HIIH loop step: Surface

Placement, credibility and infrastructure

01 · EXPOSURE & PLACEMENT PATTERNS

Expose the Surface where the question exists.

A Surface can sit in different places depending on what needs to be learned. The placement shapes what reaches it and what a given observation can support.

A · Selected Internet exposure

Where it sits — a selected address, domain or service profile, reached through an Edge Sensor.

Answers — edge pressure, authentication testing, exploit attempts, regional or sector profiles.

Does not prove — that the activity is customer-directed; relevance is assessed, not assumed.

B · Non-public / lateral discovery

Where it sits — an authorized internal or non-public segment, as an apparent target or controlled service.

Answers — discovery or lateral interaction where unsolicited access should not occur.

Does not prove — post-compromise activity, unless the deployment topology and access path support that conclusion.

Qualified
C · Isolated controlled deployment

Where it sits — a selected research or validation environment.

Answers — research, validation, threat collection or controlled exercises.

Does not prove — findings are scoped to the controlled environment, not a live customer estate.

HIIH does not divert all attacks from production and does not sit inline in front of it. Exposure and authorized placement are selected deliberately for the mission.
02 · CREDIBLE SYNTHETIC CONTEXT

A useful target must look inhabited, not merely exposed.

Skilled operators inspect a target before trusting it. The credibility of the context affects how long they remain, what they reveal and how useful the resulting observations become.

HIIH loop step: Surface
Surface Foundry
creates a coherent synthetic operating context at setup: identity, users, files, histories, configuration and other world content appropriate to the target.
HIIH loop step: Surface
Presence Engine
maintains selected background activity that helps the environment behave like a system in use.
Honest boundary
Synthetic context, not a digital twin
HIIH does not claim to replicate the customer’s full network or maintain a complete digital twin. The context is synthetic and designed for the defined engagement mission.
03 · SHARED MANAGED INFRASTRUCTURE

The heavy infrastructure is shared across the Surface. Targets are selected for the mission.

Routing, containment, evidence collection, analyst access and operations are managed once at the Surface level. Contact Points and Live Hosts are then added as engagement targets inside that managed system.

Shared Surface servicesrouting · containment · evidence · operations · analyst access
→
Targets for the missionContact Point · Contact Point · Live Host

One managed system supports a mix of economical signal and deeper interaction.

This model avoids one full platform stack per target, keeps target activity associated with a single Surface context, and lets OHIIHO operate the difficult infrastructure centrally. Publicly, each Surface maintains a defined analytical and access context for the deployment; exact capacity and internal roles are not published here.

04 · EVIDENCE & ANALYTICAL CONTEXT

Every target contributes to one engagement context.

Targets are not isolated event generators. The Evidence Plane can preserve, where applicable, the material that lets an analyst reconstruct what happened.

  • authentication and protocol observations
  • session records
  • commands and files
  • network metadata
  • artifacts and hashes
  • the relationship between activity and target identity
  • structured Findings derived from observed activity, where produced
Evidence language
Accessible for analysis — not a self-verifying chain
The Evidence Plane makes related material accessible for analysis. The current public product does not claim cryptographic sealing, tamper-evident manifests or independent verification of every item. Supporting evidence is provenance for analysis, not an automated proof.

Understand HIIH Findings · Read the Trust page