← RegistryDossier · 5 steps · 4 edges
TRITON-class SIS reprogram → disable safety shutdown
After OT-network foothold, reach a Triconex Safety Instrumented System. Download attacker logic that suppresses safety trips on a process that's about to be pushed past its safe envelope.
Filed by AD Knowledge Base
§ Kill-chainDrag · zoom · scroll
§ Context
Assumed environment: foothold inside the OT segment of a heavy-industry / petrochemical / utility plant. SIS engineering station reachable; SIS controller in PROGRAM mode (or attacker has the physical key).
§ Steps
- 01Safety system can't trip → physical incidentImpactT1486— Data Encrypted for Impact
- 02In parallel, manipulate primary control PLCImpactOT-S7-SIEMENS— Siemens S7 Protocol Abuse
- 03Find SIS controller + engineering stationLateral MovementOT-ENG-WORKSTATION— Engineering Workstation Pivot
- 04Foothold in OT segmentLateral MovementOT-IT-OT-PIVOT— IT → OT Network Pivot
- 05Download attacker safety logicImpactICS-TRITON-SIS— Triconex / TRITON SIS Reprogram
§ References
§ Frequently asked
- What is the "TRITON-class SIS reprogram → disable safety shutdown" attack path?
- After OT-network foothold, reach a Triconex Safety Instrumented System. Download attacker logic that suppresses safety trips on a process that's about to be pushed past its safe envelope. It chains 5 steps drawn from real-world offensive-security techniques.
- What starting position does this attack require?
- The first step is Safety system can't trip → physical incident (T1486) — a impact primitive. Assumed environment: foothold inside the OT segment of a heavy-industry / petrochemical / utility plant.
- What is the final impact of this kill-chain?
- The final step lands on Download attacker safety logic (ICS-TRITON-SIS), which falls under Impact. From here, an operator typically pivots into post-exploitation or maintains persistence.
- How can defenders detect or prevent this attack?
- Detection and prevention vary per step. Refer to each linked MITRE ATT&CK entry under "References" — every technique on that page lists defensive controls, detection telemetry, and known threat-actor usage.