RUK-COM BLUETHE BLUE TEAM

EASM + AI-POWERED SECURITY OPERATIONS

See threats clearly.
Defend with context.

Connect what attackers can see with what is happening inside your environment. EASM, SIEM and AI SOC, brought together by a Blue Team that investigates and responds with context.

Technology + Analyst + Response
SIMULATION
CONNECTED DEFENSE

Every layer. One Blue Team.

EASM, threat intelligence and telemetry feed AI and SIEM. The Blue Team validates findings, responds, and feeds results back into defensive improvements.

RUK-COM BLUEAI + SIEM
EASMDiscover exposure
Threat IntelligenceInternet · Dark Web · CTI
TelemetryEndpoint · Cloud · Identity
Blue TeamValidate & respond
DISCOVERDETECTRESPONDIMPROVE
Ingested events12,842
Correlated alerts48
Prioritized cases6
EXAMPLE EVENTIDENTITY · AUTHENTICATION
Credential brute force
Failed logins correlated with source context for analyst reviewInvestigating
Experience in production.
Applied to enterprise defense.
50,000+

Websites in our hosting service base

~100 GB

Daily log volume across hosting operations

10+ years

Experience supporting Ruk-Com Hosting customers

THE CONNECTED BLUE TEAM

Every signal. A team ready to act.

Visibility outside. Context inside.
Follow-through by Ruk-Com Blue.

RUK-COM BLUE / SERVICE OVERVIEW
01 / EASM + INTELLIGENCE

See your exposure

Internet · Dark Web · Public assets

02 / AI + SIEM

Connect the signals

Endpoint · Identity · Cloud logs

03 / BLUE TEAM + RESPONSE

Respond with a team

Validate · Respond · Verify

Verify outcomes → Improve defenses → Continue monitoring
01 / HOW IT WORKS

Know what is exposed—and what to fix first

Discover assets, correlate external feeds and validate organizational relevance. Prioritize findings by exploitability and business impact.

WHAT YOUR TEAM RECEIVESPrioritized findings + asset ownersSee the details
02 / HOW IT WORKS

From scattered logs to one investigation

Collect and normalize logs, enrich them with threat intelligence, and use AI to group alerts and draft evidence-linked timelines for analyst review.

WHAT YOUR TEAM RECEIVESIncident timeline + supporting evidenceSee the details
03 / HOW IT WORKS

Accountability from investigation to follow-through

The Blue Team validates findings and coordinates with your team. Respond under approved playbooks and authority, verify remediation, and feed lessons back into defenses.

WHAT YOUR TEAM RECEIVESResponse plan + action recordsSee the details

Conceptual service flow · AI, analyst coverage and response follow your plan and agreed scope

Explore a scenario: when an account or session is misused

An illustrative defense scenario, not a customer incident.

  1. 01
    USER ENDPOINT

    A user device can be the starting point

    An infostealer may steal credentials or session cookies from a user device before signals appear in corporate systems.

    Control pointEDR + Awareness
  2. 02
    EXTERNAL EXPOSURE

    Exposure beyond your perimeter

    Feeds from stealer markets, the dark web and public sources can reveal signals associated with organizational accounts and assets.

    Control pointEASM + Threat Intelligence
  3. 03
    VALID ACCOUNT MISUSE

    Legitimate access in the wrong hands

    An attacker may use a stolen account or session to access services. Authentication context and session validity both matter.

    Control pointMFA + Revoke Sessions
  4. 04
    DETECTION & RESPONSE

    Correlate signals and respond

    Correlate identity, endpoint and network logs so the Blue Team can investigate anomalies, assess impact and respond under a playbook.

    Control pointSIEM + MDR / SOC

Validate relevance and current exposure before responding. Consider credential resets, session revocation and secret rotation according to the affected data and systems.

Threat technique references MITRE T1078 · Valid Accounts · T1539 · Session Cookie Theft

01 / EXTERNAL ATTACK SURFACE MANAGEMENT

Look beyond your perimeter.
Focus on your risk.

Connect internet, dark web and threat intelligence.
See what is exposed, what changed and what needs action.

