MANAGED ENDPOINT DETECTION & RESPONSE

Stop threats at the endpoint.
Before they spread.

CrowdStrike Falcon for desktops, notebooks and servers with an MSSP Advanced Defend license—uniting next-gen antivirus, EDR, proactive threat hunting and response workflows on one cloud-native platform. Join Ruk-Com’s 30-day evaluation program with no minimum endpoint count.

30 DAYSFree evaluationNO MINIMUMAny endpoint countONE SENSORPrevent · EDR · Hunt
01

Prevent before impact

Reduce malware, ransomware and endpoint attack risk with next-gen antivirus and Falcon threat intelligence.

02

See the sequence of events

Use telemetry and detections to investigate related processes, files, users and behavior faster.

03

Respond with clear authority

Predefine owners, escalation channels and host-containment authority so every incident has accountability.

04

Start with a real evaluation

Ruk-Com’s 30-day evaluation program has no minimum endpoint count and includes a pilot, policy baseline and agreed success criteria.

MSSP ADVANCED DEFEND

One license for prevention, EDR and threat hunting

Each capability works together on the Falcon platform—from prevention and investigation signals to response context.

FALCON PREVENT

Next-Gen Antivirus

Helps prevent malware and ransomware using indicators and endpoint behavior.

  • Malware prevention
  • Exploit & behavior detection
  • Policy-based protection
FALCON INSIGHT EDR

Endpoint Visibility

Retains relevant telemetry to review detections, process trees and event activity.

  • Detection context
  • Process & activity search
  • Incident investigation
FALCON OVERWATCH

Proactive Threat Hunting

CrowdStrike threat hunters look for adversary behavior that may evade automated detection.

  • Human-led hunting
  • Adversary behavior
  • Hunt findings
RUK-COM SERVICE

Policy & Response Coordination

Supports policy groups, detection context review and response coordination within agreed authority and scope.

  • Policy baseline
  • Detection review
  • Incident escalation

ONE SENSOR · MULTIPLE DEFENSE LAYERS

Protection from the first file to behavior hidden in the system

A single Falcon sensor sends context to the cloud-native Falcon platform, where machine learning, AI, indicators of attack, exploit blocking and threat intelligence work together against malware, ransomware, malware-free and fileless attacks—online and offline.

FALCON PROTECTION CONTINUUM CLOUD-NATIVE ANALYTICS
ATTACK SPECTRUMRANSOMWAREMALWARE-FREEFILELESS ATTACKEXPLOIT
CrowdStrikeFALCON SENSORONE LIGHTWEIGHT AGENT
Machine LearningArtificial IntelligenceIndicators of AttackExploit BlockingThreat Intelligence
SECURITY OUTCOMEPREVENTBlock before executionDETECTCorrelate behaviorHUNTFind stealthy threatsRESPONDContain and remediate
A single Falcon sensor reduces agent sprawl and connects prevention, detection, investigation and response with shared context.
01Included

Falcon Prevent

NGAV uses machine learning, AI, IOAs, exploit blocking and centrally managed policy against a broad attack spectrum.

02Included

Falcon Insight EDR

Captures and analyzes raw events for detections, process-tree review and attack reconstruction in CrowdScore Incident Workbench, enriched with context for forensic investigation.

03Included

Falcon OverWatch

Human threat hunters look for adversary activity and signals automated controls may miss around the clock.

04Validate entitlement

Falcon Device Control

Adds USB visibility and granular controls by device class, vendor, product or serial number.

05Validate entitlement

Threat Graph + Falcon Data Replicator

Correlates telemetry with cloud-scale AI and provides a near-real-time event feed for analysis and integration.

06Validate entitlement

Falcon Firewall Management

Create, manage and enforce host firewall policy centrally, with visibility into network activity and anomalies.

POWERFUL PROTECTION

Immediate prevention

Reduce malware, ransomware, malware-free and fileless risk with technologies working together.

UNRIVALED VISIBILITY

Live and historical context

Connect hosts, users, processes, files and indicators into a sequence beyond isolated alerts.

FAST REMEDIATION

Investigate and respond faster

Use current and historical telemetry to contain, investigate and remediate within approved authority.

RAPID DELIVERY

Cloud delivered through one sensor

Deploy one lightweight sensor with automatic updates and online/offline operation, validating module and OS requirements before rollout.

License scope: MSSP Advanced Defend includes Falcon Prevent, Falcon Insight EDR and Falcon OverWatch. Device Control, Data Replicator and Firewall Management require entitlement, operating-system, policy and integration validation before activation.

ENDPOINT-TO-RESPONSE ARCHITECTURE

From endpoint to response, every step stays connected

Falcon Sensor sends telemetry to the Falcon platform for prevention and detection. Detections and Falcon OverWatch context then reach Ruk-Com and customer owners for review before any authorized action.

Ruk-Com CloudMANAGED EDR SERVICE FLOW
Flow example
01

Organization endpoints

Desktop · Notebook · Server

02

Falcon Sensor

Policy · Prevention · Telemetry

03CrowdStrike

Falcon Platform

Prevent · Insight EDR

04A

Falcon OverWatch

Proactive threat hunting

04B

Detection & Investigation

CrowdScore Incident Workbench

05

Ruk-Com + Customer team

Review · Escalate · Respond

Telemetry / DetectionThreat huntingAuthorized response
Primary flow: Endpoint → Falcon Sensor → Falcon Platform → Detection and threat hunting → Ruk-Com with customer owners → response under agreed authority and runbooks.

