UNDER DEVELOPMENT... Learning never stops. Your comments, encouragement or criticism to my blog tkokhing.github.io are most welcome to help me grow. Thank you! ...UNDER DEVELOPMENT

Home / heptagoning


WHAT IS HEPTAGONING?

I coined the term 'heptagoning', which came from the 7-sided polygon, or heptagon, with the inspiration from the 7 stages of attack phases in the Cyber Kill-Chain concept.

The Creation

After several years of conducting cyber risk management, I reached a point where I had to ask, "Why does this mitigation work?" This pushed me to dive deeper into how exploits are discovered, which, in turn, led to a systemic question:

"Is lateral and horizontal movement that easy?"

When advising on risk assessments, customers often focus on the entry points of a vulnerability – after all, you cannot steal what you cannot access.

There is nothing wrong with this mental model; keeping the business running at optimum cost is, undeniably, their utmost priority.

Forming the Shape

As always, the best way to answer a systemic question is through the eyes of a hacker. This realization led me to embark on the OSCP - an on-going process is taking shape - heptagoning.


Cover Image for Active Directory

More Stories