Exposure and the Finding families

01 · SAFE SELECTED EXPOSURE

Expose a controlled target, not the production appliance.

Customer choicedomain · IP · edge path
→
Approved routingEdge Sensor
→
Engagement environmentContact Point · Live Host

Production remains outside the engagement environment, the customer chooses the exposure and scope, and OHIIHO operates the specialized Surface. Exact routing and deployment details are provided during technical diligence, and hostile outbound activity is controlled at the infrastructure layer.

02 · CONTACT POINT VERSUS LIVE HOST

Match the depth to the question.

Contact PointLive Host
Purposerepresent a service or appliance interaction at protocol levelsustain deeper interaction after access
Capturesauthentication and early behaviorcommands, files and session behavior
Use forrepeated credential validation, broad exploit or protocol pressure, early signaloperator tradecraft, payloads, persistence or propagation, detection engineering
Boundaryno full shell; protocol/persona availability confirmed per deploymentcaptures only the behavior that actually occurs
Contact Point and Live Host are selected when the Surface is designed.
03 · ACCESS FINDINGS

Credential use can reveal a workflow even when exploitation does not follow.

An Access Finding can carry the credential or authentication pattern, the success/failure outcome where captured, the immediate next action or disengagement, recurrence, client and infrastructure context, relevance and confidence, and suggested production-log pivots.

HIIH FindingFinding family: Access Illustrative example
Confidence High
Observed activity
Successful authentication followed by immediate disengagement, repeated from related infrastructure
Mission relevance
Profile-specific
Why it matters
Sequence is consistent with credential validation rather than exploitation
Supporting material
Credential pattern, success/failure outcome, client and infrastructure context, recurrence
Suggested action
Pivot related production authentication logs; monitor the observed infrastructure
Delivery
Surface Console · MCP · API — pull-based
Some observed sequences are consistent with credential or access validation. HIIH preserves the sequence and supporting material; it does not automatically identify the broker, buyer or intended victim.
04 · EXPOSURE FINDINGS

See which technology assumptions and exploit paths are being tested.

Possible observations include protocol negotiation, service-specific request sequences, authentication endpoints, exploit payloads or probes, repeated campaign patterns, and source and client characteristics. Operational outputs include patch or hardening prioritization context, detection and hunting pivots, exposure-management enrichment and campaign monitoring.

HIIH is not a vulnerability scanner and does not replace vulnerability management or external attack-surface management.
05 · ENGAGEMENT FINDINGS

When access becomes interaction, the question changes from “what touched us?” to “what did it try to accomplish?”

On a Live Host, HIIH can observe discovery commands, tool download, persistence, propagation or lateral intent, crypto-mining or botnet deployment, and data-collection or outbound attempts where they occur. The output is ordered behavior, files and hashes, an assessment with confidence, a recommended hunt or response action, and Research correlation.