Suspicious Proxy Requests to IPFS URLs Containing Email Address

Alerts when proxy request URIs target IPFS and include an email address.

FreeReviewedSigma · Low · v2
Category
proxy
Author
Gavin Knapp (SigmaHQ), DRL 1.1
Published
2023-03-16
Updated
2026-07-31

ATT&CK techniques

Cred Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags proxy traffic where the requested URI includes an IPFS domain (ipfs.io) and also contains a user email address pattern. Attackers can use IPFS-hosted content to distribute phishing or credential-harvesting pages, making email-address-in-URI behavior a useful indicator. Detection relies on proxy logs with the requested URI field (cs-uri) matching the specified IPFS and email regex.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.