Skip to content

feat: add MokN integration v1.0.0#2953

Open
mokn-acasteleiro wants to merge 2 commits into
SEKOIA-IO:mainfrom
MokN-SAS:feat/mokn-integration
Open

feat: add MokN integration v1.0.0#2953
mokn-acasteleiro wants to merge 2 commits into
SEKOIA-IO:mainfrom
MokN-SAS:feat/mokn-integration

Conversation

@mokn-acasteleiro
Copy link
Copy Markdown

Description

This PR adds the documentation for the MokN - Baits module in the Threat Intelligence category.

The integration allows Sekoia.io to poll MokN bait login attempts from the MokN API and ingest them as normalized events. It is designed to help analysts detect malicious authentication activity observed on MokN bait services and enrich investigations with attacker context.

What this module covers:

  • Collection of MokN bait attempts through a polling trigger
  • Ingestion of attempt metadata such as timestamps, credentials submitted, source IP, geographic context, headers, user-agent, JA4H fingerprint, attacker reputation, and credential leak context
  • Response actions to comment an attempt and request a credential check directly from Sekoia.io automation

This documentation also includes:

  • Prerequisites and API key creation steps in MokN
  • Intake configuration steps in Sekoia.io
  • Trigger configuration details

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 24, 2026

Newest code from mokn-acasteleiro has been published to preview environment

🚀 Latest deployment was built on 2026-05-18 10:58:02 (8b4dac096783350237796f1c40f485b5ab478e7d).

@mchupeau-sk
Copy link
Copy Markdown
Contributor

Hello @mokn-acasteleiro,

For the documentation, can you remove the action part.

You can see the Microsoft Entra ID documentation for the connector part.

@mokn-acasteleiro
Copy link
Copy Markdown
Author

Hello @mchupeau-sk,

I have just pushed the version without the action part.
Is there anything else I should edit ?

Have a good day!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants