Techniques
Sample rules
Suspicious Network Communication With IPFS
- source: sigma
- technicques:
- t1056
Description
Detects connections to interplanetary file system (IPFS) containing a user’s email address which mirrors behaviours observed in recent phishing campaigns leveraging IPFS to host credential harvesting webpages.
Detection logic
condition: selection
selection:
cs-uri|re: (?i)(ipfs\.io/|ipfs\.io\s).+\..+@.+\.[a-z]+