Cloud-Native Win · Linux · macOS Auto-Remediation No Infrastructure 📡 MantisNMS · Now Live

Manage. Secure. Monitor.
Your whole network.

One platform, three products. MantisRMM™ gives you full remote control over every endpoint. Mantis360™ finds, prioritizes, and auto-closes vulnerabilities the moment they're patched. MantisNMS™ watches your whole network — 50+ sensor types plus NetFlow traffic analytics — all at a fraction of the cost of Tenable, Qualys, or PRTG.

Trusted by security-conscious MSPs and IT teams
200K+
CVEs tracked
3
Platforms (Win · Linux · macOS)
60s
Agent check-in interval
$0
Infrastructure to manage
What the name means
MANTIS

Managed Automation · Network Telemetry · Intelligent Security — the three disciplines every IT team juggles, in one platform. Each maps to a product.

Managed Automation
Full remote control, patching, scripting and workflow automation across every Windows, Linux and macOS endpoint.
MantisRMM™ →
Network Telemetry
50+ sensor types and NetFlow traffic analytics watching your switches, servers, services and cloud — one pane of glass.
MantisNMS™ →
Intelligent Security
Continuous vulnerability management that finds, prioritizes, and auto-closes risks the moment they're patched.
Mantis360™ →
See it live

Your whole fleet,
one pane of glass.

Real-time risk scoring, CVE tracking, and remote control across every endpoint — continuously updated as agents check in. No infrastructure to run.

Mantis360 — Security Dashboard Live
94
Risk score
1,284
Assets
37
Critical CVEs
1,251
Agents online
Scanning fleet…
Critical
37
High
112
Medium
206
Low
349
Features

Everything your team needs.
Nothing you don't.

Three purpose-built tools that cover remote management, vulnerability security, and network monitoring — no upsell tiers, no feature gates.

🖥️

Remote Desktop

Full remote desktop access to Windows endpoints with bidirectional clipboard sync and branded connection/disconnection notifications for the end user.

⚙️

Script Automation

Execute PowerShell, Bash, and Python scripts across your fleet. Build workflows with chained steps, variable substitution, dry-run, and rollback.

🔄

Patch Management

Windows Update management, Winget software deployment, and patch status tracking across all your endpoints from a single view.

🌐

Cross-Platform Agents

Native agents for Windows (10/11, Server), Linux (amd64 + arm64), and macOS (Intel + Apple Silicon) — all managed from one portal.

🔧

Process & Service Control

Inspect running processes, kill tasks, start and stop services, browse and transfer files — all without a remote desktop session.

🔍

CVE Correlation

Software inventory auto-correlated against NVD, EPSS, and CISA KEV. See which installed software has known exploitable vulnerabilities without switching tools.

📋

Custom Fields & Tags

Add structured custom fields to agents and use them as dynamic variables inside scripts and automation workflows — read or write via script output.

🔔

Branded Notifications

Custom connect and disconnect toast notifications shown on the managed endpoint — keeps users informed without breaking their workflow.

📡

50+ Sensor Types

Ping (with loss & jitter), TCP/HTTP/TLS, DNS, SNMP interface & host health, SSH/FTP/NTP/LDAP/RDP, SQL Server/Oracle/MySQL/PostgreSQL, Redis, MongoDB, Redfish, VMware vCenter & Hyper-V.

🔀

Traffic Flow Analytics

NetFlow v5/v9, IPFIX, and sFlow. See top talkers, conversations, and applications per exporter — exactly which hosts and apps are using your bandwidth.

🖧

Agentless Collector

One lightweight probe monitors an entire site — no per-device agent. Or install the unified agent for CPU/mem/disk/IO/network and service, process & event-log rules straight from servers.

🔔

Smart Alerting

Threshold & syslog/trap content rules, acknowledgement, dependency-aware suppression, and notifications by email, Slack, Teams, or webhook — plus run a remediation script on the probe when a rule fires.

🗺️

Discovery & Maps

Auto-discovery, an interactive network map, traceroute with a geo view, and per-interface throughput & error graphs — organize sensors into logical groups per site or company.

🔒

Credential Vault

Store service credentials once, encrypted at rest, and reuse them across VMware, Redfish, and SSH-command sensors — secrets never leave your tenant.

