Docs & Help

Teams & shared engagements

Guide contents

  1. Overview & responsible use
  2. Create your account
  3. Activating Pro & how to pay
  4. First launch: choose a mode
  5. Local mode
  6. Remote mode & the agent
  7. Teams & shared engagements
  8. The main menu
  9. Scanning — Nmap
  10. Scanning — Nuclei
  11. The workspace database
  12. Import & export
  13. Exploits
  14. Auxiliary
  15. Payloads & handlers
  16. Your own modules
  17. msfconsole
  18. Sessions & post-exploitation
  19. Jobs & background tasks
  20. Keeping Lupus off the test network
  21. Settings
  22. Troubleshooting
Read this first

Team seats need remote mode. The shared workspace lives in the agent, and the agent runs on one host. In local (on-device) mode every phone runs its own agent with its own database, so nothing is shared between them — buying seats does not change that. Set up the remote agent first.

What the team shares

Everyone points their phone at the same agent, so everyone works the same engagement. A host discovered by one member is already there for the others, along with its services, findings, credentials and loot — no export, no import, no “send me your scan”. The workspace database on that host is the single copy.

Buying seats

  1. On Pricing, choose how many seats you need. One subscription covers the whole team and is billed per seat.
  2. You get the first seat automatically — the account that pays is a member too.
  3. Adding or removing seats later changes the same subscription; you are never asked to buy a second one.

Reducing the seat count never removes anyone. It only stops new invitations until the team fits again — who leaves is your decision, not the billing system's.

Inviting your team

  1. Open your account → Team and enter the addresses.
  2. Each person gets an invite link. Opening it activates the seat on their own Lupus login — they can create the account at that point if they don't have one.
  3. Invites are single use, and an invitation holds its seat until it is claimed or you remove it.

Someone who already pays for Pro personally keeps their own plan; their seat is held and takes over automatically when the personal one ends. Nobody pays twice for the same month.

Connecting each phone

  1. Start the agent in enrollment mode with room for your team: --enrollment-mode --enrollment-slots 5.
  2. The agent prints an enrollment code. Each member enters it once, from their own phone, exactly as in remote mode — a fresh code is shown for the next device.
  3. Need to add someone later? Send the agent process SIGHUP (kill -HUP <pid>) and it re-opens for one more device. No restart, so nobody's session drops.

Every device gets its own certificate and token, so enrolling a new phone never signs the others out, and each one can be revoked on its own.

Removing someone

Removing a member frees the seat immediately, so you can invite a replacement right away. The person keeps Pro until the end of the period you already paid for — you are not refunded for the remainder, and they are not cut off mid-engagement.

← Back to the full Lupus guide