FortiGate
Traffic · VPN · Security logs
Log / Event intakeMANAGED SOC · DETECTION & RESPONSE
Bring firewall, endpoint, cloud and identity logs into a SIEM. Ruk-Com Blue investigates suspicious activity, assesses impact and coordinates response through procedures agreed with your organization.
Compare timestamps, source IPs, users and assets. Review CTI and normal behavior, then confirm findings with the system owner.
Raw events · Timeline · Analyst notesIf confirmed, coordinate session revocation or endpoint isolation within the authorized scope and available integrations. Record verification in the case.
Approval · Action · Verify · Case update01 / CONNECTED SECURITY OPERATIONS
Firewalls show connections. Identity reveals who accessed them. EDR provides endpoint behavior. We bring that context into a single investigation.
Choose the collection method supported by each product.
TLS · Intake keyRespond within the organization’s approved playbook and scope.
Monitor collection gaps and validate timestamps and parsers so detection uses reliable input.
Separate collection credentials from response accounts and scope permissions to the task.
Keep source-event references, decision rationale and verification results in the case.
02 / INTEGRATIONS
Start with your existing security stack. Validate connectors and real log samples before designing detection and response.
Traffic · VPN · Security logs
Log / Event intakeTraffic · Threat · System logs
Log / Event intakeFirewall · Security events
Log / Event intakeFirewall · Intrusion events
Log / Event intakeFirewall · Network security
Log / Event intakeEndpoint · Detection events
Log / Event intakeEndpoint · Threat events
Log / Event intakeEndpoint · Sign-in · Audit
Log / Event intakeCloud activity · Findings
Log / Event intakeCloud administration · Access
Log / Event intakeWeb application security
Log / Event intakeBackup · Infrastructure events
Log / Event intakeWe assess Syslog, HTTPS, APIs and event formats, then scope parsers, field mapping and the detection use cases you need.
03 / DETECT · HUNT · INVESTIGATE
Ruk-Com Blue designs use cases, tunes detection and investigates incidents in the context of your environment, with evidence your team can review.
Parsers map logs to common fields such as source IP, user, host and event category for cross-system queries and correlation.
Select and tune Sigma rules for the logs your organization provides. Review detection logic and known false positives in the Rules Catalog, then map enabled rules to MITRE ATT&CK techniques.
Match events against IOCs and use newly available intelligence to search retained logs, within each indicator’s validity window.
Query, filter and join events, alerts, cases and assets when testing hunting hypotheses.
Connect alerts with raw events, timelines, notes and tasks. See who investigated, why decisions were made and what remains open.
Review incidents, detection coverage, log-source health and remediation backlogs, with practical recommendations under the selected plan.
The AI Assistant helps explain alerts, retrieve threat context and draft material for review, allowing analysts to focus on risk and the response plan.
AI Assistant: Business and above · Cloud SOAR: Growth and aboveAI runbooks gather and correlate evidence with findings and traces for analyst review. For this optional capability, processing infrastructure, data scope, licensing and run allowances are agreed separately.
Add asset, vulnerability and security-coverage context from connected data to prioritize investigation. Scope depends on the selected connectors and module.
04 / CONTROLLED RESPONSE
Separate log collection from firewall-policy changes so network and security teams can review permissions and operational impact.
Send FortiGate logs to an internal Syslog forwarder, then forward them to the SOC over TLS with an intake key.
FortiGate exposes connector actions for creating addresses and address groups, and disabling local users. FortiManager orchestration can be designed as a custom API integration.
05 / SOC + THREAT INTELLIGENCE + EASM
Blue Team uses EASM to discover exposed assets and Threat Intelligence to track data leaks and relevant threats. We connect these findings with SOC logs to investigate risks from both outside and inside your environment.
Validate assets · Check relevance
Connect indicators and impact
Agree on assets, monitoring terms, feed sources and review frequency before onboarding. Source coverage depends on access rights and the selected scope; Premium Threat Intelligence Feed follows the plan comparison. Active testing is limited to authorized assets.
