Red Teaming

The Ludacris-only product module: a counted red-team engagement per year, run by Praetorian — not a customer self-serve Attacks tab.

What It Does

Red Teaming is a Guard product module, not a button in the sidebar. On Settings → Subscription it appears in the Product Modules matrix as Red Teaming. It is true only on the Ludacris tier. Freemium, Foundational, Enterprise, and Ultimate show it off.

Ludacris is Ultimate plus Red Teaming — the only tier that includes a red-team engagement. Subscription configuration for Ludacris also prices Red Teams / Year (a count of engagements), alongside AEV exercises / year.

Praetorian operators run that engagement using Guard. Customers do not get a self-serve Red Team tab.

What you will not find in the UI

There is no Attacks tab labeled Red Team.

Former Red Team operator pages are first-class Attacks tabs, and they are Praetorian-gated:

  • Domain Parking
  • Team Servers
  • Payload Generator
  • C2 Bridge
  • Phishing
  • Juicy Fruit (OSINT)
  • Capabilities

Non-Praetorian users who open those tabs see a lock screen, not a 404. The APIs behind deployment, domain parking, and campaigns require the red-team entitlement (authorized Praetorian analysts), not the Ludacris flag alone.

Legacy URLs ?tab=red-team and /red-team redirect to Team Servers. That is bookmark compatibility, not a customer module page.

Attack Paths stays available without that gate. It is not the Red Teaming module.

How it relates to other modules

ModuleTierWhat it is
Adversary Emulation Validation (BAS)Ultimate and LudacrisContinuous detection testing against your EDR/SIEM (Detections).
Red TeamingLudacris onlyCounted human-led red-team engagement(s) per year.
Continuous Penetration TestingFoundational and aboveOngoing offensive capabilities plus included compliance testing.

Ludacris still includes AEV exercises. Red Teaming is the extra row, not a rename of BAS.

Who operates it

Praetorian. If this account is not on Ludacris, the Product Modules matrix shows Red Teaming as unavailable. Enabling operator tools is not a customer Settings toggle.

Findings from an engagement still land in Unified Vulnerability Management — same table, origin, and lifecycle.