Skip to content

GREYCORTEX Mendel 4.6

Clearer Context, Faster Investigations, and Smoother Workflows

Mendel 4.6 focuses on making investigations more efficient and network context easier to understand. The new version improves how analysts work with packet data, host identity, and application-layer information, while extending support for enterprise identity standards. Together, these updates help teams confirm findings faster, reduce manual steps, and operate Mendel more effectively in large and complex environments.

Track Host Identity Changes with Hostname History

Devices in a network rarely keep a single identity. Laptops move between networks, systems are reimaged, and different protocols may report different hostnames. As a result, analysts often struggle to confirm whether multiple events belong to the same device. Hostname History and Identity Tracking provides a unified view of how a host’s name changes over time. Mendel 4.6 continuously collects and correlates hostname information from multiple network sources and presents it as a single, time-based identity record per host.
With this capability, analysts can: 
  • Recognize the same device even when its hostname or IP address changes.
  • Follow suspicious activity across different network contexts.
  • Quickly determine whether multiple alerts relate to one host or several.

The result is clearer investigations and better visibility into devices that move, are renamed, or rebuilt.

Identify Devices With Application-Layer Data

Many devices in modern networks communicate in similar ways at the network layer. Without structured application-layer context, analysts lack the information needed to accurately identify device roles and expected behavior — especially in mixed IT and OT environments.

Mendel 4.6 addresses this by extracting and structuring protocol-level metadata and linking it directly to hosts. This turns raw traffic into clear indicators of device role, service usage, and communication behavior.

With this capability, analysts can:
  • Spot unusual or unexpected protocol usage across IT and OT environments.
  • Search and filter hosts by application attributes and service characteristics.
  • Use application-layer details to add context to detections during investigations.

The new version improves asset classification, accelerates investigations, and provides clearer context for detections and alerts.

Investigate Faster with a Unified PCAP Workspace

Mendel 4.6 introduces a unified PCAP workspace that brings capture and replay into one place, with access to PCAPs from all connected sensors. This allows analysts to move directly from alerts to packet-level evidence, speeding up validation and investigation.

With this capability, analysts can:
  • Replay captured traffic to confirm detection details and understand activity in context.
  • Search and filter packets by time, IP address, or session.
  • Correlate traffic flows across IT and OT environments.

The result is faster, more confident investigations with direct access to packet-level evidence, streamlining the retrospective investigation workflow.

Extend Identity Integration with SAML Support

Mendel 4.6 extends identity integration with SAML support, complementing existing LDAP, Kerberos, and OAuth options. This allows security teams to connect Mendel to enterprise SSO platforms and align access control with established identity and authentication policies.

With this capability, administrators can:
  • Enable web-based Single Sign-On using corporate identity providers.
  • Manage authenticators through a clearer, more flexible configuration interface.
  • Secure API access using OAuth2 client credentials and scopes.

The result is simpler user onboarding, consistent access control across environments, and better alignment with enterprise identity standards.

Additional Updates

Flow-Preserving Hardware Bypass for Napatech
High-performance sensors using Napatech adapters now support a flow-preserving hardware bypass mode that reduces CPU load while keeping flow size, timing, endpoints, and metadata.

Zabbix Integration Update for Asset Information
The Zabbix integration now aligns asset data with Mendel’s standardized Asset Information tags. Vendor, model, firmware, and device type details are displayed consistently for each host.

OpenAppID Framework
Upgrade
Mendel has been updated to support the latest OpenAppID framework and signatures, improving application and protocol identification

About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

GREYCORTEX: A Decade of Network Resilience

Ten years is a decisive threshold in cybersecurity. It is an interval long enough for the market to test your claims, for the threat landscape to outpace naive assumptions, and for engineering merit to speak for itself.

In 2016, GREYCORTEX was founded in Brno by eight individuals driven by a singular conviction: world-class technical excellence could be engineered locally to protect critical enterprises anywhere in the world. A decade later, that conviction has been validated on the global stage.Today, GREYCORTEX operates across 27 international markets, earns recognition from premier analyst firms like Gartner and Forrester, and acts as a trusted partner for organizations where information security is not optional. This position was earned through one deployment, one customer, and one complex challenge at a time.