📈

History & Reports

Long-term metric history tiered to your own storage, availability reports, and a dashboard with per-site/company status widgets and top-port utilization.

💸

Priced Per Sensor

Simple PRTG-style per-sensor tiers with no multi-year lock-in — from $175/mo for 500 sensors. Bundle with RMM & 360 for 10% off.

🎯

CVE & NVD Tracking

200,000+ CVEs matched against your live software inventory on every agent check-in. EPSS exploit probability scoring cuts noise by up to 90%.

Auto-Remediation

When software is removed from an endpoint, Mantis360 automatically closes the vulnerability finding — marked "auto-remediated" with a timestamp. No other tool does this.

🗺️

Network Discovery

Deploy a lightweight probe to any subnet and instantly discover all hosts, fingerprint services, and run vulnerability scans against network-facing devices.

📊

STIG Compliance

Compliance scanning against CIS, DISA STIG, and custom frameworks. Track posture over time and generate audit-ready reports with remediation guidance.

🌍

TLS & Exposure Monitoring

Track SSL/TLS certificates and expiry across your estate and surface unexpectedly exposed services found during scans — so risky exposure is caught before it's exploited.

🔑

Identity Exposure Scanning

Active Directory posture checks — stale accounts, weak password policies, privileged group exposure, and lateral movement paths before attackers find them.

🏭

ICS/OT Detection

Identify industrial control systems and OT devices on your network and auto-match them against CISA ICS advisories — including fingerprinting for non-IP assets.

📈

Risk-Ranked Dashboard

Findings ranked by CVSS × EPSS combined risk score — the highest-risk, most-likely-to-be-exploited vulnerabilities surface at the top. CISA KEV findings auto-escalate to Critical.

Why MantisOps

Built different. Priced different.

🏷️

Transparent, public pricing

Per-agent, per-asset, and per-sensor pricing you can calculate yourself — no quotes required, no surprise invoices, no per-technician seat fees.

Auto-remediation is unique

When an agent confirms software is removed, Mantis360 closes the finding automatically. Tenable, Qualys, and Rapid7 require manual sign-off. We don't.

🔒

Per-tenant data isolation

Every tenant gets a dedicated D1 database and R2 object store. Your data never co-mingles with another organization's data in shared storage.

☁️

Zero infrastructure overhead

Deployed on Cloudflare's global edge. No servers to manage, no VMs to patch, no license managers. You install an agent and you're live in minutes.

Pricing

Simple pricing.
Know exactly what you'll pay.

Calculate your cost below. No sales call required, no annual commitment lock-in on trials.

MantisRMM
$20 /month
10 agents × $2.00/agent
10 agents
10100250500
Minimum 10 agents · purchased in increments of 10 · billed monthly
  • Windows, Linux & macOS agents
  • Remote desktop with clipboard sync
  • Script execution & workflow automation
  • Process, service & file management
  • Patch management (Winget + Windows Update)
  • NVD CVE correlation
  • Unlimited technician accounts
  • Per-tenant data isolation

Direct online purchasing opens at launch — start a free trial today.

How we stack up at 10 agents
MantisRMM $20/mo
NinjaOne ~$50/mo
Atera (1 tech) $129/mo
ConnectWise ~$300+/mo
Datto RMM ~$30/mo
Competitor prices are estimates. See full breakdown →
Mantis360
$200 /month
1 pack · 50 assets × $4.00/asset
1 pack 50 assets
502505001,000
50 assets per pack · $200/pack/month · add packs as you grow
  • CVE matching with NVD + EPSS + KEV
  • Auto-remediation on agent check-in
  • Network discovery & TLS/exposure monitoring
  • STIG compliance (CIS, DISA, custom)
  • Identity & AD exposure scanning
  • ICS/OT device detection
  • SSL/TLS certificate & exposure monitoring
  • Risk-ranked dashboard (CVSS × EPSS)

Direct online purchasing opens at launch — start a free trial today.

