One managed Surface. Multiple depths of engagement.
A HIIH Surface is a managed adversary-engagement deployment kept separate from production assets. It combines selected exposure, one or more engagement targets, evidence collection and intelligence delivery — so hostile activity is received, observed and structured on controlled assets, surfacing what adversaries bring, test and do without exposing the systems your organization actually runs.
A Surface is the system around the targets.
A Surface can contain several targets and exposure points while sharing the managed infrastructure required for routing, evidence collection, analysis and operations. The commercial unit is the Surface, because the value comes from the complete operating system around the targets.
| Term | Public definition | It is not |
|---|---|---|
| HIIH Surface | the complete managed deployment for a mission | one honeypot or one VM |
| Target | an adversary-facing asset within a Surface | the whole product |
| Exposure point | the address, domain or authorized non-public path through which interaction reaches the Surface | necessarily a production asset |
| Edge Sensor | a selected point that routes hostile traffic into the controlled environment | the analysis platform |
| Contact Point | a protocol-aware medium-interaction target | a full operating-system shell |
| Live Host | a full operating-system target for deep interaction | a customer production endpoint |
| Evidence context | the events, artifacts and analytical context associated with the Surface | a universal cryptographic evidence seal |
The Surface is described in three short chapters. Read them in order, or jump to what you need.
Design the Surface around the question you need answered.
Select the exposure or operating question that matters. The Surface, engagement depth, deployment pattern and available workflow delivery are scoped around it.