Skip to content

CRTO / CRTP

CRTP and CRTO are the reference certifications for Active Directory and Red Team. CRTP (Altered Security) focuses on attacking AD; CRTO (Zero-Point Security) teaches red team operations with C2 (Cobalt Strike) in a practical, highly valued way.

Focus attacking and abusing ACTIVE DIRECTORY (enumeration, escalation, persistence)
Covers Kerberos (kerberoasting, delegation), ACLs, trusts, GPO abuse (see Windows & AD area)
Exam practical (24h) in an AD lab: compromise the domain/forest and report
For whom those who want to master AD attacks; an excellent base before CRTO
Focus red team OPERATIONS: C2, evasion, post-exploitation in AD
Covers Cobalt Strike (malleable profiles, beacons), evasion (see mal-evasion/win-evasion),
lateral movement, persistence, working with a real C2 (see mal-c2)
Exam practical in a red team lab; very oriented to an operator's reality
For whom pentester/red teamer who wants to operate like in real engagements
CRTP more focused on AD ATTACK "by hand" (PowerShell, tools) -> fundamentals
CRTO C2 operations and EVASION -> more "real red team"; solid AD recommended first (CRTP)
# typical path: CRTP (master AD) -> CRTO (operate as red team)
- this wiki's Windows & AD cards (ad-*) are almost the CRTP syllabus directly
- CRTO: understand C2 (mal-c2), EDR evasion (mal-evasion/win-evasion), OPSEC
- practice in the included lab; GOAD as an additional own AD lab
- CRTP: highly valued for roles touching AD (most internal pentests)
- CRTO: a reference for operational RED TEAM; real C2 knowledge in demand
- excellent value for money; realistic labs
  • CRTP turns the ad-* cards into examined skill: AD attack end to end.
  • CRTO steps up to red team operations with C2 and evasion (Command & Control, Defense Evasion, Defense Evasion (AMSI / AV / EDR)).
  • Mastering AD first (CRTP/ad-*) before CRTO makes the leap much easier.
  • In high demand because almost every internal pentest touches Active Directory.
  • CRTP: focus on AD abuse (Kerberoasting, delegation, ACLs) from PowerShell; hands-on exam with a report.
  • CRTO: drill the full C2 workflow (evasion, lateral movement, persistence) and build your own lab too.
  • Common mistake: going in without your own command playbook; prepare it and organize notes by phase.