The TRITON malware framework uses TriStation, a proprietary ICS network protocol, to communicate with target Triconex SIS controllers. We did some “reverse engineering” (mostly just studying and writing down our observations) of this protocol to help understand its structure and develop some detection logic for abuse of this protocol. This talk will be a story of 1) learning a new (to us) network protocol and 2) investigating the origin story of the TRITON framework to discover some things we didn’t see before.