Separation, exposure and outbound

01 · SEPARATION FROM PRODUCTION

Hostile execution happens on HIIH targets, not your production endpoints.

HIIH is designed so adversaries interact with HIIH engagement targets, not the customer’s production endpoints.

  • Selected exposure may be directed through DNS, public edge placement or an approved local edge component.
  • Hostile sessions are routed into the HIIH engagement environment.
  • Contact Points and Live Hosts are HIIH targets, not customer systems.
  • Production systems are not used as sacrificial evidence sources.
  • HIIH does not replace endpoint, network or perimeter controls.
Adversary trafficinbound
→
Selected exposureDNS · edge · approved component
→
HIIH engagement environmentContact Points · Live Hosts
→
Observations / Findingsto SOC · CTI

Production assets remain outside the hostile execution path.

Separation is not diversion. HIIH does not claim to pull all hostile traffic away from production, to sit inline in front of every asset, to guarantee observation before a real incident, to mirror the entire attack surface, or to air-gap the Surface. It adds a controlled adversary-facing source alongside your existing controls.

What a Surface contains · How HIIH works

02 · CONTROLLED EXPOSURE AND ENGAGEMENT

“Designed to be attacked” is a deliberate operating model, not uncontrolled exposure.

A HIIH Surface exposes only the services, identities and targets defined for the engagement. The placement, interaction depth and observation scope are selected deliberately. Early protocol-level contact and deeper post-access behavior are handled by different target classes inside the same managed system.

What is exposedWhat the adversary can doWhat OHIIHO observes
selected services, identities and targets defined for the engagementinteract with a protocol-aware Contact Point or a real operating-system Live Hostauthentication material, protocol behavior, commands, tooling and post-access activity

Publicly nameable components:

HIIH loop step: Surface
Contact Point — early protocol-level signal and interaction.
HIIH loop step: Surface
Live Host — deeper post-access behavior on a real operating system.
HIIH loop step: Surface
Edge Sensor — selected public exposure and routing.
HIIH loop step: Surface
Engagement Gateway — controlled internal routing.
HIIH loop step: Observe
Evidence Plane — observation and artifact preservation.
Placement, routing and low-level configuration are deployment-specific and covered during diligence, not on the public page. Each target class links back to what a Surface contains.
03 · OUTBOUND CONTROL AND SAFE OPERATING BOUNDARIES

A compromised engagement target should not become infrastructure for attacking others.

Outbound activity from HIIH targets is governed by infrastructure-level controls and deployment policy. The default commercial posture should not provide unrestricted Internet access from an engagement target.

Direct unrestricted egressdenied by policy
Approved observation pathdeployment-specific
Customer production pathnot provided

Deployment-specific. Any exception belongs to a defined engagement policy.

  • Outbound access is not left to an adversary-controlled local process on the target.

  • The engagement environment does not rely only on a setting inside the target.

  • Observation or permitted outbound behavior, where enabled, is mission-specific.

  • The customer’s production network is not an outbound path.