Setting up the engagement

01 · STAGE 1 — DEFINE THE QUESTION & EXPOSURE

Start with what the organization needs to learn or detect.

The question and its exposure context determine what “relevant” means. An Internet-wide scan, a sector-specific validation pattern and an internal non-public touch are not treated as equivalent.

Inputs to a deployment:

  • asset or service profile of interest
  • Internet-facing, non-public or isolated placement
  • geographic or sector context
  • desired engagement depth
  • authorized interaction and containment policy
  • evidence and retention requirements
  • output destination

A financial-sector team may want to understand credential validation against an appliance profile. A mature SOC may want to observe what an operator does after a shell is obtained. An MSSP may want high-confidence interaction signal its SIEM can retrieve.

Scoping is a managed design process with OHIIHO.
02 · STAGE 2 — ROUTE INTO THE CONTROLLED ENVIRONMENT

Selected interaction reaches HIIH, not the production asset.

For exposed deployments, an Edge Sensor receives traffic for the selected exposure and routes it into the controlled HIIH engagement environment. For non-public deployments, an authorized presence or target is placed where unexpected discovery or interaction should carry operational meaning.

Adversaryhostile automation
→
Selected exposureor authorized path
→
HIIH Surfacecontrolled target

Production assets remain separate. HIIH is not an inline firewall and does not require all production traffic to pass through the Surface.

What the Surface preserves at this stage, conceptually: source and session context required for analysis, target identity, and the timing and interaction chain. How that routing is implemented is not described publicly.

03 · STAGE 3 — ENGAGE AT THE APPROPRIATE DEPTH

The target determines how much the adversary can reveal.

Engagement depth is selected and managed explicitly.

Contact Point

Connection → protocol interaction → authentication or request sequence → early observations.

Useful when the question concerns — credentials presented, service or appliance pressure, tool behavior, and broad but economical coverage.

Early signal
Live Host

Connection and authentication → operating-system session → commands, files, tooling and network behavior → deeper observations and artifacts.

Useful when the question concerns — post-access intent, tooling and tradecraft, persistence or pivot attempts, malware behavior and defensive-content generation.

Deep interaction

The target may use a coherent synthetic context generated at setup and maintained through background activity — see credible synthetic context.