EXTERNAL VISIBILITY. ACTIONABLE INTELLIGENCE.

Threat Intel + EASM.
One platform. Clearer risk.

Ruk-Com Attack Surface & Threat Intelligence

Ruk-Com combines external asset discovery, leak monitoring and threat intelligence, with AI-assisted context and prioritization plus one dashboard to track action.

Asset ownershipAnalyst validationActionable report
Ruk-Com Cloud — Credential Leaks, Source Code Leaks, EASM, Lookalike Domains, Dark Web Mentions, CVE Monitoring
Monitor credential and source code leaks, external attack surface, lookalike domains, dark web mentions and CVEs.View full-size image ↗
01

EASM

Discover external assets, find blind spots and establish ownership.

02

Threat Intelligence

Connect relevant signals with source, timing and confidence.

03

Unified Platform

Search, manage tickets, send alerts and report from one workspace, with scoped handoffs to security or SOC teams.

ONE PLATFORM. CONNECTED INTELLIGENCE.

From external signals to actionable risk

Define what to monitor, connect sources with AI and bring findings into one workspace for your security team.

Ruk-Com CloudTHREAT INTELLIGENCE + EASM
01 · Define scope

Your organization

Thai and English keywords, with an asset scope confirmed by your organization.

  • Domain
  • Email
  • Brand
  • Product
  • IP range
02 · Collect signals

Multiple data sources

  • Surface webPublic websites and internet-facing services
  • Deep & Dark webDeep web sources and threat monitoring spaces
  • Code repositoriesGitHub · GitLab · Postman
  • Security intelligenceCVE · NVD · KEV · IOC
  • Social & open sourcesPublic information and organizational mentions
03 · Analyze and correlate

AI Intelligence Engine

  • Entity recognitionIdentify relevant entities and assets
  • CorrelationConnect signals across sources
  • Risk prioritizationScore and prioritize risk
  • Context enrichmentEnrich findings with context
  • Anomaly detectionIdentify anomalies for investigation
04 · Review in one place

Unified Exposures

A consolidated risk dashboard with search, filters and supporting evidence for each finding.

EASMThreat Intelligence
05 · Turn findings into action

Act with the context you need

  • Ticket managementTrack status and follow-up
  • Email alertsReceive relevant notifications
  • PDF / ExcelReports for review and communication
Arrows show the flow of data and analysis. Teams review evidence and decide on action within the agreed service scope.

SIX MONITORING SERVICES

Threat Intel and EASM.
One platform, six monitoring services.

Register Thai or English keywords for your organization, domains, emails, IPs and products. Monitor on an agreed schedule, normalize findings across services and retain a searchable history.

Credential Leaks01

Find exposed accounts and access data

Monitor relevant emails, user accounts, passwords or hashes and infostealer signals so identity teams can assess impact and plan resets or revocation.

  • Related accounts and login URLs; cookies, access tokens or infected-device context when available
  • Source, exposure date and detection date help distinguish new leaks from resurfaced data
  • Mask sensitive data in the UI and reports; do not test discovered credentials by logging in
Source Code Leaks02

Find exposed secrets in public repositories

Monitor project names, repositories and public content on GitHub, GitLab and Postman for relevant source code, API keys, tokens, passwords and configuration.

  • Identify the exposed data type, repository, URL, file and line location
  • Record publication and detection times, with AI-assisted classification and severity assessment
  • Help development teams revoke or rotate secrets and review permissions before cleaning repository history
External Attack Surface Management03

Discover and maintain your external inventory

Discover domains, subdomains, IPs, ports, services and technologies related to your scope, then maintain an asset inventory for exposure and change tracking.

  • Identify web services, products and versions; verify ownership before assigning assets to the organization
  • Review open ports, insecure configurations and vulnerabilities relevant to discovered technology
  • Retain monitoring history to review newly discovered, changed and remediated exposure
Lookalike Domains04

Spot lookalike domains and brand impersonation

Discover domains that resemble your organization and review their use and context to distinguish name similarity from phishing or impersonation risks.

  • Review similarity patterns and level, website status and screenshots
  • Inspect IP, country, hosting, registrar and registration or expiry dates when available
  • Support takedown coordination within evidence, authorization and service scope; outcomes depend on the receiving provider
Dark Web Mentions05

Put underground mentions into context

Track agreed organization names, brands, domains, products and key people across authorized, accessible forums, marketplaces, leak sites and underground channels.