The Core Philosophy: Engineering with Consequence

Our trajectory has never been defined by single breakthroughs, but by a cultural alignment toward systemic excellence. The feedback loop between real-world deployments and core R&D is immediate. The engineers building GREYCORTEX Mendel stay directly aligned with the threat hunters monitoring live, hostile environments.

“When our platform runs inside a critical environment, our commitment is absolute—it is a matter of operational integrity, not an SLA threshold negotiated in a sales room.”
— Radek, Chief Experience Officer (CXO)

Because Mendel is deployed within hospitals, government networks, and critical industrial automation zones, every member of our team understands that security failures carry human and societal consequences. We show up because we recognize the impact of our solution.

Crucibles of Growth: Turning Points

The Geopolitical Pivot

During the onset of COVID-19, our deep market expansion in Japan paused overnight due to global travel restrictions. Despite immense financial pressure, management refused headcount or salary reductions, preserving the structural integrity of our team to execute when the world reopened.

The Architectural Leap

An early, large-scale deployment across nearly twenty remote state nodes pushed our engine beyond its original design limits. In less than thirty days, our R&D team reengineered the core processing module—creating the scalable foundation that underpins our largest enterprise models today.

The Next Epoch: IT/OT Convergence

We did not build GREYCORTEX to be a localized champion. Cybersecurity is a borderless crisis, and our mission has always been global network defense. As traditional enterprise IT rapidly converges with Operational Technology (OT) environments, the threat vector targeting critical infrastructure grows exponentially. This intersection is where we continue to deepen our analytical capabilities.

Our next chapter centers on establishing GREYCORTEX as the definitive standard for network detection and response across Europe, and subsequently, the global enterprise market.

About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

HPE Aruba & GREYCORTEX Mendel Integration Demo

The Outcome: In a live-fire simulation, the integrated HPE CX10000 and GREYCORTEX Mendel solution detected and neutralized an Nmap port scan in under two minutes, requiring zero manual analyst intervention.
 
 

The Integration Workflow

1. Telemetry Ingestion: The CX10000 collects deep flow data and relays it to the Mendel intelligence engine.
2. Behavioral Detection: Mendel recognizes malicious scan patterns in real-time.
3. Automated Response: Mendel triggers a script to update switch security policies immediately.
4. Host Isolation: The attacker is blocked from the network, containing the threat.
 
 

Technical Significance

Featured on HPE Aruba’s Airheads Broadcasting, this demonstration highlights how deep network telemetry can be transformed into actionable, automated security policy. By bridging the gap between infrastructure hardware and security analytics, organizations can significantly reduce the “mean time to respond” (MTTR).

Watch the Full Technical Demo

About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Vendor Access Monitoring & Audit Guide

Vendor access monitoring in most organizations stops at the VPN log. It tells you who connected, but fails to explain what they did next. Without activity data, investigating an incident relies on assumptions rather than facts.

Network Visibility Requirements

  • Real-time and retrospective tracking of accessed systems.
  • Protocol-level analysis of all communications.
  • Data transfer volume and directionality logs.
  • Detailed records of file copies and commands executed.

VPN vs. ZTNA: A Shift in Principle

Traditional VPN

Opens a wide network segment. Once connected, a supplier can potentially reach far more systems than required.

Modern ZTNA

Grants access exclusively to the specific service or application authorized. Nothing beyond that is reachable.

The Risk of Shadow Access (4G/5G Routers)

IT teams often face “shadow” access points installed by vendors for convenience. These unauthorized 4G/5G routers bypass security policies and monitoring entirely. In stable OT (Operational Technology) environments, this is a severe risk.

How to Detect Unauthorized Hardware

Network Detection and Response (NDR) solutions identify rogue hardware through:

  • Device Discovery: Automatic classification of every new device on the segment.
  • Behavioral Baselining: Alerting on new communication patterns or unknown destinations.

Conclusion

Building a verifiable audit trail ensures that when something goes wrong, the data is there to explain it. Moving to a passive monitoring approach allows IT teams to respond to incidents with factual certainty and fulfill compliance requirements through long-term data retention.

