Proof, evaluation and boundaries

01 · RESEARCH AS PUBLIC PROOF

Research demonstrates what controlled environments have revealed.

Finding family: Access
Access-validation ecosystem & public detection
Observed — exploitation and credential-validation pressure against an exposed appliance profile, captured from the target side. Supporting material — request patterns, tooling and the attempted sequence. Outcome — the controls that interrupted the activity, plus shareable detection content for member defense.
FortiBleed from the Target Side: What Stops Them · 2026-06 Read the research →
Finding family: Engagement
Propagation & ransomware behavior
Observed — a Go ransomware-worm executing inside a controlled target. Supporting material — session records, files and tooling recovered during the engagement. Outcome — behavioral analysis with detection and hunting content for incident responders.
Inside Sorry-worm: anatomy of a Go ransomware-worm hybrid · 2026-05 Read the research →
Finding family: Engagement
Machine-driven operator capability
Observed — AI-enabled tooling assembling and running an intrusion-support workflow inside a controlled environment. Supporting material — session activity, generated artifacts and operating patterns. Outcome — analysis of how AI-assisted tooling reshapes an intrusion, with strategic and defensive framing.
The AI Did Not Write the Phish. It Built the Business. · 2026-06 Read the research →
Finding family: Access
Cross-region campaign infrastructure
Observed — residential-sourced credential-validation activity, probing across multiple regions, captured target-side. Supporting material — authentication sequences, client characteristics, timing and infrastructure patterns. Outcome — indicators and detection context for credential-validation behavior distinct from broad scanning.
Residential Broadband Botnet Uses AsyncSSH to Validate Credentials Across Four Regions · 2026-06 Read the research →

Research demonstrates capability. It does not imply government endorsement. Explore evidence from Research ↗

02 · A PHASED EVALUATION PATH

Prove the mission before scaling the program.

Phase 1Mission definition
→
Phase 2Controlled deployment
→
Phase 3Operational validation
→
Phase 4Program decision

One sector, region or technology question → bounded Surfaces and one output path → Findings, workflow and member value → extend, maintain, redesign or stop.

Duration: six to eight weeks, with start and end dates set in advance. Success criteria: deployment and collection confirmed; governance agreed; the analyst workflow exercised; at least one controlled or real Finding path demonstrated; the sponsor receives an operational and executive briefing; and limitations documented.

See how an evaluation works →

03 · SCOPE OF THE COMMERCIAL SURFACE

Everything on this page is the commercial product.

This vertical describes the commercial HIIH Surface: a managed product, controlled target-side collection, Findings with supporting evidence, pull-based SOC and CERT delivery, and public and NDA diligence. Premium counterintelligence capabilities for eligible government and national-security agencies are discussed on request.

04 · LIMITATIONS & TECHNICAL TRUTH

Scope and limits

Honest limits
What the commercial product does not claim
  • HIIH does not create national visibility from one deployment.
  • Internet exposure does not equal confirmed targeting.
  • Regional hosting, data residence and access are confirmed per engagement.
  • Cross-Surface intelligence is not a default public capability.
  • Vendor maturity and continuity are assessed during diligence.
  • Research reports are evidence of capability, not guarantees of future events.

See where HIIH fits · Read the Trust page