Closed Beta — Now Accepting Applications

Autonomous
Penetration
Testing.

AI agents that reason, adapt, and chain findings across the full offensive security kill chain. The quality of a senior pentester, running continuously, at scale.

83+
Findings per engagement
<2h
Time to first critical
Retests included
MANTIS Internal Test Assessment
Administrator admin@usemantis.io
All Engagements
Internal Test Assessment
Completed Network
Overview
Overview
Live Feed
Scan History
Findings
All Findings
Attack Surface
Assets
Reports
Report
Compliance
Download PDF
Management
Members
Settings
Internal Test Assessment Completed Network
12 open findings Critical 1 High 4 Medium 7
12 open, 1 fixed, 1 false positive
11 active assets Endpoint 5 Web App 6
11 active, 0 inactive, 0 decommissioned
Web App Active
http://10.20.0.21:3000
1 URL discovered  4 open findings
First seen: Mar 03, 2026 00:33
55
Web App Active
ssh://10.20.0.14:22
1 URL discovered  2 open findings
First seen: Mar 03, 2026 00:37
50
Web App Active
nats://10.20.0.21:4222
1 URL discovered  1 open finding
First seen: Mar 03, 2026 00:40
40
Web App Active
telnet://10.20.0.14:23
1 URL discovered  1 open finding
First seen: Mar 03, 2026 00:44
25
Coverage
OWASP Top 10 Active Directory Network Infrastructure Web Applications PCI DSS ISO 27001 Cyber Essentials+
Methodology

Not a scanner. A tester.

Mantis agents reason about accumulated context, chain findings across the kill chain, and adapt strategy in real time — not a decision tree.

01

Define scope, launch assessment

Specify your target — web application, network range, or Active Directory environment. Mantis parses scope, discovers assets automatically, and populates the Attack Surface before testing begins.

02

Parallel agents explore and probe

Dedicated agents handle crawling, parameter mining, injection testing, authentication bypass, and infrastructure enumeration simultaneously, sharing findings through a live knowledge graph.

03

Contextual reasoning chains findings

An IDOR becomes a privilege escalation path. A misconfiguration becomes a lateral movement vector. Mantis understands what each finding means, not just that it exists.

04

Report, remediate, retest — same day

CVSS scoring, CWE mapping, and business-risk context in every finding. Mark issues remediated and Mantis retests automatically. Compliance reports generated on demand.

PHP Web Application — Scan #3
Crit 12 High 9 Med 8
27 open · 2 fixed
Critical Open
Remote Code Execution via Unrestricted File Upload
/admin/upload.php · CWE-434
10.0
Critical Open
SQL Injection in login.php — Full DB Dump
/login.php · CWE-89
9.8
Critical Open
Stored XSS — Session Cookie Exfiltration via OOB
/api/v1/comment · CWE-79
9.3
High Fixed
Reflected XSS in /search.php — Verified Remediated
/search.php · CWE-79
8.8
Office Network · Scan #2 · 192.168.1.0/24 LIVE
10:55:16NMAPsmb-vuln-ms17-010: VULNERABLE — 192.168.1.10
10:55:17FINDINGCRITICAL · EternalBlue CVE-2017-0144 · CVSS 9.8 · 7yrs unpatched
10:55:35RESULTSSH LOGIN — admin@192.168.1.10 · creds: admin:admin
10:55:36FINDINGCRITICAL · Default SSH creds · Full shell · CVSS 9.8
10:55:42SSH(ALL:ALL) NOPASSWD:ALL — root in 10 seconds
10:56:45FINDINGCRITICAL · svc_backup:Welcome1234! cracked in 14s · AS-REP
10:57:15MESSAGE54% complete — RDP brute, SMB relay, LLMNR poisoning queued
Engagements
NameTypeTargetStatusScansFindingsCreated
PHP Web Application Audit Web App http://target-app.internal/ Running 3 31 2026-03-04 ViewEdit
Office Network Audit Network 192.168.1.0/24 Running 2 16 2026-03-04 ViewEdit
Acunetix TestPHP Web App http://testphp.vulnweb.com/ Completed 2 69 2026-03-03 ViewEdit
Internal Test Assessment Network 10.20.0.0/24 Completed 9 14 2026-03-02 ViewEdit
Capabilities

Built by pentesters.

Every capability traces back to real offensive security methodology. Not product speculation.

🕷

Web Application Testing

Parallel specialist agents cover the full OWASP Top 10 — crawling, parameter mining, XSS, SQLi, IDOR, auth bypass, business logic, and file upload abuse.

🌐

Network Infrastructure

Nmap integration, service enumeration, CVE correlation, and protocol testing across subnets. Lightweight on-premises agents for internal assessments behind your perimeter.

🔑

Active Directory

Kerberoasting, AS-REP roasting, BloodHound path analysis, and privilege escalation chaining. The agent understands AD topology and adapts attack paths dynamically.

🗺

Attack Surface Management

Every engagement automatically discovers and catalogues assets — web apps, endpoints, APIs, cloud services. Risk scores update as findings are confirmed and remediated.

🔄

Bundled Remediation Retesting

Unlimited retests on every plan. Fix an issue, Mantis verifies it the same day — scoped to the original finding, timestamped for your auditor.

🏢

Multi-Tenant MSSP Architecture

White-label the platform for your full client portfolio. YAML-defined scope, one-time agent registration tokens, and fully isolated tenant data.

Comparison

Honest comparison.

Where Mantis sits relative to the rest of your security programme.

Capability Mantis Manual Pentest Burp Suite Pro Vuln Scanner
Contextual reasoning across findings
Runs autonomously without human inputPartial
Adapts to WAF and defensive controlsManual
Attack Surface Management built inLimited
Business-risk narrative in output
Bundled remediation retestingExtra costManualRescan only
Active Directory testingLimited
Cost per assessment£400–600£8,000–15,000£480/yr flatVariable
Time to first critical finding< 2 hours1–3 daysHours (manual)Fast (low quality)
Pricing

Simple. Transparent.

All plans include unlimited remediation retesting. No hidden costs, no per-finding charges, no booking fees.

Starter
£999
/month
  • 2 assessments per month
  • Web application testing
  • Full OWASP Top 10
  • Attack Surface Management
  • Unlimited remediation retests
  • PDF reports
Get Started
Most Popular
Growth
£2,999
/month
  • 8 assessments per month
  • Web app + network testing
  • Full OWASP Top 10
  • Attack Surface Management
  • Unlimited remediation retests
  • Delta and compliance reports
Get Started
Professional
£6,999
/month
  • 25 assessments per month
  • Web, network + Active Directory
  • On-premises agent deployment
  • Unlimited remediation retests
  • Multi-user access
  • Priority support
Get Started
Enterprise / MSSP
Custom
 
  • Unlimited assessments
  • Full white-label platform
  • Multi-tenant client management
  • Custom SLA and uptime
  • Dedicated Slack channel
  • Co-branded reporting
Talk to Sales

Top-up assessment credits from £500 for mid-cycle overages.

"A senior pentester runs one engagement at a time. Mantis runs dozens simultaneously and retests every fix the same day."

Silverback Cyber — Builders of Mantis

Ready to see it work?

Request a live demo against a target of your choice. No canned results, no pre-recorded output.

Request a Live Demo MSSP Partnership Enquiry