EXTERNAL SIGNALS → YOUR CONTEXT
Internet exposureDomain · DNS · IP · Certificate
Track domains, DNS, certificates, IPs and public services. Discover shadow IT and changes to assets owned by your organization.
Dark Web & MarketsMarkets · Forums · Leak signals
Receive feeds covering stealer markets, the dark web and underground forums. Investigate credential-exposure signals associated with your organization, domains and email accounts.
Open Web & OSINTBrand · Public code · Exposed data
Monitor public websites, repositories and paste sites for exposed secrets or API keys and brand impersonation. Route findings to system owners for validation.
Global intelligence feedsIoC · CVE · Malware · TTP
Combine indicators, malicious IPs and domains, malware, CVEs and adversary behavior from multiple intelligence sources to enrich SIEM detections.
EASM + CTI

Context for your organization

Validate assets · Deduplicate
Correlate context and impact

READY FOR ACTION
Asset inventoryKnow scope and ownership
Prioritized exposureKnow what to fix first
SIEM enrichmentAdd context for your SOC
Data-source coverage and validation scope

Agree on assets, monitoring terms, feed sources and review frequency before onboarding. Source coverage depends on access rights and the selected scope; Premium Threat Intelligence Feed follows the plan comparison. Active testing is limited to authorized assets.

Configuration work such as MFA, EDR, hardening and secret management, licenses and active testing are scoped in the proposal, with owners and verification evidence.

02 / AI-ASSISTED SECURITY OPERATIONS

From scattered logs.
To evidence you can act on.

AI assists SIEM operations with enrichment, alert grouping and investigation drafts, helping the Blue Team focus on validation and decisions that matter.

LOG → EVIDENCE → ACTION
01

Collect

Know your data sources

Endpoint · Firewall · WAF
Identity · Cloud · Application
02

Normalize

Connect events with context

Parser · Timestamp · Asset ID
Correlation · CTI enrichment
03

AI triage

Summarize signals and evidence

Alert clustering · Timeline
Evidence links · Analyst brief
04

Respond

Act with defined authority

Analyst review · Playbook
Approval · Audit trail
AI assists · The Blue Team validates and decidesRespond within approved authority, with a record of every action

ROY: Business+
Cloud SOAR: Growth+

See an investigation example and AI safeguards

AI ASSISTS. BLUE TEAM DECIDES.

AI that assists.
People who verify.

Query incidents and logs in natural language, connect indicators, build timelines and draft evidence-based recommendations. Analysts validate findings before confirming incidents and choosing a response.

Separate data access from change authority, with approvals and action records.
AI Assistant (ROY): Business and above · Cloud SOAR: Growth and above
INVESTIGATION BRIEFEXAMPLE
Why does this login require investigation?
EVIDENCE / 01Identity log + Network context

Repeated failed logins followed by a success from a source requiring validation.

ENRICHMENT / 02Asset owner + Threat intelligence

Link the system owner, asset criticality and IP context to support the decision.

Analyst validation before responseRecommend user verification and session review under the playbook
Ingestion healthTimestamp alignmentContextual detectionsTraceable evidence

03 / DETECTION ENGINEERING

Detect what matters.
For the systems you protect.

Build use cases around your assets and relevant threats. Define required logs, detection conditions and response actions, then tune rules to reduce noise.

WEB & API

Web & API attacks

Correlate WAF and access logs for suspicious requests, injection attempts and web-shell indicators alongside legitimate application behavior.

WAF · HTTP · Application
IDENTITY

Identity & privilege abuse

Connect failed logins, MFA, privilege changes and sessions to distinguish brute force from behavior needing further investigation.

IdP · Authentication · Audit
ENDPOINT

Ransomware & endpoint threats

Inspect process lineage, execution and abnormal file activity. Coordinate host isolation using EDR evidence and approved authority.

EDR · Process · File activity
NETWORK

Lateral movement & C2

Connect DNS, network flows and authentication to investigate unusual host-to-host connections and command-and-control indicators.

DNS · Flow · Authentication
CLOUD

Cloud & data exposure

Track IAM, cloud audit events and storage-policy changes, linking exposed assets to data risk.

Cloud audit · IAM · Storage
THREAT HUNTING

Hypothesis-led threat hunting

Use threat context and MITRE ATT&CK to form hypotheses, search evidence and improve enterprise detections and playbooks.

Hypothesis · Evidence · Detection tuning

Reference frameworks: MITRE ATT&CK · NIST SP 800-61r3 for mapping and process design; not a guarantee of detecting every threat.

04 / ENTERPRISE ASSURANCE

Trust requires
an evidence trail.

Bring Security, Risk and leadership onto the same page: data boundaries, decision authority and incident deliverables.

