Analytics BIOC Informational

Possible IPFS traffic was detected

The host attempted to access other nodes in an IPFS manner.

Module:
Platform Analytics
Data source:
Palo Alto Networks Firewall traffic Logs, XDR Agent
ATT&CK tactics: Exfiltration (TA0010) Initial Access (TA0001)
ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048) Phishing (T1566)
Attacker's goals:

IPFS access may expose your organization to new malware or allow attackers/ malicious insiders to exfiltrate data.

Investigative actions:

Check the host for IPFS client software. Examine the client's network traffic for uploaded or downloaded file hashes.

Test period:
N/A (single event)
Deduplication:
1 Day