Teams & shared engagements
Guide contents
- Overview & responsible use
- Create your account
- Activating Pro & how to pay
- First launch: choose a mode
- Local mode
- Remote mode & the agent
- Teams & shared engagements
- The main menu
- Scanning — Nmap
- Scanning — Nuclei
- The workspace database
- Import & export
- Exploits
- Auxiliary
- Payloads & handlers
- Your own modules
- msfconsole
- Sessions & post-exploitation
- Jobs & background tasks
- Keeping Lupus off the test network
- Settings
- Troubleshooting
Team seats need remote mode. The shared workspace lives in the agent, and the agent runs on one host. In local (on-device) mode every phone runs its own agent with its own database, so nothing is shared between them — buying seats does not change that. Set up the remote agent first.
What the team shares
Everyone points their phone at the same agent, so everyone works the same engagement. A host discovered by one member is already there for the others, along with its services, findings, credentials and loot — no export, no import, no “send me your scan”. The workspace database on that host is the single copy.
Buying seats
- On Pricing, choose how many seats you need. One subscription covers the whole team and is billed per seat.
- You get the first seat automatically — the account that pays is a member too.
- Adding or removing seats later changes the same subscription; you are never asked to buy a second one.
Reducing the seat count never removes anyone. It only stops new invitations until the team fits again — who leaves is your decision, not the billing system's.
Inviting your team
- Open your account → Team and enter the addresses.
- Each person gets an invite link. Opening it activates the seat on their own Lupus login — they can create the account at that point if they don't have one.
- Invites are single use, and an invitation holds its seat until it is claimed or you remove it.
Someone who already pays for Pro personally keeps their own plan; their seat is held and takes over automatically when the personal one ends. Nobody pays twice for the same month.
Connecting each phone
- Start the agent in enrollment mode with room for your team:
--enrollment-mode --enrollment-slots 5. - The agent prints an enrollment code. Each member enters it once, from their own phone, exactly as in remote mode — a fresh code is shown for the next device.
- Need to add someone later? Send the agent process
SIGHUP(kill -HUP <pid>) and it re-opens for one more device. No restart, so nobody's session drops.
Every device gets its own certificate and token, so enrolling a new phone never signs the others out, and each one can be revoked on its own.
Removing someone
Removing a member frees the seat immediately, so you can invite a replacement right away. The person keeps Pro until the end of the period you already paid for — you are not refunded for the remainder, and they are not cut off mid-engagement.