Blue TeamBY RUK-COM

MANAGED SOC · DETECTION & RESPONSE

Your systems. Our focus.
A SOC ready to respond.

Bring firewall, endpoint, cloud and identity logs into a SIEM. Ruk-Com Blue investigates suspicious activity, assesses impact and coordinates response through procedures agreed with your organization.

Analyst-led investigation and follow-upWorking with your team through agreed response procedures
BLUE / INVESTIGATION DESK
ILLUSTRATIVE INCIDENT · SIMULATED DATA

From an alert to a defensible decision

P2
VPN / Firewall
Identity
Endpoint
Correlate events · Add CTI context
VPN login succeeds after repeated failuresNETWORK
Identity event linked to the same accountIDENTITY
Retrieve endpoint context for investigationENDPOINT
An analyst validates the incident

Compare timestamps, source IPs, users and assets. Review CTI and normal behavior, then confirm findings with the system owner.

Raw events · Timeline · Analyst notes
Act within the approved playbook

If confirmed, coordinate session revocation or endpoint isolation within the authorized scope and available integrations. Record verification in the case.

Approval · Action · Verify · Case update
AI assists investigation · Analysts own the decision
Connect your stackWork with the security stack you already own
Investigate with evidenceEvidence that makes the next step clear
Respond with controlCase ownership, approvals and verification

01 / CONNECTED SECURITY OPERATIONS

One investigation.
Context from across your environment.

Firewalls show connections. Identity reveals who accessed them. EDR provides endpoint behavior. We bring that context into a single investigation.

SOC REFERENCE ARCHITECTURE
Log / TelemetryThreat contextApproved response
01 / YOUR ENVIRONMENT

Your security stack

FortiGate
NGFW
Firewall
Secure Firewall
Endpoint · Identity
Cloud · SaaS · WAF
Logs and security events
02 / COLLECT

Collection layer

Syslog Forwarder
HTTPS / API
Cloud connectors

Choose the collection method supported by each product.

TLS · Intake key
03 / DETECT & INVESTIGATE
01NormalizeParse · Common event fields
02Detect & correlateSigma rules · IOC matching
MITRE ATT&CK mapping
Threat IntelligenceIOC + adversary context → Detection
03InvestigateEvent search · Timeline · Cases
04 / RUK-COM BLUE

SOC Analyst

  • Validate evidence and impact
  • Set severity and escalation
  • Coordinate with the asset owner
Check response authority

Respond within the organization’s approved playbook and scope.

Approved ResponseAnalyst → target system
Firewall actionEndpoint isolationIdentity actionSubject to connector capabilities and permissions
Action results and verification logs are recorded in the case for validation and follow-up. Illustrative architecture.
Log source health

Monitor collection gaps and validate timestamps and parsers so detection uses reliable input.

Least-privilege access

Separate collection credentials from response accounts and scope permissions to the task.

Evidence first

Keep source-event references, decision rationale and verification results in the case.

02 / INTEGRATIONS

Connect the tools
your team already uses.

Start with your existing security stack. Validate connectors and real log samples before designing detection and response.

FortiGate

Traffic · VPN · Security logs

Log / Event intake

Palo Alto NGFW

Traffic · Threat · System logs

Log / Event intake

Check Point

Firewall · Security events

Log / Event intake

Cisco Secure Firewall

Firewall · Intrusion events

Log / Event intake

Sophos Firewall

Firewall · Network security

Log / Event intake

CrowdStrike Falcon

Endpoint · Detection events

Log / Event intake

SentinelOne

Endpoint · Threat events

Log / Event intake

Defender XDR · Entra ID

Endpoint · Sign-in · Audit

Log / Event intake

AWS CloudTrail · GuardDuty

Cloud activity · Findings

Log / Event intake

Google Cloud Audit Logs

Cloud administration · Access

Log / Event intake

Cloudflare WAF

Web application security

Log / Event intake

Veeam Backup

Backup · Infrastructure events

Log / Event intake

Have an internal system? Let’s scope a custom integration.

