What HIIH can investigate
Each question maps to a Surface pattern, observable material and a decision.
A successful login followed by immediate disengagement can mean more than a failed attack.
Some actors test credentials or access without immediately exploiting the target. Traditional logs may record the authentication but not reveal the broader sequence or purpose. A controlled target can preserve timing, repetition, related client characteristics and any subsequent behavior — supporting an access-validation hypothesis without proving an identity or a commercial transaction.
- Observed activity
- Repeated credential validation against a selected edge profile, then disengagement
- Mission relevance
- Sector-relevant
- Why it matters
- Sequence is consistent with access validation rather than exploitation or broad scanning
- Supporting material
- Authentication sequence, success/failure pattern, client characteristics, timing cluster
- Suggested action
- Review related production authentication logs and monitor for the observed pattern
- Delivery
- Surface Console · MCP · API — pull-based
Observe post-access tradecraft where failure does not mean production impact.
Live Hosts sustain deeper shell interaction on a real operating-system target. The Surface can preserve commands, files and session behavior, while outbound activity is governed within the deployment architecture. The objective is observation and intelligence, not hostile execution on production.
For finance teams this supports detection updates for modern operating systems and edge-adjacent infrastructure, incident-readiness hypotheses, review of credential use and discovery behavior, and an understanding of automated, human or mixed operator workflows where the evidence supports it.
A non-public target answers a different question from an Internet-exposed one.
| Placement | Useful for | Signal qualification |
|---|---|---|
| Publicly exposed mission | Internet pressure, credential validation, exposed-service behavior, regional or sector patterns | broad to customer-directed depending on context; never automatically targeted |
| Non-public or approved internal placement | unexpected discovery or authentication inside an approved segment; lateral-movement and post-compromise questions | higher-confidence indication that a process or actor is present where it should not be |
Availability and exact placement are shaped per deployment. HIIH does not claim large populations of simulated devices, and does not interfere with real network addressing or production services. See the HIIH Surface and the Trust page.