logo

TRISIS Takeaways: Defensive Techniques and Trench-Building for the Blue Team

ID: bb5b227d-f6b7-5d28-a1f1-25806641d03a

STIX ID: report--bb5b227d-f6b7-5d28-a1f1-25806641d03a

Feed Name: Dragos Blog

Threat Score
90/100

Date Published: 2018-06-26

Date Updated: 2026-04-27

...
...

This report provides a technical analysis of TRISIS, an ICS-targeting malware that modifies Triconex SIS controllers by extending the TriStation 1131 protocol (notably adding Command 29) to deliver payloads; it details reverse-engineering efforts, infection and persistence behaviors (memory-resident, network command processor), evasion and detection challenges (no protocol authentication, easy packet spoofing, firmware hooks), affected firmware versions (Triconex 10.2 and 10.4), and defensive recommendations such as program-download detection and minimizing time in PROGRAM mode.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.