CRTE vs CRTP
Two redteam exams that come up together — how they actually differ, and who each one is for.
If you're new to Active Directory attacks, start with CRTP — it teaches the fundamentals and is cheaper. Take CRTE once you're comfortable with single-domain compromise and want the advanced sibling: multi-domain, multi-forest environments, trust abuse, and tougher tradecraft. CRTE is a genuine step up, not an alternative, so most people do CRTP first, then CRTE.
- CRTE
- advanced, $299–$699 (USD) by 30/60/90-day lab access
- CRTP
- intermediate, $249–$499 (USD), by 30/60/90-day lab access
- Harder
- CRTE
| CRTE | CRTP | |
|---|---|---|
| Vendor | Altered Security | Altered Security |
| Level | advanced | intermediate |
| Duration | 48-hour exam + report | 24-hour exam + report |
| Format | multi-domain, multi-forest AD; escalate from a low-privileged user, then a report | hands-on AD; OS command execution on all 5 targets, then a report |
| Cost | $299–$699 (USD) by 30/60/90-day lab access | $249–$499 (USD), by 30/60/90-day lab access |
What each one is
CRTP (Certified Red Team Professional) from Altered Security is the entry point to on-premises Active Directory attacks: enumeration, privilege escalation, lateral movement, Kerberos abuse, and basic trust attacks within a single domain, mostly using PowerShell and native tooling.
CRTE (Certified Red Team Expert), also Altered Security, is the advanced sibling. It assumes you can already compromise a domain and pushes into enterprise-scale environments — multiple domains and forests, deeper trust and delegation abuse, and evasion of defenses across a larger, more realistic estate.
The real difference
Same publisher, same on-prem AD focus — CRTE simply goes further. CRTP proves you can take a single domain; CRTE proves you can navigate a fully-patched multi-domain, multi-forest network by abusing functionality and trust relationships rather than exploits. Reviewers who hold both describe CRTE as a deeper dive into the internals behind each attack path. Honest caveat: if you already have strong AD experience, parts of CRTE can feel like consolidation rather than brand-new ground — the value is the scale and the trust chains, not exotic new tricks.
Cost and time
CRTP costs $249–$499 by lab duration, with a 24-hour exam plus a written report, three-year validity, and a $99 retake.
CRTE costs $299–$699 by lab length, with a longer 48-hour exam plus a report across a network of several fully-patched Windows servers spanning multiple domains. The extra exam time reflects the larger environment: more machines, more trust hops, more to document. Both exams are hands-on and assumed-breach; neither uses multiple choice.
Which one to choose
Choose CRTP if you are starting out or want the cheapest solid grounding in AD attacks — it is the prerequisite mindset for everything above it. Choose CRTE when single-domain compromise is routine and you want to operate across forests and trusts at enterprise scale. They are a ladder, not a fork: CRTP first, CRTE second. Skipping straight to CRTE is possible if you already have real AD red team experience, but for most people CRTP builds the foundation CRTE then extends.
What people who sat these say
the CRTE took a deeper dive into complex concepts and the internals behind every attack path
I decided to skip the beginner Certified Red Team Professional (CRTP) course and head straight for CRTE.
Full detail on each: CRTE · CRTP. For where both sit in a longer plan, see the roadmap.