Prevent before impact
Reduce malware, ransomware and endpoint attack risk with next-gen antivirus and Falcon threat intelligence.
MANAGED ENDPOINT DETECTION & RESPONSE
CrowdStrike Falcon for desktops, notebooks and servers with an MSSP Advanced Defend license—uniting next-gen antivirus, EDR, proactive threat hunting and response workflows on one cloud-native platform. Join Ruk-Com’s 30-day evaluation program with no minimum endpoint count.
Reduce malware, ransomware and endpoint attack risk with next-gen antivirus and Falcon threat intelligence.
Use telemetry and detections to investigate related processes, files, users and behavior faster.
Predefine owners, escalation channels and host-containment authority so every incident has accountability.
Ruk-Com’s 30-day evaluation program has no minimum endpoint count and includes a pilot, policy baseline and agreed success criteria.
MSSP ADVANCED DEFEND
Each capability works together on the Falcon platform—from prevention and investigation signals to response context.
Helps prevent malware and ransomware using indicators and endpoint behavior.
Retains relevant telemetry to review detections, process trees and event activity.
CrowdStrike threat hunters look for adversary behavior that may evade automated detection.
Supports policy groups, detection context review and response coordination within agreed authority and scope.
ONE SENSOR · MULTIPLE DEFENSE LAYERS
A single Falcon sensor sends context to the cloud-native Falcon platform, where machine learning, AI, indicators of attack, exploit blocking and threat intelligence work together against malware, ransomware, malware-free and fileless attacks—online and offline.
NGAV uses machine learning, AI, IOAs, exploit blocking and centrally managed policy against a broad attack spectrum.
Captures and analyzes raw events for detections, process-tree review and attack reconstruction in CrowdScore Incident Workbench, enriched with context for forensic investigation.
Human threat hunters look for adversary activity and signals automated controls may miss around the clock.
Adds USB visibility and granular controls by device class, vendor, product or serial number.
Correlates telemetry with cloud-scale AI and provides a near-real-time event feed for analysis and integration.
Create, manage and enforce host firewall policy centrally, with visibility into network activity and anomalies.
Reduce malware, ransomware, malware-free and fileless risk with technologies working together.
Connect hosts, users, processes, files and indicators into a sequence beyond isolated alerts.
Use current and historical telemetry to contain, investigate and remediate within approved authority.
Deploy one lightweight sensor with automatic updates and online/offline operation, validating module and OS requirements before rollout.
License scope: MSSP Advanced Defend includes Falcon Prevent, Falcon Insight EDR and Falcon OverWatch. Device Control, Data Replicator and Firewall Management require entitlement, operating-system, policy and integration validation before activation.
ENDPOINT-TO-RESPONSE ARCHITECTURE
Falcon Sensor sends telemetry to the Falcon platform for prevention and detection. Detections and Falcon OverWatch context then reach Ruk-Com and customer owners for review before any authorized action.
Desktop · Notebook · Server
Policy · Prevention · Telemetry
Prevent · Insight EDR
Proactive threat hunting
CrowdScore Incident Workbench
Review · Escalate · Respond
DETECTION-TO-RESPONSE WORKFLOW
We distinguish detections from incidents and recommendations from system changes, keeping response aligned with context and authority.
Collect severity, host, user, process and related indicators.
Separate expected activity, false positives and events requiring investigation.
Share evidence, initial impact and response options through agreed channels.
Contain the host or take other action under approved policy and authority.
Confirm status, record the timeline and assign longer-term remediation.
Response authority is agreed before service begins.
Host isolation, process termination, file quarantine and policy changes can affect users and business systems, so actions follow defined authority, runbooks and approvers.
CONTROLLED ONBOARDING
Count desktops, notebooks and servers with OS, version, network zone and owner.
Separate users, servers and critical workloads; define prevention and justified exclusions.
Deploy a pilot group and validate key applications, performance and Falcon connectivity.
Expand by approved group, track coverage and remediate unhealthy sensors.
Validate owners, backup channels, runbooks and response authority with a scenario exercise.
SERVICE SCOPE
PROOF BEFORE COMMITMENT
This evaluation program is provided by Ruk-Com with no minimum endpoint count. We help validate compatibility, define a pilot group, establish prevention policy, verify visibility and review results at the end of 30 days before monthly service begins.
TRANSPARENT VOLUME PRICING
One node is one licensed endpoint running Falcon Sensor, such as a desktop, notebook or server.
THB / node / month
How it works: The rate for the total monthly active-node band applies to every node; pricing is not progressive.
QUESTIONS BEFORE ONBOARDING
These details align deployment and response with how your organization actually operates.
This Ruk-Com evaluation program has no minimum endpoint count. Start with one endpoint or a pilot group that reflects your environment. We validate compatibility, define policy and agree success criteria before deployment.
One rate applies to every licensed endpoint based on the total active-node count for the month: THB 500 for 1–50 nodes, THB 450 for 51–100, THB 400 for 101–1,000 and THB 350 for 1,001 or more. Rates are not progressive and exclude 7% VAT and out-of-scope integrations.
It includes Falcon Prevent for next-gen antivirus, Falcon Insight EDR for visibility and investigation, and Falcon OverWatch for proactive threat hunting.
OS, version, architecture and workload constraints must be checked against CrowdStrike support before deployment. A pilot group is used before wider rollout.
That depends on agreed policy and authority. Endpoint-impacting actions require a defined runbook, approvers and escalation path.
No. EDR is an endpoint prevention and detection layer. Organizations still need backup, patch management, identity security, email security and network controls appropriate to their risks.
Falcon OverWatch is CrowdStrike’s threat hunting service. Ruk-Com handles the agreed service scope, such as onboarding, policy, detection review and incident coordination.
Provide desktop, notebook and server counts by OS/version, site or network zone, critical systems and owners. We then review compatibility and confirm license quantity.
PROTECT EVERY ENDPOINT
Join Ruk-Com’s 30-day evaluation program with no minimum endpoint count. Share operating systems and critical workloads for compatibility, policy and rollout planning.