See your exposure
Internet · Dark Web · Public assets
EASM + AI-POWERED SECURITY OPERATIONS
Connect what attackers can see with what is happening inside your environment. EASM, SIEM and AI SOC, brought together by a Blue Team that investigates and responds with context.
EASM, threat intelligence and telemetry feed AI and SIEM. The Blue Team validates findings, responds, and feeds results back into defensive improvements.
Websites in our hosting service base
Daily log volume across hosting operations
Experience supporting Ruk-Com Hosting customers
THE CONNECTED BLUE TEAM
Visibility outside. Context inside.
Follow-through by Ruk-Com Blue.
Internet · Dark Web · Public assets
Endpoint · Identity · Cloud logs
Validate · Respond · Verify
Discover assets, correlate external feeds and validate organizational relevance. Prioritize findings by exploitability and business impact.
Collect and normalize logs, enrich them with threat intelligence, and use AI to group alerts and draft evidence-linked timelines for analyst review.
The Blue Team validates findings and coordinates with your team. Respond under approved playbooks and authority, verify remediation, and feed lessons back into defenses.
Conceptual service flow · AI, analyst coverage and response follow your plan and agreed scope
An illustrative defense scenario, not a customer incident.
An infostealer may steal credentials or session cookies from a user device before signals appear in corporate systems.
Feeds from stealer markets, the dark web and public sources can reveal signals associated with organizational accounts and assets.
An attacker may use a stolen account or session to access services. Authentication context and session validity both matter.
Correlate identity, endpoint and network logs so the Blue Team can investigate anomalies, assess impact and respond under a playbook.
Validate relevance and current exposure before responding. Consider credential resets, session revocation and secret rotation according to the affected data and systems.
Threat technique references MITRE T1078 · Valid Accounts · T1539 · Session Cookie Theft
01 / EXTERNAL ATTACK SURFACE MANAGEMENT
Connect internet, dark web and threat intelligence.
See what is exposed, what changed and what needs action.
Validate assets · Deduplicate
Correlate context and impact
Agree on assets, monitoring terms, feed sources and review frequency before onboarding. Source coverage depends on access rights and the selected scope; Premium Threat Intelligence Feed follows the plan comparison. Active testing is limited to authorized assets.
Configuration work such as MFA, EDR, hardening and secret management, licenses and active testing are scoped in the proposal, with owners and verification evidence.
02 / AI-ASSISTED SECURITY OPERATIONS
AI assists SIEM operations with enrichment, alert grouping and investigation drafts, helping the Blue Team focus on validation and decisions that matter.
Know your data sources
Endpoint · Firewall · WAFConnect events with context
Parser · Timestamp · Asset IDSummarize signals and evidence
Alert clustering · TimelineAct with defined authority
Analyst review · PlaybookROY: Business+
Cloud SOAR: Growth+
AI ASSISTS. BLUE TEAM DECIDES.
Query incidents and logs in natural language, connect indicators, build timelines and draft evidence-based recommendations. Analysts validate findings before confirming incidents and choosing a response.
Repeated failed logins followed by a success from a source requiring validation.
Link the system owner, asset criticality and IP context to support the decision.
03 / DETECTION ENGINEERING
Build use cases around your assets and relevant threats. Define required logs, detection conditions and response actions, then tune rules to reduce noise.
Correlate WAF and access logs for suspicious requests, injection attempts and web-shell indicators alongside legitimate application behavior.
Connect failed logins, MFA, privilege changes and sessions to distinguish brute force from behavior needing further investigation.
Inspect process lineage, execution and abnormal file activity. Coordinate host isolation using EDR evidence and approved authority.
Connect DNS, network flows and authentication to investigate unusual host-to-host connections and command-and-control indicators.
Track IAM, cloud audit events and storage-policy changes, linking exposed assets to data risk.
Use threat context and MITRE ATT&CK to form hypotheses, search evidence and improve enterprise detections and playbooks.
Reference frameworks: MITRE ATT&CK · NIST SP 800-61r3 for mapping and process design; not a guarantee of detecting every threat.
04 / ENTERPRISE ASSURANCE
Bring Security, Risk and leadership onto the same page: data boundaries, decision authority and incident deliverables.
Agree log sources, daily volume, retention, residency and export. Separate customer data and define role-based access for each team.
Define severity, escalation and approvers. Specify automated versus approval-required actions, with verification and rollback procedures.
Separate technical findings from executive summaries. Track backlog and detection quality with assessment evidence at the selected plan level.
05 / MEET RUK-COM BLUE
Meet the team to review your environment, discuss risk and shape the service scope at Vanit Place Ari, 27th floor.

Building A · Suite 2703 · 27th floor
304 Phahonyothin Road, Samsen Nai, Phaya Thai, Bangkok 10400
Meetings by appointment06 / RUK-COM BLUE / SERVICE PLANS
Every plan includes 24×7 Sekoia SIEM monitoring. Analyst coverage and response SLAs vary. Choose by asset count, response requirements and the depth of service you need.