Configuration work such as MFA, EDR, hardening and secret management, licenses and active testing are scoped in the proposal, with owners and verification evidence.
06 / REAL-WORLD DETECTION USE CASES
Build use cases around your assets and relevant threats. Define required logs, detection conditions and response actions, then tune rules to reduce noise.
Correlate WAF and access logs for suspicious requests, injection attempts and web-shell indicators alongside legitimate application behavior.
Connect failed logins, MFA, privilege changes and sessions to distinguish brute force from behavior needing further investigation.
Inspect process lineage, execution and abnormal file activity. Coordinate host isolation using EDR evidence and approved authority.
Connect DNS, network flows and authentication to investigate unusual host-to-host connections and command-and-control indicators.
Track IAM, cloud audit events and storage-policy changes, linking exposed assets to data risk.
Use threat context and MITRE ATT&CK to form hypotheses, search evidence and improve enterprise detections and playbooks.
Reference frameworks: MITRE ATT&CK · NIST SP 800-61r3 for mapping and process design; not a guarantee of detecting every threat.
07 / ENTERPRISE ASSURANCE
Bring Security, Risk and leadership onto the same page: data boundaries, decision authority and incident deliverables.
Agree log sources, daily volume, retention, residency and export. Separate customer data and define role-based access for each team.
Define severity, escalation and approvers. Specify automated versus approval-required actions, with verification and rollback procedures.
Separate technical findings from executive summaries. Track backlog and detection quality with assessment evidence at the selected plan level.
08 / MEET RUK-COM BLUE
Meet the team to review your environment, discuss risk and shape the service scope at Vanit Place Ari, 27th floor.

Building A · Suite 2703 · 27th floor
304 Phahonyothin Road, Samsen Nai, Phaya Thai, Bangkok 10400
Meetings by appointment09 / RUK-COM BLUE / SERVICE PLANS
Every plan includes 24×7 SIEM monitoring. Analyst coverage and response SLAs vary. Choose by asset count, response requirements and the depth of service you need.
AI Assistant: Business and above
Cloud SOAR: Growth and above
Annual contract value = monthly rate × 12
For Small Business
฿99,000/ month
฿1,188,000 / 12-month contract
Approximately ฿990 / asset / month*
Core monitoring with 8×5 analyst triage
Request a quote Small BusinessFor Small Business/Medium Business
฿149,000/ month
฿1,788,000 / 12-month contract
Approximately ฿596 / asset / month*
Adds AI Assistant and 30-day hot storage
Request a quote BusinessFor Growing Companies
฿349,000/ month
฿4,188,000 / 12-month contract
Approximately ฿349 / asset / month*
24×7 Tier 1 triage with Cloud SOAR
Request a quote GrowthFor Mid-Market
฿849,000/ month
฿10,188,000 / 12-month contract
Approximately ฿283 / asset / month*
24×7 on-call Tier 2 and monthly threat hunting
Request a quote Mid-MarketFor Large Enterprises
฿1,990,000/ month
฿23,880,000 / 12-month contract
Approximately ฿199 / asset / month*
Dedicated 24×7 analysts, TAM and WAR room
Request a quote EnterpriseScroll horizontally to compare all five plans
| Service scope | Small Business | Business | Growth | Mid-Market | Enterprise |
|---|---|---|---|---|---|
| Pricing & asset allocation | |||||
| Monthly price (THB) | 99,000 | 149,000 | 349,000 | 849,000 | 1,990,000 |
| Annual contract value (THB) | 1,188,000 | 1,788,000 | 4,188,000 | 10,188,000 | 23,880,000 |
| Assets included (up to) | 100 | 250 | 1,000 | 3,000 | 10,000 |
| Approx. effective price / asset / month (THB)* | 990 | 596 | 349 | 283 | 199 |
| Core service | |||||
| 24×7 SIEM monitoring | Included | Included | Included | Included | Included |
| Asset Discovery | Included | Included | Included | Included | Included |