BLUE / SERVICE EVIDENCE
CASE
REVIEW

One case. A complete evidence trail.

  • Incident timeline and impact assessment
  • Evidence references and investigation findings
  • Approvals and response actions
  • Remediation and follow-up
01

Defined data boundaries

Agree log sources, daily volume, retention, residency and export. Separate customer data and define role-based access for each team.

02

Response under your control

Define severity, escalation and approvers. Specify automated versus approval-required actions, with verification and rollback procedures.

03

Reporting that supports decisions

Separate technical findings from executive summaries. Track backlog and detection quality with assessment evidence at the selected plan level.

05 / MEET RUK-COM BLUE

A team you can meet.
In the heart of Bangkok.

Meet the team to review your environment, discuss risk and shape the service scope at Vanit Place Ari, 27th floor.

Vanit Place Ari, Bangkok
27FLOOR
RUK-COM TECHNOLOGYVanit Place Ari

Building A · Suite 2703 · 27th floor

View map

304 Phahonyothin Road, Samsen Nai, Phaya Thai, Bangkok 10400

Meetings by appointment

06 / RUK-COM BLUE / SERVICE PLANS

Match your SOC coverage to your organization’s risk

Every plan includes 24×7 Sekoia SIEM monitoring. Analyst coverage and response SLAs vary. Choose by asset count, response requirements and the depth of service you need.

AI Assistant (ROY): Business and above

Cloud SOAR: Growth and above

Annual contract value = monthly rate × 12

For Small Business

Small Business

฿99,000/ month

฿1,188,000 / 12-month contract

100assets included, up to

Approximately ฿990 / asset / month*

Core monitoring with 8×5 analyst triage

Request a quote Small Business

For Small Business/Medium Business

Business

฿149,000/ month

฿1,788,000 / 12-month contract

250assets included, up to

Approximately ฿596 / asset / month*

Adds AI Assistant and 30-day hot storage

Request a quote Business

For Growing Companies

Growth

฿349,000/ month

฿4,188,000 / 12-month contract

1,000assets included, up to

Approximately ฿349 / asset / month*

24×7 Tier 1 triage with Cloud SOAR

Request a quote Growth

For Mid-Market

Mid-Market

฿849,000/ month

฿10,188,000 / 12-month contract

3,000assets included, up to

Approximately ฿283 / asset / month*

24×7 on-call Tier 2 and monthly threat hunting

Request a quote Mid-Market

For Large Enterprises

Enterprise

฿1,990,000/ month

฿23,880,000 / 12-month contract

10,000assets included, up to

Approximately ฿199 / asset / month*

Dedicated 24×7 analysts, TAM and WAR room

Request a quote Enterprise

Compare the complete service scope

Scroll horizontally to compare all five plans

Ruk-Com Blue SOC pricing and service coverage — five-plan comparison
Service scopeSmall BusinessBusinessGrowthMid-MarketEnterprise
Pricing & asset allocation
Monthly price (THB)99,000149,000349,000849,0001,990,000
Annual contract value (THB)1,188,0001,788,0004,188,00010,188,00023,880,000
Assets included (up to)1002501,0003,00010,000
Approx. effective price / asset / month (THB)*990596349283199
Core service
24×7 Sekoia SIEM monitoring Included Included Included Included Included
Asset Discovery (Sekoia) Included Included Included Included Included
Verified Detection Rules Included Included Included Included Included
CTI-Enriched Alerts Included Included Included Included Included
Endpoint Agent included Included Included Included Included Included
AI Assistant (ROY) Not included Included Included Included Included
30-Day Hot Storage Not included Included Included Included Included
ExaLog 2GB extension (2 months) Not included Not included Included Included Included
Cloud SOAR (auto response) Not included Not included Included Included Included
Human SOC analyst coverage
Tier 1 alert triage8×58×524×724×724×7 dedicated
Tier 2 incident handlingEmail onlyEmail onlyBusiness hr24×7 on-call24×7 dedicated
Response SLA — P1 critical< 8 hours< 8 hours< 4 hours< 1 hour< 30 minutes
Response SLA — P2 high< 24 hours< 24 hours< 8 hours< 4 hours< 1 hour
Threat hunting Not included Not includedQuarterlyMonthlyWeekly
Customization & reporting
Custom detection rules Not included Not includedUp to 10Up to 50Unlimited
Custom IoC collections Not included Not included100k500k5m
Custom SOAR playbooks Not included Not includedUp to 3Up to 10Unlimited
Reporting cadenceMonthlyMonthlyMonthlyBi-weeklyReal-time + Weekly
Executive dashboard Not included Not includedStandardCustomizedReal-time, branded
Compliance reports (PDPA/ISO)BasicBasicStandardAdvancedAudit-ready
Account management & support
Onboarding & integration4–6 weeks (self-guided)4–6 weeks (self-guided)6–10 weeks (guided)10–16 weeks (full PS)16–24 weeks (white-glove)
Dedicated account manager Not included Not includedShared IncludedYes + TAM
Support channelEmailEmailEmail + ChatPhone 24×7Phone 24×7 + WAR room
Quarterly business review Not included Not included Not included IncludedYes (executive)
Premium threat intel feed Not included Not included Not includedOptionalIncluded
AI Incident Management (Prime) Not included Not included Not includedOptionalIncluded
Best for
Ideal customer profileSMB: 20–50 employees, low compliance burden, basic security needsSMB: 50–300 employees, low compliance burden, basic security needsMid-market: 300–1,500 employees, regulated industry (finance/healthcare), needs reliable 24×7Large mid-market / mature security org: 1,500–5,000 employees, dedicated security teamEnterprise: 5,000+ employees, multi-site/global, strict SLA, regulatory + audit needs
Discuss your scopeRequest a quote Small BusinessRequest a quote BusinessRequest a quote GrowthRequest a quote Mid-MarketRequest a quote Enterprise

