MANAGED SERVER SECURITY

Managed WAF
Protect every layer.
With a team behind it.

Bring together WAF, host firewall, malware scanning and CMS security with cPGuard. Ruk-Com helps configure policies, tune rules and verify changes for your server.

฿2,500/ Server / month

OS · web server · control panel and policy assessment before activation

RUK-COM / SECURITY STACKILLUSTRATION
WAF + Firewall Malware + CMS Managed review
01TRAFFICFirewall → ModSecurity
02SERVERFiles · CMS · Mail · Processes
03OPERATIONSReview → Tune → Verify
PROTECTION EXPLORER

See every layer.
Understand every step.

Choose a group and feature to see its input, inspection, decision and outcome. Traffic protection, file scanning and server operations each have their own flow.

01 / TRAFFIC PROTECTION

Allowed HTTPS

SIMULATED
Request / inputReturning responseStopped / deniedEvidence / analysisAction / verification
Internet → host firewall → TLS / ModSecurity → application → returning response

An allowed request passes the host firewall and ModSecurity before reaching the application. The response returns over the same transport path.

TLS terminates at the web server for this deployment; this is not a DNS-to-CDN service.

Illustrative flow only. No real attack, scan or data transfer is performed.

LAYER BY LAYER

Beyond the web request.
Down to the server itself.

Open each feature for its scope and flow. Activation depends on environment compatibility, supported modules and the policy agreed with our team.

01 / TRAFFIC PROTECTION

Stop threats before the application

Allowed HTTPS

An allowed request passes the host firewall and ModSecurity before reaching the application. The response returns over the same transport path.

TLS terminates at the web server for this deployment; this is not a DNS-to-CDN service.

HOW IT WORKS

  1. Internet → host firewall
  2. TLS / ModSecurity
  3. App → response
IP Reputation / IPDB

Use IP reputation intelligence to block matching sources at the OS firewall before the web server and record an event for review.

Review trusted-source allowlists before enabling IPDB.

HOW IT WORKS

  1. Internet
  2. Host firewall: deny
  3. Event → operator
Port · Protocol · Country

Configure IP, port, TCP/UDP and country rules for IPv4/IPv6, with temporary bans and reviewed allowlist precedence.

This example denies a source under a country rule; policies must match legitimate user locations.

HOW IT WORKS

  1. Internet
  2. Host firewall: deny
  3. Event → operator
SYN / Single-source DoS

Apply configured host firewall controls for SYN patterns and single-source DoS before traffic reaches the web server.

Host controls do not replace upstream scrubbing for attacks that saturate the network link.

HOW IT WORKS

  1. Internet
  2. Host firewall: deny
  3. Event → operator
Bad AI Bots

Use bot source intelligence in firewall rules to limit unwanted AI crawlers and review exceptions for crawlers the business needs.

Separate from HTTP User-Agent checks; identification cannot cover every bot.

HOW IT WORKS

  1. Internet
  2. Host firewall: deny
  3. Event → operator
SQL Injection / XSS

ModSecurity inspects requests for SQL injection and cross-site scripting patterns. A matching rule stops the request before the application and supplies a rule ID for false-positive review.

Application query handling and output encoding still need to be fixed.

HOW IT WORKS

  1. Internet → host firewall
  2. TLS / ModSecurity
  3. Deny → event
File Inclusion / Traversal

Inspect HTTP requests for local/remote file inclusion and suspicious path traversal patterns using applicable rules.

Coverage depends on rules and application context; this does not scan server files.

HOW IT WORKS

  1. Internet → host firewall
  2. TLS / ModSecurity
  3. Deny → event
Webshell / PHP Upload

Applicable WAF rules and upload scanning inspect PHP uploads or webshell patterns and block detected requests before application processing.

Upload scanning is an optional module requiring compatible web-server configuration; on-disk files are handled separately by the file scanner.

HOW IT WORKS

  1. Internet → host firewall
  2. TLS / ModSecurity
  3. Deny → event
Virtual Patching

Evaluate and test available vulnerability rules to filter exploit requests while planning the application update.

Does not promise coverage of every CVE or zero-day and does not replace software patches.

HOW IT WORKS

  1. Internet → host firewall
  2. TLS / ModSecurity
  3. Deny → event
Login CAPTCHA

Supported login protection can issue an external challenge. The web server validates the token and applicable rules before allowing application login processing; failed validation is denied.

Depends on the configured login module, supported login pages and external CAPTCHA provider.

HOW IT WORKS

  1. Login
  2. External challenge
  3. Validate token & rules
  4. App authenticates login
Brute Force / Bad User-Agent

Detect repeated login attempts and unwanted User-Agent patterns with supported modules, then apply denial or temporary bans under policy.

Review thresholds and exceptions; User-Agent alone does not authenticate a bot.

HOW IT WORKS

  1. Internet → host firewall
  2. TLS / ModSecurity
  3. Deny → event

02 / MALWARE & CMS

Inspect files and maintain the CMS

Real-time Malware Scan

Watch for new or modified files in selected webroots and send them to the scanner independently of incoming HTTP traffic.

