The Finding and worked examples

01 · WHAT A HIIH FINDING GIVES THE ANALYST

What the Finding gives the analyst.

A HIIH Finding is a structured interpretation of observed adversary activity, carrying context, confidence, related material and an operational implication. The example below is illustrative and sanitized.

HIIH FindingFinding family: Access Illustrative example
Confidence High
Observed activity
Repeated credential validation followed by immediate disengagement
Mission relevance
Sector-relevant
Why it matters
The sequence is consistent with access validation rather than interactive exploitation — a possible access-broker or credential-checking workflow
Supporting material
Authentication sequence, client fingerprint, timing cluster, recurring source characteristics
Suggested action
Inspect production edge authentication logs for related identifiers, assess credential exposure, monitor recurrence and infrastructure overlap
Delivery
Surface Console · MCP · API — pull-based

Customer-directed targeting is not established by the event alone. The Finding states what was observed, what it supports, and what it does not conclude.

Understand HIIH Findings

02 · WORKED EXAMPLE — ACCESS VALIDATION AT FIRST CONTACT

Facts and interpretation, kept separate.

Mission questionWhat is validating credentials against exposed edge infrastructure, and how does that differ from ordinary scanning?
Surface contextA selected edge-exposure profile represented through a controlled Contact Point separate from production.
ObservedAuthentication attempts; timing and repetition; accepted or rejected credentials where applicable; immediate disengagement after validation; related source and client characteristics.
AssessedThe sequence is more consistent with credential validation than interactive exploitation; the behavior may support an access-broker hypothesis.
Not establishedThe event does not prove the actor’s identity or final buyer, nor that the activity is directed at any single organization.
OutputAn Access Finding, inspectable in the Console; a SOC alert or investigation context; search pivots for production edge logs; detection guidance where produced.

Proof: this pattern is grounded in FortiBleed from the Target Side ↗.

03 · WORKED EXAMPLE — DEEPER POST-ACCESS BEHAVIOR

What operators do once they believe the target is real.

Mission questionWhat does the operator do after obtaining a shell on a system they believe is useful?
Surface contextA controlled Live Host separate from production, instrumented for session capture.
ObservedCommands in sequence; tool or payload transfer; discovery activity; persistence, propagation or outbound attempts where recorded; files and hashes.
AssessedLikely objective and tradecraft; whether the operator is automated, human or mixed, only where the behavior supports it; the limits of attribution.
Not establishedPost-access behavior on the Surface does not mean the client’s production was breached, and does not by itself attribute the activity to a named actor.
OutputSession replay and ordered-command review in the Console; detection and hunting content; an Engagement Finding as that family is populated; an executive or CTI briefing.

Proof: session-level capture of this kind is shown in Inside Sorry-worm ↗.