*Effective per-asset rates assume the full included asset allocation and are approximate. They are not standalone per-asset prices.

Prices are in THB. Annual contract values cover 12 months; no annual discount is shown. Confirm taxes and terms in the quotation.

Agree asset definitions, log sources, EASM scope, data volume and retention before onboarding. Table SLAs are response targets, not guaranteed incident resolution times; confirm coverage windows, SLA measurement and response authority in the contract.

07 / FROM SCOPE TO OPERATIONS

Start with real risk.
Build measurable operations.

  1. 01

    Scope & size

    Review assets, logs, SLAs and business priorities.

  2. 02

    Connect & validate

    Connect systems and validate data quality and permissions.

  3. 03

    Tune & exercise

    Validate detections and exercise playbooks together.

  4. 04

    Operate & improve

    Investigate, review results and improve operations.

Plan onboarding ranges from 4–24 weeks, depending on integrations and organizational readiness.

BEFORE WE BEGIN

Before choosing
your security partner.

How does EASM differ from VA and pentesting?
EASM continuously tracks internet-facing assets and changes. VA assesses vulnerabilities; pentesting validates attack paths within authorized scope. Discovery, scanning and deeper testing boundaries are agreed before work begins.
How does AI work with the SIEM and response?
AI helps group alerts, add context, correlate events and draft evidence-based summaries for analyst review. AI Assistant (ROY) starts with Business; Cloud SOAR starts with Growth. IP blocking, host isolation and account actions follow approved playbooks and response authority.
Does 24/7 monitoring include 24/7 analysts in every plan?
Sekoia SIEM monitoring runs 24/7 in every plan. Small Business and Business include 8×5 Tier 1; 24×7 Tier 1 starts with Growth. Tier 2, response SLAs and support channels vary by plan. Service hours, time zone and severity definitions are confirmed in the agreement.
Can you integrate existing systems and define log residency?
We inventory your SIEM, EDR, firewall, identity, cloud and applications, then validate connectors, data formats and required permissions. Ingestion, retention, data residency and access controls are agreed together. Integrations and licensing depend on the systems and selected plan.
Are the console figures real customer telemetry?
The animated console uses synthetic data to explain the workflow; it does not connect to customer telemetry. The 50,000+ websites, approximately 100 GB of daily logs and 10+ years describe the Ruk-Com Hosting service base, not SOC customer or attack counts.
How do we scope a project and calculate pricing?
Start with assets, log sources, data volumes, analyst coverage and data requirements. Compare the plans, then review integrations, SLAs, EASM scope and response authority with our team before quotation. Annual values shown equal twelve monthly payments.

YOUR ENVIRONMENT. OUR BLUE TEAM.

Put a Blue Team
behind your business.

Start with your assets, logs and the level of coverage you need.

Meet Ruk-Com Blue02-105-4385EASM · SIEM · AI SOC · BLUE TEAM