Finding family: AccessFinding family: Engagement

What HIIH can investigate

01 · FIVE QUESTIONS HIIH CAN HELP INVESTIGATE

Each question maps to a Surface pattern, observable material and a decision.

Finding family: Access
Who is validating access at the edge?
Surface — a selected edge-exposure profile with a Contact Point separate from production. Material — credential attempts, timing and repetition, success/failure sequence, client characteristics. Decision — inspect production auth logs, assess credential exposure, watch related infrastructure.
Finding family: Engagement
What happens once an operator believes access is real?
Surface — a Live Host under an approved engagement policy. Material — commands, files, discovery, persistence or outbound attempts where recorded. Decision — update detections and hunting, prepare incident hypotheses, brief leadership on observed tradecraft.
Is this broad Internet noise or something more relevant?
Material — recurrence, exposure profile, sector or regional overlap, behavior depth, internal versus public placement. Decision — classify and prioritize without calling every source targeted.
What should detection engineering do with the observation?
Material — commands, files, hashes, network patterns and related Research content. Decision — create a hunt, tune a rule, validate telemetry or update an escalation path.
What can the CISO explain to risk and leadership?
Output — a concise Finding with confidence, relevance, supporting observations, actions taken and limitations. Decision — explain the event without inflating it into an unproven attribution.
02 · EDGE & CREDENTIAL-VALIDATION INTELLIGENCE

A successful login followed by immediate disengagement can mean more than a failed attack.

Some actors test credentials or access without immediately exploiting the target. Traditional logs may record the authentication but not reveal the broader sequence or purpose. A controlled target can preserve timing, repetition, related client characteristics and any subsequent behavior — supporting an access-validation hypothesis without proving an identity or a commercial transaction.

HIIH FindingFinding family: Access Illustrative example
Confidence High
Observed activity
Repeated credential validation against a selected edge profile, then disengagement
Mission relevance
Sector-relevant
Why it matters
Sequence is consistent with access validation rather than exploitation or broad scanning
Supporting material
Authentication sequence, success/failure pattern, client characteristics, timing cluster
Suggested action
Review related production authentication logs and monitor for the observed pattern
Delivery
Surface Console · MCP · API — pull-based
The observation establishes what occurred on the Surface. It does not automatically establish that the actor targeted the firm’s production environment, nor identify the final intended buyer.
03 · CONTROLLED POST-ACCESS OBSERVATION

Observe post-access tradecraft where failure does not mean production impact.

Live Hosts sustain deeper shell interaction on a real operating-system target. The Surface can preserve commands, files and session behavior, while outbound activity is governed within the deployment architecture. The objective is observation and intelligence, not hostile execution on production.

For finance teams this supports detection updates for modern operating systems and edge-adjacent infrastructure, incident-readiness hypotheses, review of credential use and discovery behavior, and an understanding of automated, human or mixed operator workflows where the evidence supports it.

This is deep engagement on modern operating systems. HIIH does not promise a full digital twin of the bank or parity with every internal system.
04 · NON-PUBLIC PLACEMENT & INTERNAL SIGNAL

A non-public target answers a different question from an Internet-exposed one.

PlacementUseful forSignal qualification
Publicly exposed missionInternet pressure, credential validation, exposed-service behavior, regional or sector patternsbroad to customer-directed depending on context; never automatically targeted
Non-public or approved internal placementunexpected discovery or authentication inside an approved segment; lateral-movement and post-compromise questionshigher-confidence indication that a process or actor is present where it should not be

Availability and exact placement are shaped per deployment. HIIH does not claim large populations of simulated devices, and does not interfere with real network addressing or production services. See the HIIH Surface and the Trust page.