Analytics BIOC
Informational
✕
Possible IPFS traffic was detected
The host attempted to access other nodes in an IPFS manner.
- Module:
- Platform Analytics
- Data source:
- Palo Alto Networks Firewall traffic Logs, XDR Agent
ATT&CK tactics: Exfiltration (TA0010) Initial Access (TA0001)
ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048) Phishing (T1566)
Attacker's goals:
IPFS access may expose your organization to new malware or allow attackers/ malicious insiders to exfiltrate data.
Investigative actions:
Check the host for IPFS client software. Examine the client's network traffic for uploaded or downloaded file hashes.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day