The Finding and worked examples
01 · WHAT A HIIH FINDING GIVES THE ANALYST
What the Finding gives the analyst.
A HIIH Finding is a structured interpretation of observed adversary activity, carrying context, confidence, related material and an operational implication. The example below is illustrative and sanitized.
HIIH FindingFinding family: Access
Illustrative example
Confidence
High
- Observed activity
- Repeated credential validation followed by immediate disengagement
- Mission relevance
- Sector-relevant
- Why it matters
- The sequence is consistent with access validation rather than interactive exploitation — a possible access-broker or credential-checking workflow
- Supporting material
- Authentication sequence, client fingerprint, timing cluster, recurring source characteristics
- Suggested action
- Inspect production edge authentication logs for related identifiers, assess credential exposure, monitor recurrence and infrastructure overlap
- Delivery
- Surface Console · MCP · API — pull-based
Customer-directed targeting is not established by the event alone. The Finding states what was observed, what it supports, and what it does not conclude.
02 · WORKED EXAMPLE — ACCESS VALIDATION AT FIRST CONTACT
Facts and interpretation, kept separate.
| Mission question | What is validating credentials against exposed edge infrastructure, and how does that differ from ordinary scanning? |
| Surface context | A selected edge-exposure profile represented through a controlled Contact Point separate from production. |
| Observed | Authentication attempts; timing and repetition; accepted or rejected credentials where applicable; immediate disengagement after validation; related source and client characteristics. |
| Assessed | The sequence is more consistent with credential validation than interactive exploitation; the behavior may support an access-broker hypothesis. |
| Not established | The event does not prove the actor’s identity or final buyer, nor that the activity is directed at any single organization. |
| Output | An Access Finding, inspectable in the Console; a SOC alert or investigation context; search pivots for production edge logs; detection guidance where produced. |
Proof: this pattern is grounded in FortiBleed from the Target Side ↗.
03 · WORKED EXAMPLE — DEEPER POST-ACCESS BEHAVIOR
What operators do once they believe the target is real.
| Mission question | What does the operator do after obtaining a shell on a system they believe is useful? |
| Surface context | A controlled Live Host separate from production, instrumented for session capture. |
| Observed | Commands in sequence; tool or payload transfer; discovery activity; persistence, propagation or outbound attempts where recorded; files and hashes. |
| Assessed | Likely objective and tradecraft; whether the operator is automated, human or mixed, only where the behavior supports it; the limits of attribution. |
| Not established | Post-access behavior on the Surface does not mean the client’s production was breached, and does not by itself attribute the activity to a named actor. |
| Output | Session replay and ordered-command review in the Console; detection and hunting content; an Engagement Finding as that family is populated; an executive or CTI briefing. |
Proof: session-level capture of this kind is shown in Inside Sorry-worm ↗.