About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

AMI Anomaly Detection: Operational Playbooks

In modern AMI environments, smart meters and gateways communicate in highly predictable streams. Deviations from these patterns provide high-fidelity signals for configuration errors or security intrusions. These playbooks offer a structured approach to detecting and validating the most frequent network-level anomalies.

Primary AMI Anomalies and Validation Steps

1. Unidentified Device Discovery

New hardware appearing in AMI subnets often indicates undocumented field work, meter replacement, or unauthorized vendor access.

Mendel Detection: Automatically identifies new assets and classifies them by role (e.g., DLMS/COSEM Server).

Validation Checklist:

  • Service Verification: Confirm any recent local maintenance or meter swaps.
  • Protocol Analysis: Review the device’s main communication peers and used ports.
  • Pattern Matching: Compare behavior against known meters in the same subnet.
Field Action: If the device remains unverified, perform physical verification to prevent unauthorized intrusion.

2. First-Seen Communication Patterns

Emergent use of new protocols or ports may signal unauthorized firmware updates, diagnostic tool misuse, or configuration drift.

Validation Checklist:

  • Standard Compliance: Verify if the protocol aligns with standard AMI operation.
  • Firmware Context: Check for recent rollouts or vendor-driven updates.
  • Geographic Review: Ensure destination IPs are not located in high-risk regions.
Field Action: Conduct a configuration review of the relevant gateway to ensure only authorized services are active.

3. Network Segmentation Violations

Communication outside of approved boundaries (e.g., traffic to the public internet) typically indicates routing failures or firewall misconfigurations.

Validation Checklist:

  • Architectural Alignment: Is the destination part of the approved Head-End platform?
  • Change Audit: Review recent firewall or gateway configuration logs.
Field Action: Adjust gateway settings to strictly restrict AMI traffic to approved internal destinations.

4. Unauthorized DLMS/COSEM Parameter Changes

Unexpected application-layer SET operations can indicate unauthorized manipulation of meter values or settings.

Validation Checklist:

  • Baseline Comparison: Match the new parameter against the expected master configuration.
  • Source Attribution: Verify if the initiating IP address is an authorized system.
Field Action: Restore the baseline configuration and audit access logs before returning the device to service.

Conclusion

Network-level visibility transforms anomaly detection into a practical operational control. By following these playbooks, teams can maintain a predictable AMI environment and detect security deviations early.

About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

GREYCORTEX Mendel 4.6 Now Available

Streamlined Network Analysis: Mendel 4.6 introduces enriched network context and faster investigation tools, allowing security analysts to work more efficiently with complex data.

The 4.6 update focuses on optimizing how analysts validate security findings and interact with network telemetry. By providing a deeper level of visibility, the platform ensures that response teams can identify and address threats with higher precision.

New Features & System Improvements:

  • Hostname & Guest Identity Tracking: Enhanced history logs for hostnames and guest identity monitoring.
  • Application Layer Visibility: Deeper insights into device behavior and asset status using application layer data.
  • Unified PCAP Workflow: A centralized environment for the capture and playback of PCAP records.
  • Modern Authentication Support: Expanded identity management featuring SAML and Single Sign-On (SSO).
  • Napatech Bypass Mode: Implementation of a bypass mode that maintains consistent network flows for Napatech integrations.
  • Enhanced Zabbix Integration: Updated asset information exchange for better synchronization.
  • OpenAppID Framework Update: Refresh of the OpenAppID framework to the latest version.

About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Network Security Monitoring as a Service (NSMaaS): Enterprise Visibility Without the Overhead

 Until recently, achieving full network visibility was a privilege reserved for large enterprises. Advanced monitoring required significant capital investment, specialized security teams, and lengthy deployment cycles. Today, IT teams, particularly those across Europe, face heightened complexity, limited staff, and growing regulatory pressures. The threat landscape is constant, but the ability to manage it varies widely.

Making Enterprise Visibility Accessible

Managed monitoring changes the operational equation for organizations that cannot afford a dedicated 24/7 Security Operations Center (SOC). It provides many benefits similar to SOC as a Service (SOCaaS) but avoids the complexity and infrastructure burden of building a full security function internally.