How we stack up at 50 assets/year
Mantis360 $2,400/yr
Tenable.io ~$1,750/yr
Qualys VMDR ~$10,000/yr
Rapid7 InsightVM ~$11,000/yr
Microsoft Defender ~$5/user/mo (P2)
Competitor figures reflect comparable coverage — estimated. See full breakdown →
MantisNMS
$175 /mo · 500 sensors
Flat per-sensor tiers — priced like PRTG, ~12–15% less, no multi-year lock-in.
500 sensors$175/mo
1,000 sensors$325/mo
2,500 sensors$700/mo
5,000 sensors$1,250/mo
10,000 sensors$1,550/mo
A sensor = one monitored value/check · 15-day free trial (up to 100 sensors) · billed monthly
  • 50+ sensor types (SNMP, TLS, HTTP, SQL, VMware, Hyper-V…)
  • NetFlow / IPFIX / sFlow traffic analytics
  • Agentless collector + agent-fed host metrics
  • Threshold & content rules, ack & escalation
  • Auto-discovery, network map & traceroute geo
  • Encrypted credential vault
  • Email / Slack / Teams / webhook alerts
  • Per-tenant data isolation

Direct online purchasing opens at launch — start a free trial today.

How we stack up at 500 sensors
MantisNMS $175/mo
PRTG (PRTG 500) ~$200/mo
Auvik ~$300+/mo
SolarWinds NPM ~$250+/mo
Competitor prices are estimates. See full breakdown →
Best value
MantisOps Complete
Save 10%on all three products

Bundle MantisRMM, Mantis360 and MantisNMS and save 10% on your combined monthly subscription — one tenant, one bill, one pane of glass.

  • All three products under a single tenant & monthly invoice
  • Shared collector powers both Mantis360 discovery & MantisNMS monitoring
  • MantisRMM software inventory feeds Mantis360 CVE correlation
  • 10% off the combined subscription · billed monthly · no annual lock-in
Comparison

See how we stack up.

A quick look at how MantisOps compares to the most common alternatives. View the full feature-by-feature comparison →

Feature Mantis360 Tenable Qualys Rapid7
Auto-remediation on check-in
EPSS exploit probability scoring
CISA KEV auto-escalation
ICS/OT device detectionAdd-on
Identity/AD exposure scanningTenable One
Per-tenant data isolation
No annual contract or minimum
External posture scan (A–F grade)
Security Score (KEV-weighted)
Free trial (no credit card)
Feature MantisRMM NinjaOne Atera ConnectWise
Linux (amd64 + arm64) full support
macOS Intel + Apple Silicon
Branded end-user notifications
NVD CVE correlation built-in
Integrated VM platformMantis360
Remediation scripts with rollback
LAPS — local-admin password escrow
Fleet Security Score + EOL-OS detection
Pricing$2/agent/mo~$3–6/device$129/tech/moQuote required
Free trial (no credit card)
Feature MantisNMS PRTG Auvik SolarWinds
Bill only the interfaces that matter48-port switch ≈ 7 sensorsSensor per port
SNMP v1 / v2c / v3
NetFlow / IPFIX / sFlow analyticsNTA add-on
Host sensors (CPU / mem / disk)
Cloud-native SaaS (no server to run)On-prem
VM + RMM in the same platformOne bill, one dashboard
No multi-year contract lock-in
Config backup, versioning & drift alerts (NCM)
VMware / Hyper-V / database / WMI sensors
Pricing$175/mo · 500 sensors~$200/moPer device$1,600+ perpetual
Free trial (no credit card)
Documentation

Get up and running quickly.

Guides and references to help you deploy agents, build automations, and get the most out of each platform.

🚀

Quick Start — MantisRMM

Deploy your first Windows, Linux, or macOS agent in under 5 minutes. Download the installer, run it, and your endpoint appears in the portal.

📦

Agent Installation

Agents are single-binary executables. Windows: MSI installer or silent install via Group Policy. Linux: shell script or systemd service. macOS: pkg installer.

⚙️

Script Automation

Write PowerShell, Bash, or Python scripts. Use {{VARNAME}} for user variables, {{AGENT:field}} for agent fields, and {{FIELD:label}} for custom fields.

🛡️

Quick Start — Mantis360

Register your organization, install 360 agents on endpoints, and your first vulnerability findings appear within minutes of the first check-in.

📡

Network Scanning

Deploy a network probe to any subnet. The probe binary runs continuously and reports discovered hosts, open ports, and service fingerprints to the Mantis360 portal.

📋

STIG & Compliance

Assign CIS or DISA STIG bundles to endpoints. Mantis360 scores compliance posture on every check-in and flags drifted controls with remediation steps.

FAQ

Common questions.

