separate from production. Observed activity is structured into Findings your team retrieves into the workflows it already runs. Not every deployment includes every interaction depth.

From raw activity to a structured HIIH Finding.
Every engagement is recorded as a timed sequence of what the adversary actually did. Material activity is then structured into a HIIH Finding: context, confidence, supporting material and an operational implication. An alert can be a projection of a Finding — not the end product.
- T+00:00 Ingress pushes a hidden, randomly named binary into a world-writable temp directory over SSHone SSH session per step; the filename changes with every drop, the hash does not
- T+00:05 Ingress launches it detached, output redirected to a hidden sibling logmark-executable, then a detached launch from a temp path: a pre-encryption detection seam
- T+00:07 Maneuver starts, then unlinks its own binary, log and lock filegone from disk within seconds, still held open by the running process
- T+01:13 Effects encrypts user files and appends a new extension241 files in about 15 seconds in one observed cycle
- T+ ··:·· Maneuver fans out SSH brute-force scanning from the same processconcurrent with encryption: by the time files change, the next targets are already being tried
- T+01:28 Effects completes the encryption passa zero-byte marker flags the host as already processed; its path, not its hash, is the indicator
Illustrative sequence based on published OHIIHO Research: Catching Sorry-worm in the wild [1/3] ↗. Composite and sanitized; timings from the published session record, untimed steps are ordered, not timed.
The same session, structured as a Finding:
- Observed activity
- Ransomware-worm execution on a controlled Live Host: staging, self-deletion, file encryption and SSH propagation
- Mission relevance
- Sector-relevant — qualified by exposure and placement
- Why it matters
- Shows a detection seam before encryption, and propagation to further hosts starting while files are still being encrypted
- Supporting material
- Session record, recovered files and their hashes, available to the analyst
- Suggested action
- Hunt for the published behavioral patterns: a detached launch from a temporary path, a binary that deletes itself, the already-processed marker
- Delivery
- Surface Console · MCP · API — pull-based
You pull Findings on your terms — through the Surface Console, MCP or the API. STIX 2.1 over TAXII 2.1 is available by engagement.


Deploy the same operating model for different intelligence and security missions.
For SOC, MDR and regulated enterprise. Controlled targets provide early interaction and context your SOC can retrieve.
For SOC L3, CTI, incident response and detection engineering. Live Hosts expose commands, tools, files and behavioral sequence in a controlled environment.
For MSSP, MDR, integrators and regional operators. Add adversary engagement, Findings and recurring intelligence outputs without asking every client to operate hostile infrastructure.
For banks, insurers, financial market infrastructure and regulated enterprise. Evaluate HIIH through deployment scope, separation from production, data handling and integration into existing controls.
Evaluating OHIIHO as a strategic technology or investment partner? Learn about the company →
Designed for hostile activity. Operated under control.
Adversaries interact with the HIIH Surface, not with the systems the organization must protect. HIIH is not necessarily inline and does not claim to intercept every attack before production.
OHIIHO operates the difficult exposure, routing, engagement and evidence layers so the customer or MSSP does not need to build a honeypot program.
Outbound activity is governed so the engagement environment is not unrestricted attacker infrastructure.
OHIIHO distinguishes what is delivered, qualified and future. Public claims stay within demonstrated capability.
For eligible government and national-security agencies, OHIIHO Sovereign Programs provide premium counterintelligence capabilities, discussed on request.
Intent is the new IOC.
Adversary Engagement Intelligence (AEI) — first-hand cyber threat intelligence generated through controlled engagement with real adversaries.
Indicators describe artifacts: an address, domain, hash or tool. Behavior reveals choices: what an actor tests, ignores, carries, validates and attempts next. HIIH preserves the behavioral evidence from which an analyst can assess intent.
An adversary that reasons through an agent externalizes its choices. Inside a credible target, those choices become observable — timing, enumeration, self-repair, what it reads and what it trusts.
Meet OHIIHO on stage.
Start with a Surface and a question worth answering.
HIIH Surface is available through Early Access, in controlled production evaluations with a small number of organizations.
Choose the exposure, engagement depth, evidence and delivery path appropriate to your organization. See how an evaluation works →