Outcomes and the analyst decision
Preventive signal. Controlled engagement. First-party intelligence.
Authentication activity against a Contact Point, protocol fingerprints and repeated access-validation behavior, or unexpected contact with a target that should not be visible. A controlled interaction can carry more context than an isolated perimeter event.
Useful for — SOC enrichment, edge exposure, an entry point to managed deception.
Real shell interaction on a Live Host: command and tool capture, file transfer and artifact analysis, and observation of persistence or pivot intent inside the controlled environment. The team can examine behavior that would be dangerous on production, without inviting that execution onto production assets.
Useful for — investigation, incident readiness, threat hunting.
Structured Access, Exposure and Engagement Findings, recurring actor or infrastructure patterns, and detection content derived from observed behavior. The organization gains material produced from its defined Surface mission rather than relying exclusively on third-party reporting.
Useful for — CTI, detection engineering, briefings.
The output is not the session. The output is what the session lets the team decide.
- Observation — a directly recorded fact.
- Finding — a structured interpretation carrying facts, assessment, confidence, mission relevance and a recommended action.
- Supporting evidence — related session records, commands, credentials, files, fingerprints or network context where available.
- Alert — a concise operational projection for triage. Alerts remain useful; the canonical value is the Finding and its operational context.
- Intelligence — the reusable knowledge produced from Findings and analysis.
Where a target-side source changes the analyst’s day.
| Workflow | The question | What HIIH contributes | The decision it enables |
|---|---|---|---|
| Triage & prioritization | broad scanning, access validation, a tool-specific probe, or a meaningful engagement? | interaction and Surface context, repeated behavior, client fingerprints where available, Finding family and confidence | ignore as noise · monitor a cluster · inspect related production telemetry · escalate |
| Investigation & replay | what did the operator actually do after access? | ordered commands, session replay where captured, files and hashes, authentication and outbound context | identify objective or tradecraft · search the estate for related artifacts · update an incident hypothesis |
| Detection engineering | what can we detect in production based on Surface behavior? | command sequences, file and process artifacts, network patterns, credential-validation behavior, Research-derived rules where produced | create or tune a detection · add a hunt hypothesis · validate a control |
| Threat intelligence | what primary knowledge did this engagement produce? | provenance from a defined Surface, observations separated from assessment, confidence and relevance, Research correlation where appropriate | enrich an internal record · brief stakeholders · define a new collection question |
| Incident readiness & purple team | would our telemetry and controls recognize what we just observed? | real hostile sequences captured separately from production, artifacts suitable for controlled validation | test a detection safely · improve a runbook · update escalation criteria |