Finding family: AccessFinding family: ExposureFinding family: Engagement

Anatomy of a Finding

01 · WHAT A HIIH FINDING IS

A stable object for adversary activity.

Instead of asking analysts to reconstruct meaning from disconnected logs, HIIH represents material activity as a structured Finding. The Finding records what was observed, what is assessed, how confident that assessment is, why it matters to the mission, what supporting material is related, and what action may follow.

The block below shows a public explanatory model of a Finding — not a verbatim dump of the internal schema.

finding_id: HIIH-F-2026-0017
family: access | exposure | engagement
summary: concise operational statement
observed:
  - directly recorded fact
assessed:
  - interpretation, explicitly labeled
confidence: low | medium | high
relevance: internet-wide | sector-relevant | profile-specific | ...
supporting_material:
  - observations
  - sessions
  - artifacts
recommended_action:
  - operational next step
status: new | reviewed | closed

The same structured object lets a SOC analyst triage with context, a CTI analyst relate behavior to a campaign, a detection engineer derive searches, an MSSP explain the event to its client, and an executive receive a concise briefing grounded in the same activity. HIIH does not claim that all of those representations are automatically generated today.

02 · ANATOMY OF A FINDING

What the analyst needs to know — and what the system does not claim to know.

HIIH FindingFinding family: Access Illustrative example
Confidence Medium
Observed activity
A recurring client fingerprint attempted a previously observed credential set against the selected profile, then ended the session without post-authentication activity
Mission relevance
Sector-relevant
Why it matters
Behavior is consistent with access validation rather than interactive exploitation
Supporting material
24 authentication attempts over 18 minutes · repeated client characteristics from three source addresses · fixed credential order
Suggested action
Review exposed credentials and tune identity and edge monitoring for the observed pattern
Delivery
Surface Console · MCP · API — pull-based

A Finding is built from seven regions the analyst can inspect.

RegionContents
IdentityFinding ID, creation time, Surface / mission reference, current review status — a stable reference across the Surface Console and pull paths.
SummaryA one- or two-sentence operational statement. Never “malicious actor detected”; always what was observed and what it means.
Observed factsOnly directly recorded statements: attempt counts, recurring characteristics, reused credentials, transferred binaries, attempted tunnels.
AssessmentExplicit interpretation, labeled as such: consistent with access validation, one toolchain behind several origins, persistence preparation.
ConfidenceHigh, Medium or Low — the strength of support for the assessment, not severity.
RelevanceA mission-relative statement, from Internet-wide to confirmed-targeted or internal post-compromise signal.
Supporting material & actionRelated observations, session or replay, artifacts and hashes, network context, related Findings, and a recommended next step.
Supporting material can be opened alongside the Finding, so an analyst inspects the underlying activity rather than accepting a black-box conclusion. HIIH does not use “verify proof” language for this material — see supporting evidence below.
03 · THREE PUBLIC FINDING FAMILIES

Different depths of engagement produce different classes of knowledge.

Finding family: Access
Access Findings

Findings about authentication material, credentials, keys, tokens or access-validation behavior presented to the Surface.

Value — identify active credential testing, separate broad automation from repeated validation, enrich identity and response workflows.

Finding family: Exposure
Exposure Findings

Findings about the services, protocol behaviors, exploit attempts, payloads or access paths tested against the selected Surface exposure.

Value — understand pressure on selected edge technologies, prioritize hardening, identify recurring campaigns and tooling.

Finding family: Engagement
Engagement Findings

Findings about post-access activity on a controlled Live Host: commands, files, tools, persistence, pivot attempts and related behavior.

Value — understand operator workflow, obtain artifacts before they touch production, derive detection and hunting material.

Relevance is always qualified. A credential on a Surface does not automatically belong to the customer, prove valid or prove targeting; exposure activity may reflect Internet-wide scanning, regional campaigns or mission-specific interest; and post-access observation describes behavior inside the controlled environment, not the actor’s full campaign.
04 · OBSERVED, ASSESSED AND UNKNOWN

Facts remain facts. Assessment remains assessment.

HIIH makes uncertainty inspectable rather than hiding it. A Finding is more credible when it states what the Surface directly recorded, what the analyst or system assesses, how confident that assessment is, and what remains unknown.

ObservedAssessedNot established
Same client characteristics in four sessionsActivity likely used one repeatable toolchainNamed actor identity
Credential set reused in a fixed orderBehavior consistent with access validationCredential validity against production
Binary transferred and executedTooling appears intended for persistenceFull campaign objective
Internal non-public target contactedUnauthorized presence is highly likelyInitial compromise path

This distinction answers the questions that matter: Is this just Internet noise? How do you know it was targeted? Are you attributing an actor? Is this evidence or analysis? Observations and assessment are never mixed in a single list.

05 · CONFIDENCE AND MISSION RELEVANCE

The same activity can mean different things in different deployments.

Confidence describes support for the assessment — not severity, and not the probability of future compromise. Relevance describes why the activity matters to the deployment. The two are kept separate, and both are separate again from severity.

ConfidenceMeaning
HighAssessment closely supported by direct observations.
MediumPlausible interpretation with material support and remaining ambiguity.
LowEarly hypothesis requiring additional observation.
RelevanceMeaning
Internet-wideBroad activity with little mission specificity.
RegionalActivity concentrated in a selected geography.
Sector-relevantTechnology, credential or behavior relevant to the sector.
Profile-specificActivity aligned with the Surface persona or exposure profile.
Customer-directedEvidence links the activity to the organization or mission.
Confirmed-targetedDirect evidence supports deliberate targeting.
Internal post-compromise signalInteraction with a non-public target where no legitimate contact is expected.
This relevance ladder is an explanatory doctrine and is shown on selected examples. It is not a public scoring promise. Severity (potential operational consequence), confidence (support for the assessment) and relevance (relationship to the mission) are three distinct dimensions and are never collapsed into a single “threat score.”
06 · SUPPORTING EVIDENCE

Open the material behind the Finding.

Supporting evidence is the operational material linked to a Finding: related observations, session records, commands, authentication activity, files, hashes, fingerprints, network context or other artifacts available for that engagement.

Session material
Chronological session record, terminal replay where available, commands and timing, interaction depth.
Authentication & client
Credentials presented to the Surface, outcome within the controlled target, client or handshake characteristics, recurrence across observations.
Artifacts
Transferred files, cryptographic hashes as analytical identifiers, extracted tooling. A hash identifies the artifact; it is not a package-integrity seal.
Network context
Connections and destinations, protocol metadata, perimeter or post-access activity, related network observations.
Analytical context
Related Findings, recurring profiles, technique context where supported, Research or detection material derived from the activity.
Technical truth
Supporting material, not sealed proof
Current public claim: Findings can be linked to supporting operational material. HIIH does not currently claim that every evidence package is signed, tamper-evident or independently verifiable.
Downstream representation
How a Finding shows up as an enriched alert is on the Delivery page
HIIH does not ask the SOC to stop using alerts — it gives an alert a richer source. On each pull path, the retrieved object preserves the Finding identity and routes the analyst back to the related context and supporting material. The exact retrieved representation, and the paths that carry it, are on the Delivery page.