Real-time coverage follows configured watch paths and exclusions.

HOW IT WORKS

  1. Changed webroot file
  2. Watchlist + Scanner
  3. Detection → policy review
  4. Handle & rescan
Signature + AI Detection

Combine signatures and AI-assisted detection, including team-defined custom signatures, to identify suspicious files and support handling decisions.

Findings may require operator confirmation; no scanner detects every malware variant.

HOW IT WORKS

  1. File in scan scope
  2. Signature / AI / Custom
  3. Review detections
  4. Policy-based decision
Manual / Daily / Weekly

Run manual, daily or weekly scans, including rescanning modified files with updated detection information.

Scan scope and schedule must fit file volume and server resources.

HOW IT WORKS

  1. Manual / Daily / Weekly
  2. Select scan candidates
  3. Scanner rechecks files
  4. Scan result report
Watchlists / Exclusions

Select watched webroots, apply narrow exclusions and review custom signatures against actual application behavior.

Excluded files fall outside configured checks; record and review the reason.

HOW IT WORKS

  1. Webroot inventory
  2. Review exclusions
  3. Apply Watchlist / Rules
  4. Verify scan scope
Cleanup / Core Replacement

After confirming infection, quarantine or clean according to module capability and policy. Supported CMS core files can be replaced with originals and rescanned.

Assess backup and application impact before file changes; cleanup is not automatically enabled for every account.

HOW IT WORKS

  1. Suspicious file
  2. Confirm with scanner
  3. Policy → isolate / repair
  4. Rescan & website check
WordPress Database Scan

Inspect WordPress database content for malware signals beyond filesystem files, then review findings before remediation.

Requires supported WordPress access. Runs with directory scans or optional daily scans; CLI results are not saved in the portal.

HOW IT WORKS

  1. WordPress database
  2. DB Malware Scanner
  3. Review flagged records
  4. Approved fix & recheck
CMS Vulnerability / Integrity

Check supported CMS components against vulnerability information and verify file integrity to distinguish updates from unexpected modifications.

A CVE match does not prove compromise; validate the version and context.

HOW IT WORKS

  1. CMS / Plugin / Theme
  2. CVE + Integrity Check
  3. Prioritize findings
  4. Update / repair plan
Controlled CMS Updates

Configure updates for supported CMS components under policy, with compatibility review, backup preparation and post-change website checks.

Updates follow agreed authorization and a rollback plan.

HOW IT WORKS

  1. Supported update list
  2. Review & backup
  3. Update under policy
  4. Test / rollback if needed

03 / SERVER & EMAIL

Watch what happens on the server

Safe Browsing / DNSBL

Monitor domain Safe Browsing status and IP DNSBL reputation so the team can investigate causes and plan remediation before requesting review.

Status monitoring does not guarantee delisting or inbox delivery.

HOW IT WORKS

  1. Domain / Server IP
  2. Safe Browsing / DNSBL
  3. Review listing & cause
  4. Remediate & recheck
Process / Miner Monitor

Inspect suspicious processes and potential crypto miners, identify the related account and route findings for policy-based handling.

Stopping processes or suspending accounts follows agreed policy.

HOW IT WORKS

  1. Server processes
  2. Process / Miner Monitor
  3. Review account & evidence
  4. Handle under policy
Lynis Security Audit

Use Lynis system auditing to identify hardening opportunities and prioritize recommendations for the server workload.

Findings are configuration recommendations, not compliance certification or automatic OS-wide changes.

HOW IT WORKS

  1. Linux configuration
  2. Lynis audit
  3. Review hardening
  4. Approved improvement plan
Outgoing Spam / Mail Queue

Monitor outgoing mail and the mail queue for spam behavior or queue anomalies, associate senders with accounts and handle under policy.

Requires a supported cPanel / DirectAdmin / Webuzo mail stack. OSM must be enabled and thresholds configured; separate from inbound SRBL.

HOW IT WORKS

  1. Outgoing mail queue
  2. Spam / queue monitor
  3. Review sender / account
  4. Policy-based queue action
Inbound SMTP / SRBL

Check incoming SMTP source IPs against configured RBLs so the mail server can accept or deny under policy; this example shows a listed source.

This is not HTTP WAF inspection and does not promise that every accepted email is spam-free.

HOW IT WORKS

  1. Incoming SMTP IP
  2. SRBL / RBL lookup
  3. Listed IP → deny
  4. Record SMTP decision
Cron Job Monitor

Inspect scheduled commands for suspicious patterns and identify the owning account before policy-based job handling.

Cron inspection is independent of web requests and must account for legitimate business jobs.

HOW IT WORKS

  1. Scheduled commands
  2. Cron job monitor
  3. Review job / owner
  4. Approved change & recheck
WordPress Cron Scheduling

Move supported wp-cron execution from page-load triggers to configured server schedules for more predictable job timing.

