Evaluation and honest limits
01 · A BOUNDED EVALUATION PATH
Evaluate one question, one Surface and one workflow.
| Element | Scope |
|---|---|
| Question | for example: what is validating access against a selected edge profile? |
| Surface scope | one defined exposure, target set and data boundary |
| Workflow | one MCP or API pull path (STIX 2.1 over TAXII 2.1 available by engagement) |
| Success criteria | successful deployment; collection confirmed; at least one controlled or real Finding path; analyst training; technical review; a next-step decision |
| Duration | six to eight weeks, with start and end dates set in advance |
No success criterion requires the capture of a nation-state actor or a rare event. The evaluation proves the source, the workflow and the value — not a lucky catch.
02 · EVIDENCE FROM OHIIHO RESEARCH
What controlled environments have already revealed.
Finding family: Access
Access validation & edge pressure
Observed — exploitation and credential-validation pressure against an exposed appliance profile, captured from the target side.
Supporting material — request patterns, tooling and the sequence of what was attempted.
Outcome — the controls that interrupted the activity, plus shareable detection content — evidence of a class of capability, not a claim about the reader’s organization.
FortiBleed from the Target Side: What Stops Them · 2026-06
Read the research →
Finding family: Engagement
Agentic operator capability
Observed — AI-enabled tooling assembling and running an intrusion-support workflow inside a controlled environment.
Supporting material — session activity, generated artifacts and operating patterns.
Outcome — analysis of how AI-assisted tooling accelerates operator capability, with defensive framing.
The AI Did Not Write the Phish. It Built the Business. · 2026-06
Read the research →
Finding family: Engagement
Deep post-access behavior
Observed — a Go ransomware-worm executing inside a controlled target.
Supporting material — session records, files and tooling recovered during the engagement.
Outcome — behavioral analysis plus detection and hunting content.
Inside Sorry-worm: anatomy of a Go ransomware-worm hybrid · 2026-05
Read the research →
Research conducted on a generic exposure does not imply the reader's organization was involved. Each card explains the capability it supports. Explore evidence from Research ↗
03 · WHAT HIIH DOES NOT CLAIM
Scope and limits
Honest limits
HIIH is not, and does not claim to be
- an inline firewall or prevention control;
- a replacement for EDR, SIEM, XDR, CTI or exposure management;
- a complete identity-deception platform;
- a digital twin of the bank;
- proof that every source is targeting the firm;
- a compliance certification;
- an offensive or hack-back service.
04 · MATURITY & CONTINUITY
Young platform. Managed deployment. Explicit technical truth.
HIIH is delivered through bounded, managed engagements. OHIIHO maintains a claim discipline: the public site distinguishes what is available now from what is shaped per deployment. Technical diligence is available under NDA, Research demonstrates operational depth, and continuity, support and escalation are discussed during evaluation. Pretending to be older or broader than the product is would be a liability, not an advantage.