HIIH · Industrial & OT
Finding family: Access

See who tests the access layer that fronts the plant — without asking the plant to be the evidence source.

Industrial and OT environments face targeted intrusion and disruption where the consequences are physical, not only financial — and most of that pressure arrives first at the IT-exposed edge that fronts the plant. HIIH deploys a controlled Surface separate from production assets to observe who validates that access and what they do once they believe they are inside, then turns it into structured Findings for your existing SOC, CTI and OT-security workflows.

See what the Surfaces have observed ↗

HIIH is OHIIHO’s managed adversary intelligence system, deployed through controlled Surfaces separate from production assets. This page is written for industrial, manufacturing and OT organizations; it is not an OT-only variant of the product. Explore the HIIH Surface.
01 · THE THREAT THIS SECTOR ACTUALLY SEES

Industrial intrusions usually begin at the IT-facing edge, not on an industrial protocol.

Industrial operators attract adversaries who are interested in disruption of physical processes and critical services: state-aligned actors, ransomware crews that pivot from the enterprise network toward operational technology, and access brokers who validate and resell a foothold. The realistic first step is typically not an industrial control protocol. It is remote-access infrastructure, an Internet-facing appliance, or a credential tested on the enterprise side of the IT/OT boundary — the pressure a defender can actually observe before it matters.

Two views usually inform the response, and both begin late.

SourceWhat it tells youStructural limit
External threat intelligencebroad knowledge of campaigns, actors and infrastructurenot generated for your specific exposure
Production / OT telemetrywhat touches or executes on real industrial assetsthe adversary is already interacting with something that matters
HIIH Surfacewhat hostile actors bring, test and do against a defined exposure separate from productionrelevance is qualified by mission, placement and evidence
02 · WHY A HIIH SURFACE, HERE

A controlled target-side Surface produces first-party observation of the adversaries pressing your access layer.

You choose a selected edge-exposure profile: the kind of remote-access and Internet-facing service on the enterprise side of the IT/OT boundary, where ransomware crews and access brokers look for a path toward the plant. An Engagement Gateway directs each session into the controlled environment. Contact Points provide economical breadth across that edge, and a Live Host — a full operating-system target an adversary operates inside — preserves post-access behavior: session activity, commands, credentials, transferred files and observed pivot attempts.

Because the observation is drawn directly from hostile interaction on a Surface deployed for your mission, it is first-party — provenance you can follow, not resold reporting. First-party does not mean every actor was targeting you; how relevant an observation is depends on how the Surface is exposed, and HIIH is built to keep that distinction.

Finding family: Access
Access validation & edge pressure
Exploitation and credential-validation pressure against an exposed appliance profile, captured from the target side, and the controls that interrupted it — evidence of a class of capability, not a claim about your organization.
Read the report →
Finding family: Engagement
Deep post-access behavior
A ransomware-worm captured executing inside a controlled target, with detection and hunting content — the disruptive post-access behavior that matters most in an industrial context.
Read the report →
03 · WHAT THE SECURITY TEAM GETS

Structured Findings — observations kept separate from assessments, linked to the evidence — that you retrieve into your own tools.

A HIIH Finding is a structured assessment, not a raw tripwire alert: what was observed kept separate from what is assessed, with a stated confidence, a qualified relevance, and the supporting material an analyst can open. A Finding can include ATT&CK mapping where the evidence supports it.

HIIH FindingFinding family: Access Illustrative example
Confidence High
Observed activity
Repeated credential validation against a selected remote-access edge profile, then disengagement
Mission relevance
Sector-relevant
Why it matters
Sequence is consistent with access validation ahead of a later intrusion, not broad scanning
Supporting material
Authentication sequence, timing cluster, client characteristics and related network context
Suggested action
Review remote-access authentication logs on the enterprise side of the IT/OT boundary and monitor for the observed pattern
Delivery
Surface Console · MCP · API — pull-based
The observation establishes what occurred on the Surface. It does not establish that the actor reached, or intended to reach, the OT environment.

Delivery is a pull model: your team retrieves HIIH Findings through the Surface Console, MCP or the API, into the tools you already run; STIX 2.1 over TAXII 2.1 is available by engagement. Your workflows remain primary; you retrieve Findings on your terms, and HIIH does not become the system of record by default.

04 · HONEST BOUNDARIES

Scope and limits

Honest limits
HIIH observes the access layer that fronts OT — it is not the OT environment
  • HIIH observes the adversary at the IT-exposed edge that typically fronts an industrial environment; it is not an ICS/SCADA testbed, does not emulate industrial control protocols or safety-instrumented systems, and does not stand in for OT-network monitoring;
  • it sits separate from production assets — beside your environment, not inline in any control path;
  • it is a synthetic engagement context, not a replica of your plant or process network;
  • it complements CTI, EDR and SIEM — an additive third source, not a replacement;
  • the evidence is supporting material with provenance an analyst can follow, not a cryptographic attestation;
  • it is not proof that every source was targeting you, not a compliance certification, and not an offensive or hack-back service.

Bring one industrial exposure question that deserves a controlled target-side answer.

Choose the edge or access question that matters. The Surface, engagement depth, deployment pattern and one delivery workflow path are scoped around it.