Verify WordPress scheduled tasks after the change to avoid missed business jobs.

HOW IT WORKS

  1. WordPress wp-cron
  2. Review jobs & timing
  3. Server cron schedule
  4. Verify job execution

04 / MANAGED OPERATIONS

Turn findings into accountable operations

Managed Rule Tuning

Review events and rule IDs against legitimate requests, scope exceptions narrowly, validate configuration/reload and test both business flows and retained protection.

Do not disable the entire WAF for a false positive; retain rationale and a rollback plan.

HOW IT WORKS

  1. Event & rule ID
  2. Analyst & app owner
  3. Narrow rule exception
  4. Verify / rollback plan
Central Dashboard / CLI

Bring findings and module status into a central dashboard, with on-server CLI tools for authorized administrators.

Dashboard logs are fetched from the server on demand with restricted access, not uploaded to central storage; CLI access is authorized.

HOW IT WORKS

  1. Module events / status
  2. Central dashboard
  3. Operator / authorized CLI
  4. Track & record outcomes
Event Hooks / Integrations

Use supported scanner event hooks to connect notifications or team workflows with appropriate permissions and event fields.

Integrations are optional and require destination and access review.

HOW IT WORKS

  1. Scanner event
  2. Supported event hook
  3. Authorized workflow
  4. Record event delivery
Reports / Email Digest

Summarize configured findings, events and policy changes in reports or email digests so teams can track completed work and follow-up items.

Recipients, reporting cadence and report scope are agreed for the service.

HOW IT WORKS

  1. Scan / security events
  2. Aggregate & review
  3. Report / email digest
  4. Track open follow-ups
Account Suspension Policy

When evidence meets agreed conditions, restrict or suspend an affected account under policy, verify the impact and plan service restoration.

This affects service availability; agree approval authority and restoration conditions in advance.

HOW IT WORKS

  1. Account-level evidence
  2. Check policy & approval
  3. Restrict / suspend account
  4. Verify & restore plan
THE MANAGED DIFFERENCE

Security tools need
operational judgment.

Ruk-Com turns findings into practical steps for your environment, from pre-activation rule review to verifying that each change works as intended.

01

Assess & baseline

Review OS, panel, web server, CMS and existing rules before selecting supported modules.

02

Activate under policy

Agree scan scope, exceptions, notifications and authorization for remediation.

03

Tune from evidence

Review false positives with the app owner and limit exceptions to necessary rules and context.

04

Verify & report

Validate configuration/reload, test business flows, prepare rollback and report open follow-ups.

Cleanup, quarantine, CMS updates, process termination and account suspension can affect production. Conditions and authorization are defined in the agreed policy before activation.

ONE SERVER. LAYERED PROTECTION.

Invest in protection.
Backed by our team.

For teams running business websites, WordPress and web servers who want traffic inspection and on-server risk checks within one operating approach.

RUK-COM MANAGED SERVICE

Managed WAF

฿2,500

/ Server / month

  • WAF and host firewall with supported modules
  • Malware, CMS and server checks under agreed scope
  • Policy configuration, rule tuning and verification
  • Compatibility assessment before activation
Share your server specifications

Ruk-Com service price per server per month. Confirm service scope, taxes and quotation terms with our team before starting.

Ruk-Com Agent

Agent support across every service

Working with our specialists across Technology and Cyber Security: monitoring, anomaly analysis, planning and coordinated response.

Technology · Performance, capacity and operations

Cyber Security · Risk, vulnerabilities and threat monitoring

Data access, changes and support levels follow the permissions and service scope agreed with our team.

Meet Ruk-Com Agent
QUESTIONS, ANSWERED

Before you start Managed WAF

Which servers are supported?
We assess Linux OS, web server, control panel and versions first. cPGuard supports compatible environments with or without a panel; individual modules may have additional mail-server or CMS requirements.
How do WAF and malware scanning differ?
The WAF inspects HTTP requests at the web server and blocks rule matches. Scanners inspect local files or WordPress content even without incoming requests. They are complementary protection layers.
Are all features enabled immediately?
No. We review existing rules and compatibility before enabling the WAF, then select modules and policies for the environment, particularly cleanup, updates and account suspension.
Does this cover every type of DDoS?
Host firewall controls can address configured SYN and single-source DoS patterns. They do not replace upstream filtering when attacks saturate a link. Assess upstream DDoS protection separately.
How are false positives handled?
Review events, rule IDs and business flows with the app owner. Scope exceptions narrowly, validate configuration and behavior, and record the rationale and rollback plan.
Is pricing per domain or per server?
The price is ฿2,500 / Server / month. We assess websites, resources, environment and modules to define the service scope first. This does not imply unlimited websites or operations.
LET’S SECURE YOUR SERVER

Start with what your server
needs to protect.

Share your OS, web server, control panel and website workload. Our team will assess suitable modules and an operating plan.

Talk to Ruk-Com

Product capability references: cPGuard features · WAF documentation · Scanner documentation