We assess Syslog, HTTPS, APIs and event formats, then scope parsers, field mapping and the detection use cases you need.

Discuss your environment

03 / DETECT · HUNT · INVESTIGATE

Detect threats.
Give your team the evidence.

Ruk-Com Blue designs use cases, tunes detection and investigates incidents in the context of your environment, with evidence your team can review.

Normalized events

Events from different products, in a common format

Parsers map logs to common fields such as source IP, user, host and event category for cross-system queries and correlation.

Detection engineering

Detection built around your risks

Select and tune Sigma rules for the logs your organization provides. Review detection logic and known false positives in the Rules Catalog, then map enabled rules to MITRE ATT&CK techniques.

CTI & retrohunt

New intelligence can reveal past activity

Match events against IOCs and use newly available intelligence to search retained logs, within each indicator’s validity window.

Advanced threat hunting

Investigate beyond the alert queue

Query, filter and join events, alerts, cases and assets when testing hunting hypotheses.

Case management

An incident record your team can follow

Connect alerts with raw events, timelines, notes and tasks. See who investigated, why decisions were made and what remains open.

Service reporting

Reporting that drives operational decisions

Review incidents, detection coverage, log-source health and remediation backlogs, with practical recommendations under the selected plan.

AI + HUMAN EXPERTISE

AI helps investigate. Analysts validate the decision.

The AI Assistant helps explain alerts, retrieve threat context and draft material for review, allowing analysts to focus on risk and the response plan.

AI Assistant: Business and above · Cloud SOAR: Growth and above
Add AI investigation and asset intelligenceScoped separately
AI investigation agents

AI runbooks gather and correlate evidence with findings and traces for analyst review. For this optional capability, processing infrastructure, data scope, licensing and run allowances are agreed separately.

Asset intelligence

Add asset, vulnerability and security-coverage context from connected data to prioritize investigation. Scope depends on the selected connectors and module.

04 / CONTROLLED RESPONSE

How Fortinet connects.
Who authorizes a change.

Separate log collection from firewall-policy changes so network and security teams can review permissions and operational impact.

NATIVE LOG INTAKE

FortiGate → Ruk-Com SOC

Send FortiGate logs to an internal Syslog forwarder, then forward them to the SOC over TLS with an intake key.

  • Traffic · VPN · Security events
  • Choose log types and validate field mapping
  • Check buffering, timestamps and collection health
RESPONSE / SCOPED ACTIONS

Native actions and custom APIs

FortiGate exposes connector actions for creating addresses and address groups, and disabling local users. FortiManager orchestration can be designed as a custom API integration.

Creating an address object alone does not block traffic. A policy must reference it, be deployed and be verified.
FORTIMANAGER / CUSTOM API REFERENCE FLOW
01Analyst approvalConfirm incident and response authority
02SOAR playbookAction → on-prem runner
03FortiManager APIHTTPS / JSON-RPC
Scoped ADOM / Policy
04FortiGate policyCommit / install per workflow
05Verify & recordCheck task, policy and logs; update the case
Reference design for assessment, not a native FortiManager connector. An on-premises runner executes actions inside the network with scoped API permissions and a rollback plan.

05 / SOC + THREAT INTELLIGENCE + EASM

Beyond SOC.
Threat Intelligence + EASM.

Blue Team uses EASM to discover exposed assets and Threat Intelligence to track data leaks and relevant threats. We connect these findings with SOC logs to investigate risks from both outside and inside your environment.

