HIIH · Edge exposure
Finding family: AccessFinding family: ExposureFinding family: Engagement

See what reaches the edge—and what it is trying to do.

HIIH directs selected hostile traffic into controlled engagement targets separate from production, capturing credential validation, exploit pressure and deeper operator behavior as structured Findings for your SOC and intelligence workflows.

Read the target-side access research ↗

HIIH is OHIIHO’s managed adversary intelligence system, deployed through controlled Surfaces separate from production assets. Edge exposure is one application of the same system, not a separate appliance product. Explore the HIIH Surface.
01 · WHAT EDGE TELEMETRY LEAVES UNANSWERED

A perimeter event says something arrived. It rarely explains what the actor was sent to achieve.

Scanners, credential validators, exploit automation, access brokers, botnets and human operators may all touch the same exposed service. A firewall or appliance log records important events but cannot safely sustain hostile interaction for analysis. External CTI supplies broad context but may not contain the exact sequence observed at your selected exposure, and patching or exposure management reduce risk without answering every question about hostile interest or behavior.

HIIH adds a controlled target-side observation point around selected edge questions. It does not replace the firewall, the log source or the exposure-management program.
02 · THREE EDGE-INTELLIGENCE QUESTIONS

Access, Exposure and Engagement — one triad from early signal to deep behavior.

Finding family: Access
Access — what material does the actor bring?
  • usernames and passwords
  • authentication sequences
  • client fingerprints where available
  • repeated validation patterns
  • timing and source recurrence
Finding family: Exposure
Exposure — what is the actor testing?
  • service discovery
  • exploit probes
  • request patterns
  • payload delivery attempts
  • technology- or persona-specific behavior where the target is confirmed
Finding family: Engagement
Engagement — what does the actor do after access?
  • commands
  • tools and files
  • discovery
  • persistence or propagation attempts
  • outbound behavior inside the controlled environment
03 · READ IN THREE CHAPTERS

The edge application is described in three short chapters. Read them in order, or jump to what you are scoping.

1 · Exposure and the Finding families
Safe selected exposure, matching Contact Point or Live Host depth to the question, and the Access, Exposure and Engagement Findings the Surface produces.
Exposure · depth · Access/Exposure/Engagement
Read chapter 1 →
2 · Relevance, outputs and a worked example
How broad pressure is separated from directed interest, a target-side credential-validation worked example, and the SOC, CTI and hardening outputs.
Relevance · example · SOC/CTI/hardening
Read chapter 2 →
3 · Fit, deployment, proof and limits
How the edge application coexists with existing categories, the deployment patterns, the Research evidence, and the stated limitations.
Coexistence · deployment · evidence
Read chapter 3 →

Start with one exposed technology profile and one intelligence question.

Engagement depth, deployment pattern and one delivery workflow path are scoped around them.