Each product works independently — subscribe to MantisRMM, Mantis360, MantisNMS, or any combination. When used together they reinforce each other: MantisRMM's software inventory feeds Mantis360's CVE correlation, and the shared collector powers both Mantis360 discovery and MantisNMS monitoring — no extra configuration. Each product also has standalone value, and bundling all three saves 10%.

Yes, free trials are available for all three products — no credit card required. Fill out the trial registration form and we'll provision your tenant. The trial includes full feature access with a limited agent/asset/sensor count (MantisNMS: up to 100 sensors) so you can evaluate everything before committing.

MantisRMM is priced at $2 per agent per month, with a minimum of 10 agents ($20/month). You can add agents in increments of 10 at any time. There are no per-technician fees — all users in your organization can access the portal. An "agent" is one installed endpoint (Windows, Linux, or macOS device running the MantisRMM agent).

Mantis360 is priced at $4 per asset per month, sold in packs of 50 assets ($200/pack/month). An "asset" is any endpoint, network device, or cloud resource monitored by Mantis360 — whether through an installed agent or via network scanning. You can add packs as your asset count grows.

The MantisRMM, Mantis360, and MantisNMS host agents support:

  • Windows: Windows 10, Windows 11, Windows Server 2016/2019/2022
  • Linux: Debian/Ubuntu, RHEL/CentOS, Alpine — amd64 and arm64
  • macOS: macOS 12 (Monterey) and later — Intel and Apple Silicon

All agents report to the same portal. No separate console or product needed per platform.

Every time a Mantis360 agent checks in (every 60 seconds by default), it reports the current software inventory. Mantis360 compares this against all open vulnerability findings for that endpoint. If the vulnerable software is no longer present, the finding is automatically marked "auto-remediated" with a timestamp and the identity of who/what removed the software. Manual remediation (where a human marks a finding resolved) creates a separate "manually remediated" audit entry. No other commercial vulnerability management tool does this automatically.

Every organization gets a dedicated D1 database and R2 object store — your data is never stored in shared tables alongside other tenants' data. Data is hosted on Cloudflare's infrastructure in the United States. MantisOps staff have admin-level access for support purposes only and do not access customer data without permission. No data is sold or shared with third parties.

Agent installation takes under 5 minutes per machine — download the installer, run it, and the endpoint appears in your portal within seconds. For network scanning, deploying a probe to a subnet takes about 10 minutes. The Mantis360 vulnerability dashboard starts populating with findings on the first agent check-in (~60 seconds after install). There are no servers, no virtual machines, and no configuration files to manage.

Yes, and this is the recommended configuration. Both agents are lightweight and run independently. When both are installed, Mantis360 uses MantisRMM's live software inventory for deeper CVE correlation, and you can trigger remediation scripts via MantisRMM when Mantis360 surfaces a critical vulnerability — all from a unified workflow.

EPSS (Exploit Prediction Scoring System) is a machine-learning model maintained by FIRST.org that predicts the probability that a given CVE will be exploited in the wild within the next 30 days. A critical-severity CVE with a low EPSS score (rare exploits in the wild) is far less urgent than a medium-severity CVE with a high EPSS score (actively exploited today). Mantis360 multiplies CVSS × EPSS to rank findings by actual risk — not just theoretical severity — which can reduce actionable vulnerability noise by up to 90%.

MANTIS is an acronym for Managed Automation, Network Telemetry, and Intelligent Security — the three disciplines the platform unifies. Managed Automation is MantisRMM (remote endpoint management and workflow automation), Network Telemetry is MantisNMS (network monitoring), and Intelligent Security is Mantis360 (risk-ranked vulnerability management). One platform, one bill, one pane of glass across all three.

The mantis is the perfect metaphor for what the platform does. It's a patient, ever-watchful predator with a near-360° field of vision — it sees everything on its turf — and the instant a threat appears it strikes with speed and precision. That's exactly how MantisOps operates: continuously watching every endpoint and network device, surfacing what actually matters, and responding fast and accurately when something's wrong. The circuit ring around the mark ties that natural instinct to the technology it protects.

Ready to run IT
from one platform?

Start a free trial of MantisRMM, Mantis360, or MantisNMS — or bundle all three as MantisOps Complete and save 10%. No credit card, no infrastructure to manage.

Start MantisRMM Trial Start Mantis360 Trial Start MantisNMS Trial Talk to us