  • Preserve matched keywords, content and context alongside the originating site or channel
  • Include author, detection time, evidence and severity when available
  • Use mentions as signals for validation; a mention alone does not establish a data breach
CVE Monitoring06

Match vulnerabilities to your technology

Track CVEs affecting products, vendors and versions in your asset inventory to guide patch prioritization and review of critical systems.

  • CVE identifier, description, severity, affected products and versions
  • Known exploitation context from CISA KEV, with CVE/NVD and vendor advisory references
  • Prioritize using exposure and business impact; a product-name match alone does not confirm impact

CYBER NEWS & THREAT INTELLIGENCE

Threat intelligence your team can put to work.

Four intelligence views complement organization-specific monitoring, from threat trends to indicators and vulnerabilities that merit review.

01

Dark Web News

Follow relevant news and discussions about data trading, cyberattacks and threat actors to identify emerging trends.

News and event context
02

Threat Insight · CTI

Explore threat actors and TTPs with MITRE ATT&CK context to support industry risk assessment, threat hunting and incident response.

Actor behavior and techniques
03

IOC Feed

Use threat-related IPs, domains, URLs and hashes to inform detection in SIEM, EDR or firewalls, subject to the receiving system’s supported formats.

Indicators for detection
04

CVE Feed

Track new CVEs, severity and KEV status globally, then use CVE Monitoring to determine relevance to your assets.

Vulnerability context and priority

IOC feeds provide intelligence for downstream use. Integrations and automated blocking require separate configuration and authorization.

FROM SIGNAL TO VERIFIED ACTION

Follow a signal
to accountable action.

Choose a scenario to inspect its evidence and workflow. This simulation does not scan systems or transmit real data.

SIMULATED EXAMPLEIntelligence → Action
Recommended response path · SimulatedAn admin interface outside inventory
View evidence ↓
InternetDNS · TLS · Port · Web
Public RepoSecret / Configuration
Dark Web / Data LeakCredentials · Paste · Infostealer
  1. 01
    CollectionCollect within scope

    Record source and observed time

  2. 02
    Normalize / DeduplicateNormalize and deduplicate

    Preserve freshness and provenance

  3. 03
    Asset correlationMatch organizational assets

    Check ownership and business impact

  4. 04
    Analyst validationReview and validate evidence

    Set confidence and investigation needs

  5. 05
    Owner / SOC actionRoute to accountable owners

    Remediate or investigate within permissions

  6. 06
    Verification feedbackRecheck and update inventory

    Record outcomes and residual risk

Inventory & Watchlists

Update verified status and evidence → use as the next monitoring baseline

BASELINE UPDATE
① Observation · Collected signals② Analysis · Relevance and validation③ Response · Action and verification

SCENARIO EVIDENCE

An admin interface outside inventory

An admin interface on staging.example.com is visible from the internet. Confirm ownership and access restrictions before assessing risk.

Source
Internet observation (simulated)
Observed
2026-09-10 09:20 UTC
Confidence
Medium · Analyst review pending
Affected asset
staging.example.com
Masked evidence
HTTPS /admin · banner: [masked]
Owner
Infrastructure / Application owner
Synthetic evidence reference
OBS-1042 · staging.example.com/admin
Initial triage priority
Prompt review · Public admin may expose system access; access controls remain unverified
NEXT ACTION

Confirm ownership → restrict access under policy → recheck and record the result in inventory.

Arrows represent context and work handoffs, not data sent back to the dark web. Verification updates inventory and watchlists. All values are simulated.

EVIDENCE YOUR TEAM CAN USE

Evidence your team
can put to work.

Ruk-Com connects external intelligence with accountable teams so security, IT and leadership work from the same evidence.

EXPOSURE & INTELLIGENCE BRIEFSAMPLE DELIVERABLE
01
Asset inventory & ownership

Confirmed assets, candidates needing review and accountable owners.

02
Prioritized findings

Masked evidence, timestamps, sources, confidence and business impact.

03
Remediation & verification

Recommended actions, owners, recheck results and remaining risk.

ONE WORKSPACE. ACCOUNTABLE ACTION.

From scattered findings
to accountable work.

Unified Exposures gives teams a consistent format for executive visibility, detailed investigation and individual risk tracking.

Unified Dashboard

Review overall risk, work status, trends over time and distribution by service or severity in one view.

Intelligence Search

Search across services by keyword, email or domain and connect related findings and context.

Actionable Recommendations

Use risk-specific investigation and remediation guidance, with accountable teams making decisions within their context and authority.

Ticket Management

Track each item and its history so teams can hand off work, review outcomes and close findings with supporting evidence.