EASM + THREAT INTELLIGENCE → SOC
Internet exposureDomain · DNS · IP · Certificate
Track domains, DNS, certificates, IPs and public services. Discover shadow IT and changes to assets owned by your organization.
Dark Web & MarketsMarkets · Forums · Leak signals
Receive feeds covering stealer markets, the dark web and underground forums. Investigate credential-exposure signals associated with your organization, domains and email accounts.
Open Web & OSINTBrand · Public code · Exposed data
Monitor public websites, repositories and paste sites for exposed secrets or API keys and brand impersonation. Route findings to system owners for validation.
Global intelligence feedsIoC · CVE · Malware · TTP
Combine indicators, malicious IPs and domains, malware, CVEs and adversary behavior from multiple intelligence sources to enrich SIEM detections.
EASM + THREAT INTEL

Threat context for your organization

Validate assets · Check relevance
Connect indicators and impact

READY FOR ACTION
Asset inventoryKnow scope and ownership
Prioritized exposureKnow what to fix first
Threat context for SOCConnect external threats with internal logs
Data-source coverage and validation scope

Agree on assets, monitoring terms, feed sources and review frequency before onboarding. Source coverage depends on access rights and the selected scope; Premium Threat Intelligence Feed follows the plan comparison. Active testing is limited to authorized assets.

Configuration work such as MFA, EDR, hardening and secret management, licenses and active testing are scoped in the proposal, with owners and verification evidence.

06 / REAL-WORLD DETECTION USE CASES

Detect what matters.
For the systems you protect.

Build use cases around your assets and relevant threats. Define required logs, detection conditions and response actions, then tune rules to reduce noise.

WEB & API

Web & API attacks

Correlate WAF and access logs for suspicious requests, injection attempts and web-shell indicators alongside legitimate application behavior.

WAF · HTTP · Application
IDENTITY

Identity & privilege abuse

Connect failed logins, MFA, privilege changes and sessions to distinguish brute force from behavior needing further investigation.

IdP · Authentication · Audit
ENDPOINT

Ransomware & endpoint threats

Inspect process lineage, execution and abnormal file activity. Coordinate host isolation using EDR evidence and approved authority.

EDR · Process · File activity
NETWORK

Lateral movement & C2

Connect DNS, network flows and authentication to investigate unusual host-to-host connections and command-and-control indicators.

DNS · Flow · Authentication
CLOUD

Cloud & data exposure

Track IAM, cloud audit events and storage-policy changes, linking exposed assets to data risk.

Cloud audit · IAM · Storage
THREAT HUNTING

Hypothesis-led threat hunting

Use threat context and MITRE ATT&CK to form hypotheses, search evidence and improve enterprise detections and playbooks.

Hypothesis · Evidence · Detection tuning

Reference frameworks: MITRE ATT&CK · NIST SP 800-61r3 for mapping and process design; not a guarantee of detecting every threat.

07 / ENTERPRISE ASSURANCE

Know what happened.
Who owns it. What comes next.

Bring Security, Risk and leadership onto the same page: data boundaries, decision authority and incident deliverables.

BLUE / SERVICE EVIDENCE
CASE
REVIEW

Incident, evidence and action records.

  • Incident timeline and impact assessment
  • Evidence references and investigation findings
  • Approvals and response actions
  • Remediation and follow-up
01

Defined data boundaries

Agree log sources, daily volume, retention, residency and export. Separate customer data and define role-based access for each team.

02

Response under your control

Define severity, escalation and approvers. Specify automated versus approval-required actions, with verification and rollback procedures.

03

Reporting that supports decisions

Separate technical findings from executive summaries. Track backlog and detection quality with assessment evidence at the selected plan level.

08 / MEET RUK-COM BLUE

A team you can meet.
In the heart of Bangkok.

Meet the team to review your environment, discuss risk and shape the service scope at Vanit Place Ari, 27th floor.

Vanit Place Ari, Bangkok
27FLOOR
RUK-COM TECHNOLOGYVanit Place Ari

Building A · Suite 2703 · 27th floor

View map

304 Phahonyothin Road, Samsen Nai, Phaya Thai, Bangkok 10400

Meetings by appointment

09 / RUK-COM BLUE / SERVICE PLANS

Match your SOC coverage to your organization’s risk

Every plan includes 24×7 SIEM monitoring. Analyst coverage and response SLAs vary. Choose by asset count, response requirements and the depth of service you need.

