Adversary Engagement Intelligence
Real adversaries engage credible targets that OHIIHO controls at the edge of an organization’s exposure, once they have decided the target is real, and away from production. What humans, scripts and AI agents test, carry, choose and reveal there is recorded first-hand and turned into evidence a security team can act on.
Adversary Engagement Intelligence (AEI) — first-hand cyber threat intelligence generated through controlled engagement with real adversaries.
How the intelligence is made.
Intent is the new IOC.
Indicators describe what was seen somewhere else, and they age quickly. What an adversary tests, carries and chooses on a system it believes is real is evidence of what it wants. Adversary Engagement Intelligence preserves that behavioral evidence so an analyst can assess intent and act on it.
Observations come from controlled HIIH Surfaces operated by OHIIHO. The public evidence is published by OHIIHO Research.
Defined by OHIIHO, September 2026.
How AEI relates to what you already use.
Each approach produces something different, and each remains useful. Honeypots are part of the technical lineage.
| Approach | What it does | What you get |
|---|---|---|
| Honeypot | captures interactions with a decoy system | logs and samples |
| Deception | detects or misdirects an adversary inside your environment | alerts |
| Threat intelligence | analyzes information about threats collected elsewhere | reports and indicators |
| Adversary Engagement Intelligence | engages real adversaries on credible, controlled targets | first-hand intelligence on what they test, carry, choose and reveal |
The term adversary engagement comes from MITRE Engage ↗. Adversary Engagement Intelligence names the intelligence that adversary engagement produces.