Evidence

What the Surfaces have already revealed.

OHIIHO Research is the editorial research function of the same organization. Its credibility comes from primary observation, explicit evidence classes and restraint. Below is a selection, grouped by the behavior each engagement was built to observe.

01 · ACCESS VALIDATION & EDGE PRESSURE

What actors bring and test before they commit.

Before an actor invests in an intrusion, it tests what it already has — credentials, an exposed appliance profile, the shape of a service. Seen target-side, that validation behavior is an early, low-cost indicator that separates deliberate access-seeking from background scanning.

Finding family: Access
Edge exploit pressure
Observed — exploitation pressure against an exposed appliance profile, captured from the target side. Supporting material — request patterns, tooling and the sequence of what was attempted. Outcome — the controls that interrupted the activity, plus shareable detection content.
FortiBleed from the Target Side: What Stops Them · 2026-06 Read the research →
Finding family: Access
Access validation
Observed — residential-sourced credential-validation activity, probing SSH across multiple regions, captured target-side. Supporting material — authentication sequences, client characteristics, timing and infrastructure patterns. Outcome — indicators and detection context for credential-validation behavior distinct from broad scanning.
Residential Broadband Botnet Uses AsyncSSH to Validate Credentials Across Four Regions · 2026-06 Read the research →
02 · AI-ENABLED & AGENTIC TRADECRAFT

Machine-speed operators, observed at work.

AI-enabled tooling compresses the work of an intrusion — reconnaissance, decision-making and follow-through move at machine speed. The tell is the operating pattern rather than any single artifact, and controlled engagement is where that pattern becomes legible instead of blurring into ordinary traffic.

Finding family: Engagement
Operator workflow augmentation
Observed — AI-enabled tooling used to assemble and run an intrusion-support workflow, seen inside a controlled environment. Supporting material — session activity, generated artifacts and operating patterns. Outcome — analysis of how AI-assisted tooling reshapes an intrusion, with defensive framing.
The AI Did Not Write the Phish. It Built the Business. · 2026-06 Read the research →
Finding family: Engagement
Detection with deception
Covered — how controlled engagement environments surface AI-enabled intrusion behavior that production telemetry alone tends to miss. Supporting material — behavioral signatures and the deception patterns that expose them. Outcome — a defender’s approach to detecting and countering AI-enabled activity.
Detecting and Countering AI-Enabled Intrusions with Deception · 2026-04 Read the research →
03 · POST-ACCESS BEHAVIOR

What an actor does once inside a controlled target.

The most useful knowledge appears only after an actor believes it has succeeded — the commands it runs, the tools it brings, the order in which it moves. On a real network that behavior would mean a live compromise; on a controlled target it becomes detection and hunting material instead.

Finding family: Engagement
Ransomware-worm behavior
Observed — a Go ransomware-worm executing inside a controlled target. Supporting material — session records, files and tooling recovered during the engagement. Outcome — behavioral analysis plus detection and hunting content.
Inside Sorry-worm: anatomy of a Go ransomware-worm hybrid · 2026-05 Read the research →
Finding family: Engagement
Host triage before payload
Observed — an SSH botnet triaging hosts to decide their value before deploying a payload, captured in controlled interaction. Supporting material — the triage logic, commands and decision points observed in-session. Outcome — insight into how automated actors prioritize targets, with detection context.
Before It Mines You, It Checks Whether You're Worth More · 2026-06 Read the research →
04 · BOTNET ECOSYSTEMS & CROSS-PLATFORM ACTIVITY

How campaigns compete, reuse infrastructure and move between systems.

Automated campaigns are not isolated events — they contest the same hosts, reuse infrastructure and pivot between operating systems. Observed across many engagements over time, those overlaps become clustering signals that link activity a single alert would treat as unrelated.

Finding family: Engagement
Contested infrastructure
Observed — competing botnets contesting the same compromised hosts, captured target-side. Supporting material — eviction behavior, tooling and the sequence of competing activity. Outcome — a picture of how automated campaigns fight for the same ground, with clustering signals.
Turf Wars at Scale: Botnets Fighting for the Same Servers · 2026-05 Read the research →
Finding family: Engagement
Cross-platform pivots
Observed — the same command infrastructure operating across operating systems, observed months apart. Supporting material — shared indicators and the pivot primitives carried between platforms. Outcome — a strong clustering signal linking activity across systems.
Two-Way Prometei: When the Linux Botnet Pivots Back to Windows · 2026-05 Read the research →

The claims that matter trace to primary observation.

A public corpus — session material, indicators, detection and hunting content — is published by OHIIHO Research.