From hostile activity to structured Findings.
A HIIH Finding organizes directly observed adversary activity into context, confidence, related observations or artifacts, and an operational implication your teams can act on. It is more than a touch alert.
The output model is grounded in real hostile activity captured target-side, not in a template. Three examples, each drawn from a published report.
A sensor record is not yet intelligence.
A connection, command or file transfer is a fact. It becomes operationally useful when the fact is normalized, related to other activity, placed in context, and qualified with what is known, assessed and still uncertain. HIIH uses a structured output model so the SOC receives more than an isolated touch notification.
Not every Observation becomes a Finding. Activity stays raw or observational until it deserves an assessment.
| Layer | What it is |
|---|---|
| Raw Event | A low-level record generated by a target or sensor. Necessary, but not the main customer value. |
| Observation | A normalized fact from the Surface: an authentication attempt, command, file transfer, connection, fingerprint or other directly recorded behavior. |
| HIIH Finding | A structured interpretation of observed adversary activity, carrying context, confidence, related observations or artifacts, and an operational implication. |
| Alert | A concise operational representation used to draw attention in a SOC workflow. |
| Intelligence | The usable result: Findings, campaign or actor context, detection material, briefings and related analytical outputs. |
The Finding object is described in three short chapters. Read them in order, or jump to what you need.
Bring one intelligence question. Inspect the Finding it can produce.
An evaluation can start with a specific operational question, the relevant exposure or engagement pattern, the observations HIIH can collect, and the form in which your team needs the result.