AI Assistant: Business and above

Cloud SOAR: Growth and above

Annual contract value = monthly rate × 12

For Small Business

Small Business

฿99,000/ month

฿1,188,000 / 12-month contract

100assets included, up to

Approximately ฿990 / asset / month*

Core monitoring with 8×5 analyst triage

Request a quote Small Business

For Small Business/Medium Business

Business

฿149,000/ month

฿1,788,000 / 12-month contract

250assets included, up to

Approximately ฿596 / asset / month*

Adds AI Assistant and 30-day hot storage

Request a quote Business

For Growing Companies

Growth

฿349,000/ month

฿4,188,000 / 12-month contract

1,000assets included, up to

Approximately ฿349 / asset / month*

24×7 Tier 1 triage with Cloud SOAR

Request a quote Growth

For Mid-Market

Mid-Market

฿849,000/ month

฿10,188,000 / 12-month contract

3,000assets included, up to

Approximately ฿283 / asset / month*

24×7 on-call Tier 2 and monthly threat hunting

Request a quote Mid-Market

For Large Enterprises

Enterprise

฿1,990,000/ month

฿23,880,000 / 12-month contract

10,000assets included, up to

Approximately ฿199 / asset / month*

Dedicated 24×7 analysts, TAM and WAR room

Request a quote Enterprise

Compare the complete service scope

Scroll horizontally to compare all five plans

Ruk-Com Blue SOC pricing and service coverage — five-plan comparison
Service scopeSmall BusinessBusinessGrowthMid-MarketEnterprise
Pricing & asset allocation
Monthly price (THB)99,000149,000349,000849,0001,990,000
Annual contract value (THB)1,188,0001,788,0004,188,00010,188,00023,880,000
Assets included (up to)1002501,0003,00010,000
Approx. effective price / asset / month (THB)*990596349283199
Core service
24×7 SIEM monitoring Included Included Included Included Included
Asset Discovery Included Included Included Included Included
Verified Detection Rules Included Included Included Included Included
CTI-Enriched Alerts Included Included Included Included Included
Endpoint Agent included Included Included Included Included Included
AI Assistant Not included Included Included Included Included
30-Day Hot Storage Not included Included Included Included Included
Log Storage Extension 2GB (2 months) Not included Not included Included Included Included
Cloud SOAR (Approved Playbooks) Not included Not included Included Included Included
Human SOC analyst coverage
Tier 1 alert triage8×58×524×724×724×7 dedicated
Tier 2 incident handlingEmail onlyEmail onlyBusiness hr24×7 on-call24×7 dedicated
Response SLA — P1 critical< 8 hours< 8 hours< 4 hours< 1 hour< 30 minutes
Response SLA — P2 high< 24 hours< 24 hours< 8 hours< 4 hours< 1 hour
Threat hunting Not included Not includedQuarterlyMonthlyWeekly
Customization & reporting
Custom detection rules Not included Not includedUp to 10Up to 50Unlimited
Custom IoC collections Not included Not included100k500k5m
Custom SOAR playbooks Not included Not includedUp to 3Up to 10Unlimited
Reporting cadenceMonthlyMonthlyMonthlyBi-weeklyReal-time + Weekly
Executive dashboard Not included Not includedStandardCustomizedReal-time, branded
Compliance reports (PDPA/ISO)BasicBasicStandardAdvancedAudit-ready
Account management & support
Onboarding & integration4–6 weeks (self-guided)4–6 weeks (self-guided)6–10 weeks (guided)10–16 weeks (full PS)16–24 weeks (white-glove)
Dedicated account manager Not included Not includedShared IncludedYes + TAM
Support channelEmailEmailEmail + ChatPhone 24×7Phone 24×7 + WAR room
Quarterly business review Not included Not included Not included IncludedYes (executive)
Premium threat intel feed Not included Not included Not includedOptionalIncluded
AI Incident Management Not included Not included Not includedOptionalIncluded
Best for
Ideal customer profileSMB: 20–50 employees, low compliance burden, basic security needsSMB: 50–300 employees, low compliance burden, basic security needsMid-market: 300–1,500 employees, regulated industry (finance/healthcare), needs reliable 24×7Large mid-market / mature security org: 1,500–5,000 employees, dedicated security teamEnterprise: 5,000+ employees, multi-site/global, strict SLA, regulatory + audit needs
Discuss your scopeRequest a quote Small BusinessRequest a quote BusinessRequest a quote GrowthRequest a quote Mid-MarketRequest a quote Enterprise

