The TRITON Won’t Protect You From Our Punches
ID: c6cd6f6b-7bfd-548b-aee3-689b04822bbe
STIX ID: report--c6cd6f6b-7bfd-548b-aee3-689b04822bbe
Feed Name: SensePost Blog
This Red Team report describes how Forcepoint TRITON web-content gateway logic can be abused to exfiltrate files and implement a stealthy external command-and-control channel: a PowerShell/Internet Explorer COM-based client chops data into hex chunks sent as URL paths and the server uses 301/302 redirects to encode commands back to the client (including multi-chunk retrieval), enabling remote command execution and script invocation; the technique was demonstrated successfully against multiple DLP/proxy products and delivered via VBA to achieve multiple internal shells without detection by network defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
