Dropping Elephant RAT IP Fingerprinting and C2 Domain Contact
Detects suspected malicious activity associated with the Dropping Elephant threat group. The rule monitors for two behaviors: 1) IP address geolocation fingerprinting by identifying non-browser processes communicating with ipify.org and ip2c.org within a 60-second window, and 2) Direct network connections to known Dropping Elephant C2 domains, specifically gcl-power.org and chinagreenenergy.org.
Microsoft Sentinel (KQL)