*Effective per-asset rates assume the full included asset allocation and are approximate. They are not standalone per-asset prices.

Prices are in THB and exclude 7% VAT. Annual contract values cover 12 months; no annual discount is shown. Confirm terms in the quotation.

Agree asset definitions, log sources, EASM scope, data volume and retention before onboarding. Table SLAs are response targets, not guaranteed incident resolution times; confirm coverage windows, SLA measurement and response authority in the contract.

10 / FROM SCOPE TO OPERATIONS

Scope, connect and validate.
Then move into operations.

  1. 01

    Scope & size

    Review assets, logs, SLAs and business priorities.

  2. 02

    Connect & validate

    Connect systems and validate data quality and permissions.

  3. 03

    Tune & exercise

    Validate detections and exercise playbooks together.

  4. 04

    Operate & improve

    Investigate, review results and improve operations.

Plan onboarding ranges from 4–24 weeks, depending on integrations and organizational readiness.

BEFORE WE BEGIN

Before choosing
your security partner.

Can we keep our existing firewalls?
Our SOC service supports log integrations for FortiGate, Palo Alto NGFW, Check Point, Cisco Secure Firewall and other listed products. We validate versions, log types, licenses and collection methods. Log intake does not imply support for every response action.
Can FortiManager be connected?
A custom API integration can be assessed using JSON-RPC and an on-premises runner to manage objects and install policies within approved permissions. It must be tested against your version and workflow; this custom integration is scoped separately.
Where are logs stored and for how long?
Agree on the data region, hot and cold retention, access, export requirements and personal-data scope before onboarding. Retention follows the selected plan and agreed scope; the service does not imply that all data resides in a Thai datacenter.
How does EASM differ from VA and pentesting?
EASM continuously tracks internet-facing assets and changes. VA assesses vulnerabilities; pentesting validates attack paths within authorized scope. Discovery, scanning and deeper testing boundaries are agreed before work begins.
How does AI work with the SIEM and response?
AI helps group alerts, add context, correlate events and draft evidence-based summaries for analyst review. AI Assistant starts with Business; Cloud SOAR starts with Growth. IP blocking, host isolation and account actions follow approved playbooks and response authority.
Does 24/7 monitoring include 24/7 analysts in every plan?
SIEM monitoring runs 24/7 in every plan. Small Business and Business include 8×5 Tier 1; 24×7 Tier 1 starts with Growth. Tier 2, response SLAs and support channels vary by plan. Service hours, time zone and severity definitions are confirmed in the agreement.
Can you integrate existing systems and define log residency?
We inventory your SIEM, EDR, firewall, identity, cloud and applications, then validate connectors, data formats and required permissions. Ingestion, retention, data residency and access controls are agreed together. Integrations and licensing depend on the systems and selected plan.
Are the console figures real customer telemetry?
The diagrams and incident example use simulated data to explain investigation steps. They do not connect to logs or display real customer data.
How do we scope a project and calculate pricing?
Start with assets, log sources, data volumes, analyst coverage and data requirements. Compare the plans, then review integrations, SLAs, EASM scope and response authority with our team before quotation. Annual values shown equal twelve monthly payments.

YOUR ENVIRONMENT. OUR BLUE TEAM.

Put a Blue Team
behind your business.

Start with your assets, logs and the level of coverage you need.

Meet Ruk-Com Blue02-105-4385EASM · SIEM · AI SOC · BLUE TEAM