TRISIS Takeaways: Defensive Techniques and Trench-Building for the Blue Team
ID: bb5b227d-f6b7-5d28-a1f1-25806641d03a
STIX ID: report--bb5b227d-f6b7-5d28-a1f1-25806641d03a
Feed Name: Dragos Blog
This report provides a technical analysis of TRISIS, an ICS-targeting malware that modifies Triconex SIS controllers by extending the TriStation 1131 protocol (notably adding Command 29) to deliver payloads; it details reverse-engineering efforts, infection and persistence behaviors (memory-resident, network command processor), evasion and detection challenges (no protocol authentication, easy packet spoofing, firmware hooks), affected firmware versions (Triconex 10.2 and 10.4), and defensive recommendations such as program-download detection and minimizing time in PROGRAM mode.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
