Analytics BIOC Informational

Possible use of IPFS was detected

The host produced traffic consistent with IPFS.

Module:
Platform Analytics
Data source:
Palo Alto Networks Firewall traffic Logs, XDR Agent
ATT&CK tactics: Exfiltration (TA0010) Initial Access (TA0001)
ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048) Phishing (T1566)
Attacker's goals:

IPFS access may expose your organization to new malware or allow attackers/ malicious insiders to exfiltrate data.

Investigative actions:

Check the host for IPFS client software. Look at the user's website history for IPFS url's and check the content ID (CID) for malicious indicators. Examine the client's network traffic for uploaded or downloaded file hashes.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Possible use of IPFS was detected Informational