From observation to delivery
The Surface records what happened, not merely that something was touched.
Sensors produce low-level events. HIIH normalizes relevant activity into observations associated with the Surface, target and engagement context. Availability depends on target type and deployment.
| Observation class | What it captures, where available |
|---|---|
| Authentication & protocol | credentials and protocol behavior presented to the target |
| Session & command activity | interactive and non-interactive command execution |
| Transferred files & hashes | files brought in or created, with their hashes |
| Tool & client characteristics | tooling and client fingerprints seen during interaction |
| Network metadata & pivots | outbound attempts, tunnels and pivot indicators |
| Related artifacts & timelines | supporting material that reconstructs the engagement |
Session records, commands, authentication sequences, files, hashes and network context may support later analysis, and are accessible for inspection where the deployment captures them. Internal field names, datasets, stream architecture and retention defaults are not published here.

Observation becomes useful when it supports a decision.
Not every observation becomes a Finding. Findings are structured interpretations, and their confidence and relevance depend on the available context.
A Finding can carry what was observed, its family or type, severity and confidence, why it matters, related observations or artifacts, a recommended action, and its status and delivery identity.
The result belongs in the tools your team already runs.
HIIH makes Findings retrievable by the tools teams already operate; the Surface Console is there for depth. The paths:
A retrieved Finding may support SOC triage and escalation, threat hunting, detection tuning, CTI analysis, incident-readiness exercises, or executive and customer briefing. These outcomes are supported by the workflow — they are not all generated automatically.