Mantis is an open source security framework designed to automate the workflow of asset discovery, reconnaissance, and vulnerability scanning for organizations and security teams. Mantis operates through a command line interface and accepts targets such as top level domains, IP addresses, or network ranges as input. From these inputs, it automatically discovers associated digital assets including subdomains and SSL certificates, allowing users to map the attack surface of a system. After discovery, the framework performs reconnaissance on active assets to gather technical information such as open ports, technologies, network details, and hosting infrastructure. Mantis then conducts security scans to identify vulnerabilities, exposed secrets, configuration weaknesses, and potentially malicious phishing domains. It integrates both open source and custom security tools to automate multiple phases of a security assessment in a single workflow.
Features
- Automated asset discovery, reconnaissance, and vulnerability scanning workflows
- Distributed scanning that allows workloads to run across multiple machines
- Customizable scanning workflows and configurations for different targets
- Dashboard integration for viewing assets, vulnerabilities, and findings
- Advanced alerting and notification support for security issues
- Modular design that allows quick integration of new or existing security tools