Detection, proof and boundaries
01 · DETECTION ENGINEERING & HUNTING
Turn observed behavior into defensive content.
Observedcommand · file · network
→Assessmentanalyst review
→Candidate logicdetection · hunt
→Productionvalidate · tune
Where the material supports it, Research produces hunting guides from session behavior, detection and analysis content from observed activity, and infrastructure or credential-validation pivots. HIIH does not promise that every Finding automatically becomes a rule — it provides the captured behavior to build one from.
Delivery & operating model
Delivery paths and the managed operating model are on the Delivery and Trust pages
HIIH is a source upstream of the tools your team already runs — the MCP and API pull paths bring a Finding into your SIEM and analyst workflow, retrieved on your own schedule, without replacing your SIEM, XDR, SOAR or TIP. STIX 2.1 over TAXII 2.1 is available by engagement. OHIIHO designs and operates the Surface so your team consumes intelligence rather than running honeypot infrastructure. Both are set out on Delivery and the Trust page.
02 · EVIDENCE FROM OHIIHO RESEARCH
What the Surfaces have already revealed.
Finding family: Engagement
Post-access malware behavior
Observed — a Go ransomware-worm executing inside a controlled target.
Supporting material — session records, files and tooling recovered during the engagement.
Outcome — behavioral analysis plus detection and hunting content for the SOC.
Inside Sorry-worm: anatomy of a Go ransomware-worm hybrid · 2026-05
Read the research →
Finding family: Engagement
Operator workflow augmentation
Observed — AI-enabled tooling used to assemble and run an intrusion-support workflow, seen inside a controlled environment.
Supporting material — session activity, generated artifacts and operating patterns.
Outcome — analysis of how AI-assisted tooling reshapes an intrusion, with defensive framing.
The AI Did Not Write the Phish. It Built the Business. · 2026-06
Read the research →
Finding family: Access
Access validation & detection content
Observed — exploitation and credential-validation pressure against an exposed appliance profile, captured from the target side.
Supporting material — request patterns, tooling and the sequence of what was attempted.
Outcome — the controls that interrupted the activity, plus shareable detection content.
FortiBleed from the Target Side: What Stops Them · 2026-06
Read the research →
Selected for the SOC questions above. Explore the full evidence set from Research ↗
03 · BOUNDARIES & FIT
What HIIH adds — and what it does not.
- HIIH does not replace EDR, NDR, SIEM, XDR, SOAR or external CTI; it adds a target-side source and a managed engagement environment.
- Internet-exposed activity is not automatically customer-targeted.
- HIIH does not guarantee that an advanced actor will engage during any fixed period.
- Session depth depends on the target type and adversary behavior.
- Specialized target types must be confirmed for the deployment.
- HIIH does not automate attribution beyond the available evidence.
Current public scope
What HIIH claims — and what it does not
HIIH publicly claims Live Host and Contact Point engagement, structured Findings and selected workflow delivery. It does not claim universal deployment across every target type, signed or tamper-evident evidence, self-verifying Surfaces or a complete digital twin of the customer.