AI Assistant (ROY): Business and above
Cloud SOAR: Growth and above
Annual contract value = monthly rate × 12
For Small Business
฿99,000/ month
฿1,188,000 / 12-month contract
Approximately ฿990 / asset / month*
Core monitoring with 8×5 analyst triage
Request a quote Small BusinessFor Small Business/Medium Business
฿149,000/ month
฿1,788,000 / 12-month contract
Approximately ฿596 / asset / month*
Adds AI Assistant and 30-day hot storage
Request a quote BusinessFor Growing Companies
฿349,000/ month
฿4,188,000 / 12-month contract
Approximately ฿349 / asset / month*
24×7 Tier 1 triage with Cloud SOAR
Request a quote GrowthFor Mid-Market
฿849,000/ month
฿10,188,000 / 12-month contract
Approximately ฿283 / asset / month*
24×7 on-call Tier 2 and monthly threat hunting
Request a quote Mid-MarketFor Large Enterprises
฿1,990,000/ month
฿23,880,000 / 12-month contract
Approximately ฿199 / asset / month*
Dedicated 24×7 analysts, TAM and WAR room
Request a quote EnterpriseScroll horizontally to compare all five plans
| Service scope | Small Business | Business | Growth | Mid-Market | Enterprise |
|---|---|---|---|---|---|
| Pricing & asset allocation | |||||
| Monthly price (THB) | 99,000 | 149,000 | 349,000 | 849,000 | 1,990,000 |
| Annual contract value (THB) | 1,188,000 | 1,788,000 | 4,188,000 | 10,188,000 | 23,880,000 |
| Assets included (up to) | 100 | 250 | 1,000 | 3,000 | 10,000 |
| Approx. effective price / asset / month (THB)* | 990 | 596 | 349 | 283 | 199 |
| Core service | |||||
| 24×7 Sekoia SIEM monitoring | Included | Included | Included | Included | Included |
| Asset Discovery (Sekoia) | Included | Included | Included | Included | Included |
| Verified Detection Rules | Included | Included | Included | Included | Included |
| CTI-Enriched Alerts | Included | Included | Included | Included | Included |
| Endpoint Agent included | Included | Included | Included | Included | Included |
| AI Assistant (ROY) | Not included | Included | Included | Included | Included |
| 30-Day Hot Storage | Not included | Included | Included | Included | Included |
| ExaLog 2GB extension (2 months) | Not included | Not included | Included | Included | Included |
| Cloud SOAR (auto response) | Not included | Not included | Included | Included | Included |
| Human SOC analyst coverage | |||||
| Tier 1 alert triage | 8×5 | 8×5 | 24×7 | 24×7 | 24×7 dedicated |
| Tier 2 incident handling | Email only | Email only | Business hr | 24×7 on-call | 24×7 dedicated |
| Response SLA — P1 critical | < 8 hours | < 8 hours | < 4 hours | < 1 hour | < 30 minutes |
| Response SLA — P2 high | < 24 hours | < 24 hours | < 8 hours | < 4 hours | < 1 hour |
| Threat hunting | Not included | Not included | Quarterly | Monthly | Weekly |
| Customization & reporting | |||||
| Custom detection rules | Not included | Not included | Up to 10 | Up to 50 | Unlimited |
| Custom IoC collections | Not included | Not included | 100k | 500k | 5m |
| Custom SOAR playbooks | Not included | Not included | Up to 3 | Up to 10 | Unlimited |
| Reporting cadence | Monthly | Monthly | Monthly | Bi-weekly | Real-time + Weekly |
| Executive dashboard | Not included | Not included | Standard | Customized | Real-time, branded |
| Compliance reports (PDPA/ISO) | Basic | Basic | Standard | Advanced | Audit-ready |
| Account management & support | |||||
| Onboarding & integration | 4–6 weeks (self-guided) | 4–6 weeks (self-guided) | 6–10 weeks (guided) | 10–16 weeks (full PS) | 16–24 weeks (white-glove) |
| Dedicated account manager | Not included | Not included | Shared | Included | Yes + TAM |
| Support channel | Email + Chat | Phone 24×7 | Phone 24×7 + WAR room | ||
| Quarterly business review | Not included | Not included | Not included | Included | Yes (executive) |
| Premium threat intel feed | Not included | Not included | Not included | Optional | Included |
| AI Incident Management (Prime) | Not included | Not included | Not included | Optional | Included |
| Best for | |||||
| Ideal customer profile | SMB: 20–50 employees, low compliance burden, basic security needs | SMB: 50–300 employees, low compliance burden, basic security needs | Mid-market: 300–1,500 employees, regulated industry (finance/healthcare), needs reliable 24×7 | Large mid-market / mature security org: 1,500–5,000 employees, dedicated security team | Enterprise: 5,000+ employees, multi-site/global, strict SLA, regulatory + audit needs |
| Discuss your scope | Request a quote Small Business | Request a quote Business | Request a quote Growth | Request a quote Mid-Market | Request a quote Enterprise |
*Effective per-asset rates assume the full included asset allocation and are approximate. They are not standalone per-asset prices.
Prices are in THB. Annual contract values cover 12 months; no annual discount is shown. Confirm taxes and terms in the quotation.
Agree asset definitions, log sources, EASM scope, data volume and retention before onboarding. Table SLAs are response targets, not guaranteed incident resolution times; confirm coverage windows, SLA measurement and response authority in the contract.
07 / FROM SCOPE TO OPERATIONS
Review assets, logs, SLAs and business priorities.
Connect systems and validate data quality and permissions.
Validate detections and exercise playbooks together.
Investigate, review results and improve operations.
Plan onboarding ranges from 4–24 weeks, depending on integrations and organizational readiness.
BEFORE WE BEGIN
YOUR ENVIRONMENT. OUR BLUE TEAM.
Start with your assets, logs and the level of coverage you need.