Exposure and the Finding families
Expose a controlled target, not the production appliance.
Production remains outside the engagement environment, the customer chooses the exposure and scope, and OHIIHO operates the specialized Surface. Exact routing and deployment details are provided during technical diligence, and hostile outbound activity is controlled at the infrastructure layer.
Match the depth to the question.
| Contact Point | Live Host | |
|---|---|---|
| Purpose | represent a service or appliance interaction at protocol level | sustain deeper interaction after access |
| Captures | authentication and early behavior | commands, files and session behavior |
| Use for | repeated credential validation, broad exploit or protocol pressure, early signal | operator tradecraft, payloads, persistence or propagation, detection engineering |
| Boundary | no full shell; protocol/persona availability confirmed per deployment | captures only the behavior that actually occurs |
Credential use can reveal a workflow even when exploitation does not follow.
An Access Finding can carry the credential or authentication pattern, the success/failure outcome where captured, the immediate next action or disengagement, recurrence, client and infrastructure context, relevance and confidence, and suggested production-log pivots.
- Observed activity
- Successful authentication followed by immediate disengagement, repeated from related infrastructure
- Mission relevance
- Profile-specific
- Why it matters
- Sequence is consistent with credential validation rather than exploitation
- Supporting material
- Credential pattern, success/failure outcome, client and infrastructure context, recurrence
- Suggested action
- Pivot related production authentication logs; monitor the observed infrastructure
- Delivery
- Surface Console · MCP · API — pull-based
See which technology assumptions and exploit paths are being tested.
Possible observations include protocol negotiation, service-specific request sequences, authentication endpoints, exploit payloads or probes, repeated campaign patterns, and source and client characteristics. Operational outputs include patch or hardening prioritization context, detection and hunting pivots, exposure-management enrichment and campaign monitoring.
When access becomes interaction, the question changes from “what touched us?” to “what did it try to accomplish?”
On a Live Host, HIIH can observe discovery commands, tool download, persistence, propagation or lateral intent, crypto-mining or botnet deployment, and data-collection or outbound attempts where they occur. The output is ordered behavior, files and hashes, an assessment with confidence, a recommended hunt or response action, and Research correlation.