Setting up the engagement
Start with what the organization needs to learn or detect.
The question and its exposure context determine what “relevant” means. An Internet-wide scan, a sector-specific validation pattern and an internal non-public touch are not treated as equivalent.
Inputs to a deployment:
- asset or service profile of interest
- Internet-facing, non-public or isolated placement
- geographic or sector context
- desired engagement depth
- authorized interaction and containment policy
- evidence and retention requirements
- output destination
A financial-sector team may want to understand credential validation against an appliance profile. A mature SOC may want to observe what an operator does after a shell is obtained. An MSSP may want high-confidence interaction signal its SIEM can retrieve.
Selected interaction reaches HIIH, not the production asset.
For exposed deployments, an Edge Sensor receives traffic for the selected exposure and routes it into the controlled HIIH engagement environment. For non-public deployments, an authorized presence or target is placed where unexpected discovery or interaction should carry operational meaning.
Production assets remain separate. HIIH is not an inline firewall and does not require all production traffic to pass through the Surface.
What the Surface preserves at this stage, conceptually: source and session context required for analysis, target identity, and the timing and interaction chain. How that routing is implemented is not described publicly.
The target determines how much the adversary can reveal.
Engagement depth is selected and managed explicitly.
Connection → protocol interaction → authentication or request sequence → early observations.
Useful when the question concerns — credentials presented, service or appliance pressure, tool behavior, and broad but economical coverage.
Connection and authentication → operating-system session → commands, files, tooling and network behavior → deeper observations and artifacts.
Useful when the question concerns — post-access intent, tooling and tradecraft, persistence or pivot attempts, malware behavior and defensive-content generation.
The target may use a coherent synthetic context generated at setup and maintained through background activity — see credible synthetic context.