Evidence, facts and priorities

01 · PRIMARY OBSERVATION AS EVIDENCE

A public record of observed activity.

Cybersecurity claims should be testable. OHIIHO Research publishes analysis derived from activity observed inside controlled environments: operator behavior, malware, tools, infrastructure, detection content and defensive implications.

The Research corpus does not replace technical or commercial product diligence. It is public evidence that OHIIHO’s observation environments generate primary material that can be turned into defensible intelligence.

Finding family: Access
Exploit pressure & defensive response
Observed — exploitation attempts against an exposed appliance profile, captured from the target side. Supporting material — request patterns, payloads, tooling and the sequence of attempted activity. Outcome — analysis of the controls that interrupted the activity, together with reusable detection content.
FortiBleed from the Target Side: What Stops Them · 2026-06 Read the research →
Finding family: Engagement
Operator workflow augmentation
Observed — AI-enabled tooling used to assemble and operate an intrusion-support workflow inside a controlled environment. Supporting material — session activity, generated artifacts, tool usage and operating sequence. Outcome — analysis of how AI-assisted tooling changes the composition, speed and observable characteristics of an operator workflow.
The AI Did Not Write the Phish. It Built the Business. · 2026-06 Read the research →
Finding family: Engagement
Post-access malware behavior
Observed — a Go ransomware-worm executing across multiple stages inside a controlled target. Supporting material — session records, recovered files, execution traces and associated tooling. Outcome — behavioral analysis, detection logic and hunting guidance derived from the observed execution.
Inside Sorry-worm: anatomy of a Go ransomware-worm hybrid · 2026-05 Read the research →
Finding family: Access
Access validation & edge pressure
Observed — credential-validation activity and SSH probing sourced through residential networks across multiple regions, captured from the target side. Supporting material — authentication sequences, client characteristics, timing, source patterns and infrastructure relationships. Outcome — indicators and detection context that distinguish credential-validation behavior from broad, non-interactive scanning.
Residential Broadband Botnet Uses AsyncSSH to Validate Credentials Across Four Regions · 2026-06 Read the research →

OHIIHO Research is the public research function of OHIIHO, separate from commercial product messaging. Explore evidence from OHIIHO Research ↗

02 · PARTNER OPERATING MODEL

Specialized operation without displacing the customer relationship.

OHIIHO works with MSSPs, MDR providers, integrators, enterprise security teams, CERTs and selected public-sector organizations.

Partners can retain the customer relationship and their broader service responsibilities while OHIIHO operates the specialized HIIH layer under defined technical, commercial, authority and data-handling boundaries.

Explore the partner model

03 · COMPANY FACTS AND LEGAL ENTITIES

Core information for procurement and diligence.

Detail
Legal entitiesOHIIHO Pte. Ltd. (Singapore) · OHIIHO OÜ (Tallinn, Estonia)
HeadquartersSingapore
Primary commercial entityOHIIHO Pte. Ltd., Singapore
Research publicationOHIIHO Research — research.ohiiho.com
Contact routehello@ohiiho.com

Registration numbers, registered offices and jurisdictional roles are published on /legal/; controller roles are restated in /privacy/. Incorporation, ownership and IP-assignment documents are available under NDA during formal diligence.

04 · CURRENT OPERATING PRIORITIES

From operating capability to repeatable delivery.

OHIIHO has operating technology, a growing corpus of primary research and active customer and partner development. The current stage is focused on making deployment, delivery and governance repeatable across customers and partners.

Current priorities include:

  • repeatable managed deployment;
  • partner enablement and explicit service boundaries;
  • customer and data governance;
  • regional commercial and partner distribution;
  • technical diligence and procurement support;
  • operational scale;
  • traceability between product behavior, Research evidence and public claims.