With technologies like GREYCORTEX Mendel (a Network Detection and Response, or NDR, solution), providers can offer the same depth of insight previously only accessible to major corporations.

The core value is simple: organizations finally gain clarity into what is happening inside their network. They can spot misconfigurations, detect unauthorized connections, and notice the early signs of malicious activity. For many, this is the first time they can verify whether their segmentation and firewall rules are effective against real-world traffic.

How Service-Based Monitoring Works in Practice

This model is exemplified by partners like SOC360 in Poland. They combine Mendel’s deep visibility with their own expert monitoring and response processes, providing predictable costs, quick deployment, and continuous expert oversight.

Key Components of a Managed NDR Service:

  • ✅ Continuous network and log monitoring, providing a constant pulse on system health.
  • ✅ Detection of hidden threats, unauthorized access attempts, and policy violations using behavioral analysis.
  • ✅ Investigation support using historical metadata and full-context analytics for rapid root cause analysis.
  • ✅ Monthly reporting and guidance with clear, actionable recommendations for IT teams.

For many organizations, this replaces reliance on assumptions and isolated alerts with insights supported by data and clear recommendations.

Scaling Up: Visibility for Mature Security Teams

For larger organizations that maintain their own SOC, the approach shifts. Instead of outsourcing, they integrate GREYCORTEX Mendel directly into their environment. In these setups, deep network visibility becomes a powerful analytical advantage.

In-house SOC teams gain a clear view of device communication, user behavior, and performance trends over time. Crucially, they access historical data that traditional log-centric tools often cannot provide. This depth speeds up investigations, reduces noise, and helps analysts understand not only that something happened, but also how and why it occurred.

Conclusion: Visibility That Fits Any Security Maturity

Network security monitoring proves that meaningful visibility is no longer limited by the size of your security team. Smaller companies gain critical clarity without building a SOC, while mature environments enhance their detection and investigation workflows through deeper network context.

GREYCORTEX Mendel supports both needs: it enables providers to deliver reliable monitoring as a service, and it gives enterprise SOCs the analytical depth required to manage complex infrastructures. The objective remains the same: reduce uncertainty, speed up response, and create a network environment where hidden activity is harder to ignore.

About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Women of GREYCORTEX: Different Paths, One Purpose in Cybersecurity

 

When people envision cybersecurity, they often default to a highly technical, male-dominated image. The reality, particularly at events like the recent Ženy v kyber (Women in Cyber) conference in the Czech Republic, paints a different picture—one focused on stories, curiosity, and the determination to enter a new field.

We were proud supporters of the event, as diversity is a core principle at GREYCORTEX. Approximately one-third of our team are women, playing vital roles across every department: development, product, marketing, sales, and technical support. Each of them followed a unique trajectory into cybersecurity. Let’s explore what brought them here.

Curiosity, Coincidence, and Determination

The journey into cybersecurity is rarely linear. Some arrive naturally, while others find their way almost by chance.

  • Minh, a developer, was drawn by the field’s broad scope—from mathematics and cryptography to programming and data analysis. “What drew me most,” she says, “was that the work has real impact, even on a national level. And, of course, I liked the idea of using my analytical mind to fight the bad guys.”

  • Aja, our marketing manager, started by coincidence after writing about tech companies during parental leave. “When they later opened a marketing role, I didn’t hesitate,” she laughs.

Regardless of their starting point, the consensus is that the field’s fast pace and energy keep them engaged. As Monika, our Country Manager for Poland, notes: “I like people, and I like when things happen, and in cybersecurity, things are always happening.”

Cybersecurity is not exclusively reserved for people with traditional technical degrees. What truly counts is persistence, curiosity, and a dedication to lifelong learning.

Irina from our marketing team shared, “The beginning was tough. I had to dive into the tools and really understand how cybersecurity works. I’m still learning every day, but that’s exactly what makes it exciting.”

Breaking Down Stereotypes

Though outdated stereotypes of cybersecurity being solely a “men’s field” are fading, many women still encounter them in professional and everyday situations.

