Fit, deployment, proof and limits
01 · COEXISTENCE WITH EXISTING CATEGORIES
A new source for the controls you already operate.
| Existing category | What it optimizes | What HIIH adds |
|---|---|---|
| Firewall / IPS | inline allow, block and inspect | controlled off-production interaction and behavioral context |
| EASM / ASM | discover and assess exposed assets | observe what hostile actors do against a selected controlled profile |
| Vulnerability management | identify and prioritize weaknesses | evidence of real exploit or access pressure on a controlled target |
| External CTI | broad campaign and infrastructure context | first-party observations from the defined Surface mission |
| SIEM / XDR | correlate operational telemetry | structured target-side Findings as a new upstream source |
| Canary / tripwire | deterministic touch alert | protocol context and deeper engagement where required |
Honeypots are part of the technical lineage. The HIIH Surface is the managed system, and structured adversary intelligence is the output.
02 · DEPLOYMENT PATTERNS
Selected exposure, partner-managed, or approved non-public placement.
A · Direct selected exposure
An approved DNS, IP or routing arrangement points at a controlled HIIH environment hosted and operated by OHIIHO. Production remains separate.
B · Partner-managed edge service
An MSSP or operator retains the client-facing integration and SOC workflow. OHIIHO operates Surface infrastructure, and the partner retrieves the outputs.
C · Non-public approved placement
A target discoverable only from an approved internal or restricted segment, used for high-confidence unexpected-interaction questions. Availability and exact architecture are confirmed during diligence.
HIIH does not promise universal deployment in every network topology. Placement and personas are confirmed for the deployment.
03 · RESEARCH EVIDENCE
What controlled edge exposure has already revealed.
Finding family: Access
Target-side access validation
Observed — exploitation and credential-validation pressure against an exposed appliance profile, captured from the target side.
Supporting material — request patterns, tooling and the attempted sequence.
Outcome — the controls that interrupted the activity, plus shareable detection content.
FortiBleed from the Target Side: What Stops Them · 2026-06
Read the research →
Finding family: Engagement
Agentic use of edge access and tooling
Observed — AI-enabled tooling assembling and running an intrusion-support workflow inside a controlled environment.
Supporting material — session activity, generated artifacts and operating patterns.
Outcome — analysis of how AI-assisted tooling reshapes edge access and operator capability.
The AI Did Not Write the Phish. It Built the Business. · 2026-06
Read the research →
Finding family: Access
Repeated infrastructure & cross-region patterns
Observed — residential-sourced credential-validation activity, probing across multiple regions, captured target-side.
Supporting material — authentication sequences, client characteristics, timing and infrastructure patterns.
Outcome — indicators and detection context for credential validation distinct from broad scanning.
Residential Broadband Botnet Uses AsyncSSH to Validate Credentials Across Four Regions · 2026-06
Read the research →
04 · LIMITATIONS & TECHNICAL TRUTH
Scope and limits
Honest limits
What the edge application does not claim
- Not every edge technology or protocol is currently represented; personas and target types are confirmed for the deployment.
- Internet-exposed activity is not automatically customer-targeted.
- HIIH does not patch, block inline or replace exposure management.
- A Live Host captures only the behavior that actually occurs.
- Exact scale, regions and edge availability are confirmed before use.
- Research evidence demonstrates capability, not guaranteed future traffic.