How to Get Started with Lunar (2026 Guide)
A practical step-by-step guide to setting up Lunar properly — including the one mistake most teams make.
Some links below are affiliate links — we may earn a commission if you sign up, at no cost to you. This never affects our assessments.
Lunar — A free, open breach-search platform by Webz.io that monitors compromised employee credentials, stolen session cookies, and infostealer logs across the open, deep, and dark web. Here's the fastest sensible path from signup to real value.
Getting started, step by step
- Step 1. Register your organization domain to see current credential exposure
- Step 2. Review the infostealer-log findings first — those include malware context (machine, malware family), which tells you if a device is still compromised
- Step 3. Force-reset any account with a stolen session cookie, not just the password — cookies survive password changes
- Step 4. Add key client domains you manage if you run infrastructure for them
- Step 5. On enterprise tier, wire alerts into Slack or your ticketing system so exposure creates a ticket automatically
One mistake to avoid
The free tier shows exposure but doesn't push alerts — you have to check. Full automation is enterprise-tier.
Cost to expect
Free tier for breach visibility; enterprise tier adds alerting, integrations, and automation (quoted).
Looking for a software agency?
Take our free 3-minute matching quiz and get a personalised agency shortlist.