  • Bára, a security analyst, recalled an instance when a shop assistant only accepted her complaint about a faulty router after she meticulously listed every technical test she had already performed on the device.

  • Saša from the product team experienced similar subtle bias at university, which, rather than discouraging her, served as a strong motivator: “Those moments motivated me to keep improving, to be consistent, and confident in my work.”

From the HR perspective, there is growing awareness of the value women bring. Ira from HR states, “I often hear that teams want more women because they bring a different way of thinking and communicating.”

At GREYCORTEX, success is measured by results and expertise, not background or gender. Women on our team lead major projects, design products, analyze network traffic, and run international business operations. They find respect, equal opportunities, and space to grow.

The Human Side of Cybersecurity

When asked what draws people to the field, conference participants cited remarkably similar answers: constant learning, variety, and the feeling that their work has a tangible, real-world impact.

What resonated most was the sense of community. Behind the complex systems are people who share knowledge and support each other, underscoring that security is fundamentally about collaboration and trust.

Ira from HR summarizes this well: “HR in IT is the ideal mix for me. You need to understand technology, but also know how to help teams grow and work together.”

Supporting Women in Cybersecurity

The message from the confident, curious, and inspiring women of GREYCORTEX to anyone considering the field is clear:

If cybersecurity interests you, go for it. And choose a company where the people inspire you and the environment feels right.

At GREYCORTEX, we prove every day that diverse perspectives make teams stronger, more creative, and ready for any challenge ahead.

About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

The Most Frequent DNS Management Errors and How to Fix Them

Want to be sure your DNS setup isn’t weakening your security or network performance? GREYCORTEX experts highlight the most frequent mistakes from countless network audits. This guide breaks them down with practical examples and clear steps for remediation. 

DNS plays a far greater role than simply resolving names to IP addresses. It shapes where users are redirected and reveals which servers devices connect to. DNS traffic is powerful: whoever controls or intercepts it can redirect users, map internal services, or extract sensitive data. That is why DNS remains one of the most overlooked but impactful parts of network security.

Unrestricted DNS Port 53 as a Security Risk

In many networks, outbound port 53 is left completely open, meaning any internal device can connect to any device on the Internet. This critical vulnerability allows attackers to create a DNS tunnel to send arbitrary data through, often hidden within DNS queries. For example, using software like Iodine, they can establish a reverse SSH tunnel from the Internet to the internal network, creating permanent, undetected access.

From an analyst’s perspective, this looks like normal communication with a legitimate DNS server, but a closer look at data patterns—such as constantly changing third-order domain names (e.g., `freemovies.tk`) or the use of unusual record types (like NULL in the `rrtype` attribute)—betrays the presence of tunneling attempts.

Remediation Tips from GREYCORTEX Experts:

  • Block outbound port 53 for all but your authorized DNS servers.
  • Monitor DNS logs for anomalies such as unusual third-level domain patterns or unexpected record types.
  • Treat repeated NULL or other rare `rrtype` values as strong indicators of tunneling attempts.

When Port 53 Is Legally Needed: If port 53 must remain open for corporate resolvers or authorized external providers, restrict it only to those trusted resolvers. Additionally, audit devices that attempt direct resolution against Internet DNS servers, as this often signals malware activity.

Uncontrolled Encrypted DNS (DoH and DoT)

Encrypted DNS protocols like DNS over HTTPS (DoH) on port 443 and DNS over TLS (DoT) on port 853 are designed for user privacy but create significant blind spots in corporate networks. They hide DNS traffic inside encrypted sessions, preventing inspection and policy enforcement. Attackers can leverage these methods to tunnel data, bypass corporate resolvers, or maintain persistence.

While DoT (port 853) is generally easier to block, DoH (port 443) is much harder because it masquerades as normal HTTPS traffic.

Remediation Tips from GREYCORTEX Experts:

  • Block outbound port 853 unless explicitly required by policy.
  • Monitor TLS traffic for signatures and patterns of DoH usage inside port 443, and block those specific DNS domains if they pose an unwanted security risk.

Using Unregistered or External Domains

During audits, experts found cases where companies created secondary domains (e.g., `company2v.com`) but failed to register or control them. When administrators set up proxy servers via Windows Group Policy (GPO), workstations attempted to reach a non-existent, externally owned domain (e.g., `wpad.company2v.com`) to fetch settings.

Since the external party controlled the domain, they could redirect internal corporate devices to any server on the Internet, opening the door for man-in-the-middle attacks—delivering malware under the guise of legitimate updates. A minor oversight in domain registration became a direct attack path.

Remediation Tips from GREYCORTEX Experts:

  • Always register and control all domains that resemble your internal naming scheme.
  • Audit which domains are in active use on your network and confirm ownership.
  • Pay close attention to automatically generated names such as `wpad.domain.com`, which attackers often abuse.

Misspellings in DNS Server IP Addresses

Not all DNS errors stem from complex attacks; sometimes, they are simple human mistakes. Typos in DNS server configurations—like mistyping Google’s resolvers or private IP ranges—are frequently encountered.

While user systems catch these quickly, errors on manually configured devices (like IoT equipment) can persist unnoticed, preventing critical updates or causing hidden communication failures. In the worst case, a typo may resolve to a legitimate Internet DNS server, causing internal queries to leak outside the company network.

Remediation Tips from GREYCORTEX Experts:

  • Use centralized configuration management (like GPO or RMM tools) to reduce manual DNS entry errors.
  • Continuously monitor DNS traffic for failed query destinations or unusual external communications.

Why DNS Hygiene Demands Constant Attention

Modern attackers do not need to break firewalls if DNS gives them a way in. Unrestricted queries on port 53, tunneling hidden inside DoT/DoH, unregistered domains, or misconfigured servers all provide silent channels for persistence or data exfiltration. Continuous auditing and long-term monitoring are the only ways to uncover these errors before they escalate into outages or breaches.

GREYCORTEX Mendel provides you with visibility into your DNS traffic, alerts on unauthorized resolvers, and detects tunneling patterns.

About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Detecting Ransomware Across the Entire Attack Lifecycle

The threat of ransomware is constantly evolving, and traditional security tools are struggling to keep up. This is largely because ransomware has become a sophisticated business model, fueled by the availability of “Ransomware-as-a-Service.” This model allows individuals with very little technical skill to launch professional-grade attacks. Traditional defenses like firewalls and endpoint protection platforms (EPPs) are no longer sufficient because they leave significant blind spots, especially with unmanaged devices such as printers, scanners, and IoT devices that cannot run an endpoint agent.

The Importance of Network Visibility

The core principle for effective ransomware detection is comprehensive network visibility. Every stage of a ransomware attack, from the initial compromise to data exfiltration, leaves a detectable trace in network traffic. By mapping the stages of an attack to the MITRE ATT&CK framework, we can see how network monitoring can reveal malicious activity:

  • Initial Access: Unauthorized user logins or connections to external systems.
  • Execution: The start of a new process or suspicious PowerShell command.
  • Persistence: The creation of new user accounts or scheduled tasks.
  • Privilege Escalation: Network access to administrator accounts or servers.
  • Lateral Movement: Communication between endpoints that normally don’t interact.
  • Command and Control: Connections to suspicious IP addresses or domains.
  • Exfiltration: Large data transfers to external, unknown servers.

How Network-Based Detection Works

A solution like GREYCORTEX Mendel is designed to provide this essential network visibility. Mendel monitors the behavior of the entire network infrastructure, using machine learning and behavioral analysis to detect malicious activity. This is effective even on devices where endpoint protection cannot be deployed.

Beyond active detection, a network-based approach also aids in post-attack compromise assessment. By continuously monitoring for hidden backdoors and “keep alive” connections, it helps ensure the network is truly clean after remediation, preventing attackers from returning later.

Strengthening Your Cybersecurity Ecosystem

A solution like Mendel is a crucial component of a modern cybersecurity ecosystem. By providing deep network visibility, it not only helps stop active attacks but also strengthens long-term network resilience. This holistic approach ensures that your defenses are prepared for a ransomware attack at every stage of its lifecycle.

About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.