Exposure management lifecycle

  1. DetectedCreate an item with evidence
  2. PendingValidate context and assign a team
  3. Investigate / actSelect a risk-appropriate action
  4. Review / closeRecord rationale and review outcome

Classify outcomes as resolved, not a risk or not relevant before closure. Review new findings again when the context changes.

REPORTING, ALERTS & PLATFORM CONTROLS

Built for IT, security
and leadership.

A cloud-based platform combines alerts, reporting and access controls so each team receives the information it needs.

Email Alerts

Receive new-risk email alerts around the clock and configure daily, weekly, monthly, quarterly or annual summaries with designated recipients.

Executive PDF & Technical Excel

Executive PDFs summarize risk, trends and recommendations. Technical Excel reports provide details for IT and security teams, with configurable reporting schedules.

Report Management

Configure recipients and suppress duplicate or previously reported cases to focus on changes and progress.

MFA & User Management

Support multi-factor authentication, user creation, updates and removal, and permission-based access management.

Activity Log

Track user activity and system changes to support traceability and access reviews.

Sensitive Data Masking

Mask emails, passwords, IPs, tokens and API keys in the interface and reports to reduce sensitive-data exposure during collaboration.

Agree coverage, monitoring cadence, recipients, data access and response scope during onboarding. Continuous alerting does not guarantee detection of every threat or automatic remediation.

Ruk-Com Agent

Agent support across every service

Working with our specialists across Technology and Cyber Security: monitoring, anomaly analysis, planning and coordinated response.

Technology · Performance, capacity and operations

Cyber Security · Risk, vulnerabilities and threat monitoring

Data access, changes and support levels follow the permissions and service scope agreed with our team.

Meet Ruk-Com Agent

START WITH A CLEAR SCOPE

Start with what matters to your business.

01

Define scope

Share domains, brands, IP ranges and business units; identify critical assets, owners and assessment permissions.

02

Agree coverage and workflow

Agree sources, alerting, retention, masking, SOC handoffs and who executes each action.

03

Baseline and track changes

Review the initial inventory, triage findings and track remediation progress through rechecks.

A proposal tied to your actual scope

Scope and pricing reflect asset count and types, data sources, monitoring cadence and required analyst/response support. The team confirms cost and deliverables before onboarding.

Talk to our security team →

QUESTIONS BEFORE ONBOARDING

Before you get started.

Are threat intelligence and EASM part of the same platform?

Yes. EASM discovers and tracks external assets, while threat intelligence adds threat signals and context. Unified Exposures brings findings together for search, tickets, alerts and reporting in one workspace.

How does CVE Feed differ from CVE Monitoring?

CVE Feed provides broad visibility into new vulnerabilities and KEV status. CVE Monitoring relates this information to products and versions in your asset inventory before prioritizing action.

What reporting and access controls are available?

Executive PDF and technical Excel reports support recipients, schedules and duplicate-report suppression. Platform controls include MFA, user and permission management, activity logs and sensitive-data masking.

What does takedown support include?

Support includes evidence gathering and coordination for risky lookalike domains within the agreed scope. Authorization and supporting evidence are required; outcomes and timing depend on the registrar, hosting provider or other relevant parties.

How does this differ from vulnerability scanning or pentesting?

EASM discovers and tracks external exposure on an agreed cadence, while threat intelligence adds threat context. Active testing and deeper vulnerability validation require a separately authorized VA/pentest scope.

Do we need an agent on every machine?

External attack surface discovery starts from an outside view and does not require an endpoint agent on every machine. Additional log, SOC or internal data integration depends on agreed access and scope.

Does a credential signal confirm a breach?

No. Sources, timestamps, account ownership and context need review; data may be old or repeated. We do not attempt logins with discovered credentials. Reset, revocation, rotation and log review are considered as appropriate.

Does this cover the entire dark web?

Coverage depends on accessible, authorized sources. It does not guarantee detection of every source, leak or post. Source limitations and confidence are documented in analysis.

Does public repo monitoring include a code audit?

It focuses on relevant secret and exposure signals, rather than a full code audit. Revoke or rotate affected secrets, then address repository history and review impacted permissions.

Who remediates findings and how are they shared?

Owners, communication channels and permissions are agreed during onboarding. We share masked evidence and recommended actions. Production changes, SOC response and tooling integrations follow the agreed service scope.

MAKE EXTERNAL RISK VISIBLE

Start with your organization’s domain.
Let’s make the risks visible.

Bring your domains, brands and accountable teams to define an EASM & Threat Intel scope you can act on.