3BB: sales portal auth from attacker infra with anomalous context
Detects instances where internal devices access the 3BB sales portal (agent.3bb.co.th) while demonstrating signs of compromise. The rule correlates the portal access with recent network activity involving identified MeshCentral attacker infrastructure (ayuthayatech.com or 92.63.180.133) and further filters for behavioral anomalies such as off-hours access, the use of non-standard browser processes, or the use of unexpected service accounts.
Microsoft Sentinel (KQL)

