CRTP Review: course, exam and tips

CRTP Review: course, exam and tips

6 February 2025 · 4 min read · Reviews

Active Directory Red Teaming Certifications

Active Directory is in almost every corporate network. As an attacker you want to understand how the structure fits together, where the security is weak and which attack techniques work. Last year I took the Certified Red Team Professional (CRTP) from Altered Security, a training on red team attacks against Active Directory. The hands-on labs and the tough practical exam moved me forward considerably with Windows security and AD exploitation.

CRTP certificate

Below are my experiences with the course and the exam.

Course overview

The CRTP course is structured like other Altered Security (formerly Pentester Academy) trainings. The course consists of:

  • Extensive slides and video lessons
  • Practical demonstrations of attack techniques
  • Hands-on labs to apply it right away
  • 24-hour lab access during the course (30 or 60 days)

What makes this training strong is its practice-oriented approach. Every concept that is explained, you test straight away in a realistic lab environment. Throughout the course you encounter flags that belong to each assignment. You only answer a flag correctly once you have truly completed the task, so you know for sure you have mastered the techniques.

Course content

The course covers Active Directory attack paths and red team methodologies. In short:

  • Domain enumeration with PowerView and BloodHound, trust mapping, misconfigurations
  • Privilege escalation: Kerberoasting, AS-REP Roasting, Unconstrained/Constrained/RBCD delegation
  • Lateral movement: Pass-the-Hash, Pass-the-Ticket, DCSync, Golden/Silver Ticket, persistence
  • Domain privilege escalation: Domain Admins, Enterprise Admins, cross-domain trust, AdminSDHolder
  • Defense evasion: AMSI bypass, bypassing PowerShell logging, whitelisting bypasses

The Kerberos attacks and delegation techniques were the strongest part for me. The explanation of how Kerberos works and where the weak spots are is clear.

Tools and methodology

Tool Purpose
PowerView AD enumeration and reconnaissance
Mimikatz Credential dumping and Kerberos ticket manipulation
Rubeus Kerberos abuse and ticket attacks
BloodHound Graph-based AD attack path analysis
PowerUpSQL SQL Server discovery and exploitation

The course explains both the use of the tools and the underlying techniques.

Exam experience

The CRTP exam is a 24-hour hands-on assessment that tests the knowledge and skills from the course. The task is to take over an Active Directory forest with multiple domains and obtain the highest privileges across the entire forest.

The exam forces you to apply the techniques you learned creatively. The course gives you a good foundation, but to pass you need adaptability and problem-solving thinking.

Tips for the exam

  • Enumeration makes the difference. If you get stuck, enumerate again with PowerView and BloodHound. For me, extra enumeration was always the deciding factor.
  • There are multiple routes to the goal. Do not get stuck on one approach.
  • 24 hours goes faster than you think. Keep an eye on the time and take breaks.
  • No tools are pre-installed. Prepare your tooling and write scripts for tasks you do often.
  • You combine multiple techniques for a domain compromise. Take notes during the course; you may use them during the exam.
  • Document as you go: take your screenshots and note your commands during the exam, not afterwards.

Reporting

After the practical part you have 48 hours to submit an exam report. In it you set out your enumeration steps, the vulnerabilities found, the techniques used with screenshots, the attack chain and your recommendations for remediation. The report counts just as heavily as the technical work and later comes in handy for your portfolio.

Conclusion

The CRTP is a strong course for anyone who wants to dive into Active Directory red teaming. The approach is practice-oriented, the labs are realistic and you learn techniques you rarely come across elsewhere. The certificate is widely recognised in the infosec community.

The course suits pentesters, security consultants and system administrators who want to understand the attacker’s side. Helpful prior knowledge: a basis in Windows and AD, PowerShell and some experience with pentesting.

The course is available through Altered Security, with 30 or 60 days or lifetime lab access plus exam. A shout-out to Nikhil Mittal for the quality of the material.

Ready to test your security?

Get in touch with no obligation. We are happy to think along about the best approach for your organisation.

Get in touch

Or email us directly at [email protected]

Related articles