HIIH loop step: Observe

From observation to delivery

01 · STAGE 4 — OBSERVE & PRESERVE RELATED MATERIAL

The Surface records what happened, not merely that something was touched.

Sensors produce low-level events. HIIH normalizes relevant activity into observations associated with the Surface, target and engagement context. Availability depends on target type and deployment.

Observation classWhat it captures, where available
Authentication & protocolcredentials and protocol behavior presented to the target
Session & command activityinteractive and non-interactive command execution
Transferred files & hashesfiles brought in or created, with their hashes
Tool & client characteristicstooling and client fingerprints seen during interaction
Network metadata & pivotsoutbound attempts, tunnels and pivot indicators
Related artifacts & timelinessupporting material that reconstructs the engagement

Session records, commands, authentication sequences, files, hashes and network context may support later analysis, and are accessible for inspection where the deployment captures them. Internal field names, datasets, stream architecture and retention defaults are not published here.

Surface Console — engagements per hour over the last 24 hours, colored by engagement phase
Surface Console · Engagements per hour, last 24 h (UTC)
02 · STAGE 5 — STRUCTURE HIIH FINDINGS

Observation becomes useful when it supports a decision.

Raw eventsensor level
→
Observationnormalized
→
Contextcorrelated
→
HIIH Findingstructured

Not every observation becomes a Finding. Findings are structured interpretations, and their confidence and relevance depend on the available context.

A Finding can carry what was observed, its family or type, severity and confidence, why it matters, related observations or artifacts, a recommended action, and its status and delivery identity.

Evidence language
Supporting evidence, not a self-verifying chain
Findings may link to supporting observations and artifacts. The public product does not claim cryptographic sealing, tamper-evident manifests or independent verification of every item.

Understand HIIH Findings

03 · STAGE 6 — RETRIEVAL INTO SECURITY WORKFLOWS

The result belongs in the tools your team already runs.

HIIH makes Findings retrievable by the tools teams already operate; the Surface Console is there for depth. The paths:

HIIH Findingstructured object
→
Surface Consoleinspect & investigate
→
MCP · APIyour tools & analysts
→
TAXII 2.1by engagement

A retrieved Finding may support SOC triage and escalation, threat hunting, detection tuning, CTI analysis, incident-readiness exercises, or executive and customer briefing. These outcomes are supported by the workflow — they are not all generated automatically.

Where delivery stands
Pull-based delivery, one Finding identity
A Finding keeps the same identity across the Console, MCP and API pull paths, retrieved on your own schedule; STIX 2.1 over TAXII 2.1 is available by engagement. The Access Finding family is live and inspectable in the Console. Delivery stays pull-based: nothing is pushed into your stack.
Architecture & boundaries
The reference architecture and the boundaries live on their own pages
The logical planes — exposure, engagement, evidence, intelligence, operations — are described on the Surface page. Inbound scope, governed outbound activity, separation from production and data handling are defined at diligence depth on Trust — see production separation, governed outbound and data handling — not repeated here.