Head to head

CARTP vs CRTP

Two redteam exams that come up together — how they actually differ, and who each one is for.

Take CRTP first if your targets are on-premises Active Directory and you want the fundamentals; it's the cheaper, entry-level starting point. Take CARTP when your organisation runs Azure and Entra ID and you need cloud attack paths. They cover different ground — on-prem AD versus cloud — so most people do CRTP, then CARTP, rather than choosing one.

CARTP
advanced, $449–$849 (USD) by 30/60/90-day lab access
CRTP
intermediate, $249–$499 (USD), by 30/60/90-day lab access
Harder
CARTP
CARTPCRTP
VendorAltered SecurityAltered Security
Leveladvancedintermediate
Duration24-hour exam + report24-hour exam + report
Formatcompromise resources across multiple Azure tenants, then a reporthands-on AD; OS command execution on all 5 targets, then a report
Cost$449–$849 (USD) by 30/60/90-day lab access$249–$499 (USD), by 30/60/90-day lab access

What each one is

CRTP (Certified Red Team Professional), from Altered Security, is an entry-level on-premises Active Directory red team course and exam. It teaches enumeration, privilege escalation, lateral movement, domain and forest trust abuse, and persistence against a Windows domain, largely with PowerShell and built-in tooling.

CARTP (Certified Azure Red Team Professional), also from Altered Security, is the cloud counterpart. It targets Azure and Entra ID (formerly Azure AD): abusing managed identities, service principals, enterprise applications, storage, and the on-prem-to-cloud connections that most real Azure tenants expose.

The real difference

The split is where the fight happens. CRTP lives entirely on-prem — domain controllers, Kerberos, ACLs, GPOs. CARTP lives in the cloud control plane — tokens, OAuth consent, role assignments, and identity misconfigurations. The skills overlap in mindset only; the tooling and attack surface are different. CARTP is generally described as rougher and less structured than CRTP, which reflects how messy cloud attack paths are in practice. If your environment is hybrid — and most are — the two together cover far more of a real estate than either alone.

Cost and time

CRTP runs $249–$499 depending on lab duration, with a 24-hour hands-on exam plus a written report. The certification is valid three years, and a retake is $99.

CARTP runs $449–$849 by lab length, with a 24-hour exam plus a report. Both are practical, assumed-breach style assessments — no multiple choice. CARTP is the pricier of the two, and reviewers commonly note its exam feels lighter than the course, so budget your effort toward learning the material rather than fearing the test.

Which one to choose

Choose CRTP if you are newer to AD attacks or your scope is on-prem Windows. It is the cheaper, more foundational course and the standard first step. Choose CARTP if you already understand identity attacks and your targets are Azure/Entra tenants. Because they cover separate ground, the common path is CRTP first for the fundamentals, then CARTP once you are attacking cloud — not one instead of the other. If you only have budget for one and your organisation is cloud-first, CARTP is defensible on its own.

What people who sat these say

Time has passed, and I figured it was time to dive into Azure. CARTP was a natural next step.
Guzzytook CRTP in 2023, then CARTP
I honestly did not expect the exam to be that easy and I had to email support to make sure I hadn't skipped anything.
Stefano Lanaroholds CRTP and CARTP

Full detail on each: CARTP · CRTP. For where both sit in a longer plan, see the roadmap.