logo

The TRITON Won’t Protect You From Our Punches

ID: c6cd6f6b-7bfd-548b-aee3-689b04822bbe

STIX ID: report--c6cd6f6b-7bfd-548b-aee3-689b04822bbe

Feed Name: SensePost Blog

Threat Score
75/100

Date Published: 2017-04-06

Date Updated: 2026-04-29

...
...

This Red Team report describes how Forcepoint TRITON web-content gateway logic can be abused to exfiltrate files and implement a stealthy external command-and-control channel: a PowerShell/Internet Explorer COM-based client chops data into hex chunks sent as URL paths and the server uses 301/302 redirects to encode commands back to the client (including multi-chunk retrieval), enabling remote command execution and script invocation; the technique was demonstrated successfully against multiple DLP/proxy products and delivered via VBA to achieve multiple internal shells without detection by network defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.