MokN provides a SaaS platform that deploys realistic credential decoys (Baits) to detect when stolen passwords are actively used against an organization’s external login portals. The system validates credentials in real time, generates alerts only for verified logins, and enriches them with attacker context and threat intelligence, while its Lantern eASM module continuously maps internet‑facing assets to reduce exposure.
Funding
$17.8M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.



AIDFounders
Product
Problem
Organizations continue to suffer credential theft, yet most stolen passwords never appear on public dark‑web feeds, leaving security teams unaware of active compromises until attackers use them to access internal systems.
Solution
MokN deploys ultra‑realistic credential decoys, called Baits, that mimic an organization’s external login portals and services. When attackers test stolen credentials on these Baits, MokN agents validate the credentials in real time and generate alerts only for truly valid logins, eliminating false positives. The platform enriches each alert with attacker context, such as source IP, targeted user, and associated threat actors, providing organization‑specific threat intelligence. Alerts integrate directly with existing SIEM, SOAR, and ticketing tools, enabling rapid response. MokN also offers Lantern, an external attack surface management module that continuously inventories internet‑facing assets and detects risky exposures within minutes, ensuring that exposed services are secured before credentials can be leveraged.
Target Audience
Primary customers are security operations teams and incident response groups at mid‑size to large enterprises that need early detection of credential misuse and continuous visibility of their external attack surface.
Features
- Deployable Baits in minutes from a SaaS platform, requiring no changes to existing infrastructure
- Real‑time credential validation that triggers alerts only on verified, usable credentials
- Enriched alerts with attacker signals, top‑targeted users, and threat‑level scoring
- Off‑the‑shelf and custom Bait libraries covering common technologies such as SSL VPNs, webmail, and bespoke login portals
- Seamless integration with SIEM, SOAR, ticketing, and other security orchestration tools
- Lantern eASM engine that continuously discovers and maps external assets using controlled, attacker‑style scanning
- Instant cloud visibility via native connectors to AWS, Azure, and GCP, updating inventories as public IPs appear
- Breach‑oriented alerts that prioritize exposures actively exploitable by attackers, reducing noise