EASM
Discover external assets, find blind spots and establish ownership.
EXTERNAL VISIBILITY. ACTIONABLE INTELLIGENCE.
Ruk-Com Attack Surface & Threat Intelligence
Ruk-Com combines external asset discovery, leak monitoring and threat intelligence, with AI-assisted context and prioritization plus one dashboard to track action.

Discover external assets, find blind spots and establish ownership.
Connect relevant signals with source, timing and confidence.
Search, manage tickets, send alerts and report from one workspace, with scoped handoffs to security or SOC teams.
ONE PLATFORM. CONNECTED INTELLIGENCE.
Define what to monitor, connect sources with AI and bring findings into one workspace for your security team.
THREAT INTELLIGENCE + EASMThai and English keywords, with an asset scope confirmed by your organization.
A consolidated risk dashboard with search, filters and supporting evidence for each finding.
SIX MONITORING SERVICES
Register Thai or English keywords for your organization, domains, emails, IPs and products. Monitor on an agreed schedule, normalize findings across services and retain a searchable history.
Monitor relevant emails, user accounts, passwords or hashes and infostealer signals so identity teams can assess impact and plan resets or revocation.
Monitor project names, repositories and public content on GitHub, GitLab and Postman for relevant source code, API keys, tokens, passwords and configuration.
Discover domains, subdomains, IPs, ports, services and technologies related to your scope, then maintain an asset inventory for exposure and change tracking.
Discover domains that resemble your organization and review their use and context to distinguish name similarity from phishing or impersonation risks.
Track agreed organization names, brands, domains, products and key people across authorized, accessible forums, marketplaces, leak sites and underground channels.
Track CVEs affecting products, vendors and versions in your asset inventory to guide patch prioritization and review of critical systems.
CYBER NEWS & THREAT INTELLIGENCE
Four intelligence views complement organization-specific monitoring, from threat trends to indicators and vulnerabilities that merit review.
Follow relevant news and discussions about data trading, cyberattacks and threat actors to identify emerging trends.
News and event contextExplore threat actors and TTPs with MITRE ATT&CK context to support industry risk assessment, threat hunting and incident response.
Actor behavior and techniquesUse threat-related IPs, domains, URLs and hashes to inform detection in SIEM, EDR or firewalls, subject to the receiving system’s supported formats.
Indicators for detectionTrack new CVEs, severity and KEV status globally, then use CVE Monitoring to determine relevance to your assets.
Vulnerability context and priorityIOC feeds provide intelligence for downstream use. Integrations and automated blocking require separate configuration and authorization.
FROM SIGNAL TO VERIFIED ACTION
Choose a scenario to inspect its evidence and workflow. This simulation does not scan systems or transmit real data.
Record source and observed time
Preserve freshness and provenance
Check ownership and business impact
Set confidence and investigation needs
Remediate or investigate within permissions
Record outcomes and residual risk
Update verified status and evidence → use as the next monitoring baseline
SCENARIO EVIDENCE
An admin interface on staging.example.com is visible from the internet. Confirm ownership and access restrictions before assessing risk.
Confirm ownership → restrict access under policy → recheck and record the result in inventory.
Arrows represent context and work handoffs, not data sent back to the dark web. Verification updates inventory and watchlists. All values are simulated.
EVIDENCE YOUR TEAM CAN USE
Ruk-Com connects external intelligence with accountable teams so security, IT and leadership work from the same evidence.
Confirmed assets, candidates needing review and accountable owners.
Masked evidence, timestamps, sources, confidence and business impact.
Recommended actions, owners, recheck results and remaining risk.
ONE WORKSPACE. ACCOUNTABLE ACTION.
Unified Exposures gives teams a consistent format for executive visibility, detailed investigation and individual risk tracking.
Review overall risk, work status, trends over time and distribution by service or severity in one view.
Search across services by keyword, email or domain and connect related findings and context.
Use risk-specific investigation and remediation guidance, with accountable teams making decisions within their context and authority.
Track each item and its history so teams can hand off work, review outcomes and close findings with supporting evidence.
Classify outcomes as resolved, not a risk or not relevant before closure. Review new findings again when the context changes.
REPORTING, ALERTS & PLATFORM CONTROLS
A cloud-based platform combines alerts, reporting and access controls so each team receives the information it needs.
Receive new-risk email alerts around the clock and configure daily, weekly, monthly, quarterly or annual summaries with designated recipients.
Executive PDFs summarize risk, trends and recommendations. Technical Excel reports provide details for IT and security teams, with configurable reporting schedules.
Configure recipients and suppress duplicate or previously reported cases to focus on changes and progress.
Support multi-factor authentication, user creation, updates and removal, and permission-based access management.
Track user activity and system changes to support traceability and access reviews.
Mask emails, passwords, IPs, tokens and API keys in the interface and reports to reduce sensitive-data exposure during collaboration.
Agree coverage, monitoring cadence, recipients, data access and response scope during onboarding. Continuous alerting does not guarantee detection of every threat or automatic remediation.
Working with our specialists across Technology and Cyber Security: monitoring, anomaly analysis, planning and coordinated response.
Technology · Performance, capacity and operations
Cyber Security · Risk, vulnerabilities and threat monitoring
Data access, changes and support levels follow the permissions and service scope agreed with our team.
Meet Ruk-Com AgentSTART WITH A CLEAR SCOPE
Share domains, brands, IP ranges and business units; identify critical assets, owners and assessment permissions.
Agree sources, alerting, retention, masking, SOC handoffs and who executes each action.
Review the initial inventory, triage findings and track remediation progress through rechecks.
Scope and pricing reflect asset count and types, data sources, monitoring cadence and required analyst/response support. The team confirms cost and deliverables before onboarding.
QUESTIONS BEFORE ONBOARDING
Yes. EASM discovers and tracks external assets, while threat intelligence adds threat signals and context. Unified Exposures brings findings together for search, tickets, alerts and reporting in one workspace.
CVE Feed provides broad visibility into new vulnerabilities and KEV status. CVE Monitoring relates this information to products and versions in your asset inventory before prioritizing action.
Executive PDF and technical Excel reports support recipients, schedules and duplicate-report suppression. Platform controls include MFA, user and permission management, activity logs and sensitive-data masking.
Support includes evidence gathering and coordination for risky lookalike domains within the agreed scope. Authorization and supporting evidence are required; outcomes and timing depend on the registrar, hosting provider or other relevant parties.
EASM discovers and tracks external exposure on an agreed cadence, while threat intelligence adds threat context. Active testing and deeper vulnerability validation require a separately authorized VA/pentest scope.
External attack surface discovery starts from an outside view and does not require an endpoint agent on every machine. Additional log, SOC or internal data integration depends on agreed access and scope.
No. Sources, timestamps, account ownership and context need review; data may be old or repeated. We do not attempt logins with discovered credentials. Reset, revocation, rotation and log review are considered as appropriate.
Coverage depends on accessible, authorized sources. It does not guarantee detection of every source, leak or post. Source limitations and confidence are documented in analysis.
It focuses on relevant secret and exposure signals, rather than a full code audit. Revoke or rotate affected secrets, then address repository history and review impacted permissions.
Owners, communication channels and permissions are agreed during onboarding. We share masked evidence and recommended actions. Production changes, SOC response and tooling integrations follow the agreed service scope.
MAKE EXTERNAL RISK VISIBLE
Bring your domains, brands and accountable teams to define an EASM & Threat Intel scope you can act on.