| Verified Detection Rules | Included | Included | Included | Included | Included |
| CTI-Enriched Alerts | Included | Included | Included | Included | Included |
| Endpoint Agent included | Included | Included | Included | Included | Included |
| AI Assistant | Not included | Included | Included | Included | Included |
| 30-Day Hot Storage | Not included | Included | Included | Included | Included |
| Log Storage Extension 2GB (2 months) | Not included | Not included | Included | Included | Included |
| Cloud SOAR (Approved Playbooks) | Not included | Not included | Included | Included | Included |
| Human SOC analyst coverage | |||||
| Tier 1 alert triage | 8×5 | 8×5 | 24×7 | 24×7 | 24×7 dedicated |
| Tier 2 incident handling | Email only | Email only | Business hr | 24×7 on-call | 24×7 dedicated |
| Response SLA — P1 critical | < 8 hours | < 8 hours | < 4 hours | < 1 hour | < 30 minutes |
| Response SLA — P2 high | < 24 hours | < 24 hours | < 8 hours | < 4 hours | < 1 hour |
| Threat hunting | Not included | Not included | Quarterly | Monthly | Weekly |
| Customization & reporting | |||||
| Custom detection rules | Not included | Not included | Up to 10 | Up to 50 | Unlimited |
| Custom IoC collections | Not included | Not included | 100k | 500k | 5m |
| Custom SOAR playbooks | Not included | Not included | Up to 3 | Up to 10 | Unlimited |
| Reporting cadence | Monthly | Monthly | Monthly | Bi-weekly | Real-time + Weekly |
| Executive dashboard | Not included | Not included | Standard | Customized | Real-time, branded |
| Compliance reports (PDPA/ISO) | Basic | Basic | Standard | Advanced | Audit-ready |
| Account management & support | |||||
| Onboarding & integration | 4–6 weeks (self-guided) | 4–6 weeks (self-guided) | 6–10 weeks (guided) | 10–16 weeks (full PS) | 16–24 weeks (white-glove) |
| Dedicated account manager | Not included | Not included | Shared | Included | Yes + TAM |
| Support channel | Email + Chat | Phone 24×7 | Phone 24×7 + WAR room | ||
| Quarterly business review | Not included | Not included | Not included | Included | Yes (executive) |
| Premium threat intel feed | Not included | Not included | Not included | Optional | Included |
| AI Incident Management | Not included | Not included | Not included | Optional | Included |
| Best for | |||||
| Ideal customer profile | SMB: 20–50 employees, low compliance burden, basic security needs | SMB: 50–300 employees, low compliance burden, basic security needs | Mid-market: 300–1,500 employees, regulated industry (finance/healthcare), needs reliable 24×7 | Large mid-market / mature security org: 1,500–5,000 employees, dedicated security team | Enterprise: 5,000+ employees, multi-site/global, strict SLA, regulatory + audit needs |
| Discuss your scope | Request a quote Small Business | Request a quote Business | Request a quote Growth | Request a quote Mid-Market | Request a quote Enterprise |
*Effective per-asset rates assume the full included asset allocation and are approximate. They are not standalone per-asset prices.
Prices are in THB and exclude 7% VAT. Annual contract values cover 12 months; no annual discount is shown. Confirm terms in the quotation.
Agree asset definitions, log sources, EASM scope, data volume and retention before onboarding. Table SLAs are response targets, not guaranteed incident resolution times; confirm coverage windows, SLA measurement and response authority in the contract.
10 / FROM SCOPE TO OPERATIONS
Review assets, logs, SLAs and business priorities.
Connect systems and validate data quality and permissions.
Validate detections and exercise playbooks together.
Investigate, review results and improve operations.
Plan onboarding ranges from 4–24 weeks, depending on integrations and organizational readiness.
BEFORE WE BEGIN
YOUR ENVIRONMENT. OUR BLUE TEAM.
Start with your assets, logs and the level of coverage you need.