CRTO / CRTP
CRTP and CRTO are the reference certifications for Active Directory and Red Team. CRTP (Altered Security) focuses on attacking AD; CRTO (Zero-Point Security) teaches red team operations with C2 (Cobalt Strike) in a practical, highly valued way.
CRTP (Certified Red Team Professional)
Section titled “CRTP (Certified Red Team Professional)”Focus attacking and abusing ACTIVE DIRECTORY (enumeration, escalation, persistence)Covers Kerberos (kerberoasting, delegation), ACLs, trusts, GPO abuse (see Windows & AD area)Exam practical (24h) in an AD lab: compromise the domain/forest and reportFor whom those who want to master AD attacks; an excellent base before CRTOCRTO (Certified Red Team Operator)
Section titled “CRTO (Certified Red Team Operator)”Focus red team OPERATIONS: C2, evasion, post-exploitation in ADCovers Cobalt Strike (malleable profiles, beacons), evasion (see mal-evasion/win-evasion), lateral movement, persistence, working with a real C2 (see mal-c2)Exam practical in a red team lab; very oriented to an operator's realityFor whom pentester/red teamer who wants to operate like in real engagementsCRTP vs CRTO
Section titled “CRTP vs CRTO”CRTP more focused on AD ATTACK "by hand" (PowerShell, tools) -> fundamentalsCRTO C2 operations and EVASION -> more "real red team"; solid AD recommended first (CRTP)# typical path: CRTP (master AD) -> CRTO (operate as red team)How to prepare
Section titled “How to prepare”- this wiki's Windows & AD cards (ad-*) are almost the CRTP syllabus directly- CRTO: understand C2 (mal-c2), EDR evasion (mal-evasion/win-evasion), OPSEC- practice in the included lab; GOAD as an additional own AD labProfessional value
Section titled “Professional value”- CRTP: highly valued for roles touching AD (most internal pentests)- CRTO: a reference for operational RED TEAM; real C2 knowledge in demand- excellent value for money; realistic labsBlue Team / career
Section titled “Blue Team / career”- CRTP turns the ad-* cards into examined skill: AD attack end to end.
- CRTO steps up to red team operations with C2 and evasion (Command & Control, Defense Evasion, Defense Evasion (AMSI / AV / EDR)).
- Mastering AD first (CRTP/ad-*) before CRTO makes the leap much easier.
- In high demand because almost every internal pentest touches Active Directory.
Tips and common mistakes
Section titled “Tips and common mistakes”- CRTP: focus on AD abuse (Kerberoasting, delegation, ACLs) from PowerShell; hands-on exam with a report.
- CRTO: drill the full C2 workflow (evasion, lateral movement, persistence) and build your own lab too.
- Common mistake: going in without your own command playbook; prepare it and organize notes by phase.
Testing checklist
Section titled “Testing checklist”- Master the Windows & AD cards (ad-*)
- CRTP: AD attack by hand (Kerberos, ACLs, trusts, GPO)
- Practice in the included lab (+ your own GOAD)
- CRTO: C2 (Command & Control) and evasion (Defense Evasion/Defense Evasion (AMSI / AV / EDR))
- OPSEC and red team operations
- Practical exam report
- Plan the order (CRTP → CRTO)