DETECTION-TO-RESPONSE WORKFLOW

From alert to a traceable response decision

We distinguish detections from incidents and recommendations from system changes, keeping response aligned with context and authority.

01DETECT

Receive detection

Collect severity, host, user, process and related indicators.

02TRIAGE

Review context

Separate expected activity, false positives and events requiring investigation.

03ESCALATE

Notify owners

Share evidence, initial impact and response options through agreed channels.

04RESPOND

Limit impact

Contain the host or take other action under approved policy and authority.

05VERIFY

Verify and close

Confirm status, record the timeline and assign longer-term remediation.

Response authority is agreed before service begins.
Host isolation, process termination, file quarantine and policy changes can affect users and business systems, so actions follow defined authority, runbooks and approvers.

CONTROLLED ONBOARDING

A controlled rollout that avoids unnecessary disruption

01

Inventory endpoints

Count desktops, notebooks and servers with OS, version, network zone and owner.

02

Design policies

Separate users, servers and critical workloads; define prevention and justified exclusions.

03

Pilot and validate

Deploy a pilot group and validate key applications, performance and Falcon connectivity.

04

Roll out in waves

Expand by approved group, track coverage and remediate unhealthy sensors.

05

Test escalation

Validate owners, backup channels, runbooks and response authority with a scenario exercise.

SERVICE SCOPE

Know what is included and what needs assessment

Included

  • CrowdStrike Falcon MSSP Advanced Defend license
  • Scoped policy groups and onboarding plan
  • Detection context review and incident coordination
  • Coverage and sensor-health review

Requires assessment

  • Legacy operating systems, specialized applications or network constraints
  • External SIEM, SOAR, ticketing or workflow integrations
  • Incident response, forensics or threat hunting outside the license scope
  • Falcon modules outside MSSP Advanced Defend
30DAYSRUK-COM EVALUATION

PROOF BEFORE COMMITMENT

Evaluate any number of endpoints in the scope you need to prove

This evaluation program is provided by Ruk-Com with no minimum endpoint count. We help validate compatibility, define a pilot group, establish prevention policy, verify visibility and review results at the end of 30 days before monthly service begins.

01Define scope02Deploy sensor03Validate detections04Review 30 days
Request a trial

TRANSPARENT VOLUME PRICING

Lower per-node rates as your protected estate grows

One node is one licensed endpoint running Falcon Sensor, such as a desktop, notebook or server.

ENTRY TIER · 1–50 NODES
฿500

THB / node / month

  • MSSP Advanced Defend
  • Prevent + Insight EDR + OverWatch
  • Price excludes 7% VAT

Active-node volume rates

1–50 NodeEntry tier฿500 / Node
51–100 NodeGrowing teams฿450 / Node
101–1,000 NodeEnterprise tier฿400 / Node
1,001+ NodeLarge estates฿350 / Node

How it works: The rate for the total monthly active-node band applies to every node; pricing is not progressive.

QUESTIONS BEFORE ONBOARDING

Questions to settle before deployment

These details align deployment and response with how your organization actually operates.

How does Ruk-Com’s 30-day evaluation program work?

This Ruk-Com evaluation program has no minimum endpoint count. Start with one endpoint or a pilot group that reflects your environment. We validate compatibility, define policy and agree success criteria before deployment.

How does volume pricing work?

One rate applies to every licensed endpoint based on the total active-node count for the month: THB 500 for 1–50 nodes, THB 450 for 51–100, THB 400 for 101–1,000 and THB 350 for 1,001 or more. Rates are not progressive and exclude 7% VAT and out-of-scope integrations.

What is included in MSSP Advanced Defend?

It includes Falcon Prevent for next-gen antivirus, Falcon Insight EDR for visibility and investigation, and Falcon OverWatch for proactive threat hunting.

Does it support every operating system?

OS, version, architecture and workload constraints must be checked against CrowdStrike support before deployment. A pilot group is used before wider rollout.

Will a detected host be isolated immediately?

That depends on agreed policy and authority. Endpoint-impacting actions require a defined runbook, approvers and escalation path.

Does EDR replace backup, patching or email security?

No. EDR is an endpoint prevention and detection layer. Organizations still need backup, patch management, identity security, email security and network controls appropriate to their risks.

Is Falcon OverWatch operated by Ruk-Com?

Falcon OverWatch is CrowdStrike’s threat hunting service. Ruk-Com handles the agreed service scope, such as onboarding, policy, detection review and incident coordination.

What is needed for a quotation?

Provide desktop, notebook and server counts by OS/version, site or network zone, critical systems and owners. We then review compatibility and confirm license quantity.

PROTECT EVERY ENDPOINT

Start with a clear inventory.
Build EDR around your organization.

Join Ruk-Com’s 30-day evaluation program with no minimum endpoint count. Share operating systems and critical workloads for compatibility, policy and rollout planning.