MokN is a cybersecurity company focused on helping defenders detect and reduce external threats before they become compromise. Its positioning centers on earlier, higher-confidence visibility into attacker activity, especially around credential theft and internet-facing exposure, reflecting a philosophy shaped by SOC experience and a preference for practical detection over added complexity.
MokN’s offering combines two core products: Baits, which uses defensive phishing pages to capture the use of stolen credentials, and Lantern, which inventories and monitors exposed internet assets to surface risky weaknesses in real time. Together, they address both sides of the external threat problem: what attackers can see on the perimeter and how they try to log in once credentials are compromised.
Offerings, Capabilities, and Integrations
MokN provides deception-based credential threat detection, external attack surface management, and organization-specific threat intelligence derived from real attacker behavior. Its capabilities include validated credential compromise alerts, real-time visibility into exposed services, prioritized exposure detection, and inventory workflows designed to keep external asset data accurate and actionable.
The platform is delivered as SaaS and is designed to fit into existing security operations workflows. MokN supports integrations with SIEM, SOAR, and ticketing tools, and its site highlights connectivity with Splunk, Microsoft Sentinel, IBM Security, Elastic, Cortex XSOAR, Google SecOps, Filigran, and ServiceNow. Lantern also supports native connectors for major cloud providers to keep public-facing asset visibility current.
Products and Services
- Baits: Baits is MokN’s credential-threat detection product. It deploys ultra-realistic defensive phishing pages that blend into a customer’s environment, validate tested credentials in real time, and turn attacker interactions into actionable alerts and tailored threat intelligence.
- Lantern: Lantern is MokN’s external attack surface management solution. It builds an actionable inventory of exposed assets, detects dangerous internet-facing exposures in real time, and uses cloud connectors and controlled discovery to keep the external perimeter current.
- Custom Baits: Custom Baits is a tailored service for replicating sensitive login pages, high-value portals, or user-specific targets so decoys match a customer’s exact environment.
Target Customers
MokN targets organizations with meaningful internet-facing attack surfaces, cloud estates, and security teams that need faster visibility into real external risk. Its messaging is especially relevant for enterprises concerned with credential theft, exposed admin or remote-access services, and shadow IT across distributed environments.
Use cases on MokN’s site point to large, multi-site or multinational organizations, including examples in logistics, retail, manufacturing, and other complex enterprises. The offering also fits teams that need to protect executives, employees, service accounts, and third-party-connected populations from targeted credential misuse.
Cloud Integrations and Marketplace
- AWS: Lantern offers native connectors for AWS that pull public-facing assets into inventory and monitoring workflows in real time.
- Microsoft Azure: Lantern offers native connectors for Azure that pull public-facing assets into inventory and monitoring workflows in real time.
- Google Cloud: Lantern offers native connectors for GCP that pull public-facing assets into inventory and monitoring workflows in real time.
Key People
- Gautier Bugeon: CEO
- Alexis Georges: CTO
- Antoine Coudoux: CMO
- Adrien Casteleiro: Lead Developer
Key Facts
- Headquarters: Paris, France
- Employees: 2-10 employees
- Annual Revenue: Over €1M in annual recurring revenue
- Parent Company: None
- Subsidiaries: None
- Publicly Listed: Privately held