Outcomes and the analyst decision

01 · ONE SURFACE, THREE SOC OUTCOMES

Preventive signal. Controlled engagement. First-party intelligence.

Preventive signal

Authentication activity against a Contact Point, protocol fingerprints and repeated access-validation behavior, or unexpected contact with a target that should not be visible. A controlled interaction can carry more context than an isolated perimeter event.

Useful for — SOC enrichment, edge exposure, an entry point to managed deception.

Controlled engagement

Real shell interaction on a Live Host: command and tool capture, file transfer and artifact analysis, and observation of persistence or pivot intent inside the controlled environment. The team can examine behavior that would be dangerous on production, without inviting that execution onto production assets.

Useful for — investigation, incident readiness, threat hunting.

First-party intelligence

Structured Access, Exposure and Engagement Findings, recurring actor or infrastructure patterns, and detection content derived from observed behavior. The organization gains material produced from its defined Surface mission rather than relying exclusively on third-party reporting.

Useful for — CTI, detection engineering, briefings.

02 · FROM INTERACTION TO ANALYST DECISION

The output is not the session. The output is what the session lets the team decide.

Hostile activityraw events
→
Observationsrecorded facts
→
HIIH Findingfacts + assessment
→
Analyst reviewalert · investigate · detect
  • Observation — a directly recorded fact.
  • Finding — a structured interpretation carrying facts, assessment, confidence, mission relevance and a recommended action.
  • Supporting evidence — related session records, commands, credentials, files, fingerprints or network context where available.
  • Alert — a concise operational projection for triage. Alerts remain useful; the canonical value is the Finding and its operational context.
  • Intelligence — the reusable knowledge produced from Findings and analysis.
03 · FIVE OPERATIONAL WORKFLOWS

Where a target-side source changes the analyst’s day.

WorkflowThe questionWhat HIIH contributesThe decision it enables
Triage & prioritizationbroad scanning, access validation, a tool-specific probe, or a meaningful engagement?interaction and Surface context, repeated behavior, client fingerprints where available, Finding family and confidenceignore as noise · monitor a cluster · inspect related production telemetry · escalate
Investigation & replaywhat did the operator actually do after access?ordered commands, session replay where captured, files and hashes, authentication and outbound contextidentify objective or tradecraft · search the estate for related artifacts · update an incident hypothesis
Detection engineeringwhat can we detect in production based on Surface behavior?command sequences, file and process artifacts, network patterns, credential-validation behavior, Research-derived rules where producedcreate or tune a detection · add a hunt hypothesis · validate a control
Threat intelligencewhat primary knowledge did this engagement produce?provenance from a defined Surface, observations separated from assessment, confidence and relevance, Research correlation where appropriateenrich an internal record · brief stakeholders · define a new collection question
Incident readiness & purple teamwould our telemetry and controls recognize what we just observed?real hostile sequences captured separately from production, artifacts suitable for controlled validationtest a detection safely · improve a runbook · update escalation criteria
HIIH is not a complete breach-and-attack-simulation platform and does not provide universal ground truth for every control. It supplies real, captured behavior that your team chooses how to validate against.
Engagement depth
Contact Point vs Live Host — the depth ladder is on the Surface page
Use the interaction depth that matches the question: a Contact Point for authentication, protocol and access-validation signal at low cost per target; a Live Host for post-access commands, files, tooling and pivot intent. Specialized target types are confirmed for a given deployment, not assumed. The full ladder is on the Surface page.