CRTO vs CRTP
Two redteam exams that come up together — how they actually differ, and who each one is for.
Take CRTP if you want cheap, foundational on-premises Active Directory skills built on PowerShell and native tooling. Take CRTO (Zero-Point Security) if you want adversary simulation with Cobalt Strike — C2, OPSEC, and evasion inside a defended network. They teach different things, so many people do both; if forced to pick, choose by whether you need AD fundamentals or C2 tradecraft.
- CRTO
- advanced, £399 (GBP), incl. licensed Cobalt Strike lab
- CRTP
- intermediate, $249–$499 (USD), by 30/60/90-day lab access
- Harder
- CRTO
| CRTO | CRTP | |
|---|---|---|
| Vendor | Zero-Point Security | Altered Security |
| Level | advanced | intermediate |
| Duration | 48h runtime across a 4-day window | 24-hour exam + report |
| Format | assumed-breach CTF; capture 6 of 8 flags (75%); no written report | hands-on AD; OS command execution on all 5 targets, then a report |
| Cost | £399 (GBP), incl. licensed Cobalt Strike lab | $249–$499 (USD), by 30/60/90-day lab access |
What each one is
CRTP (Certified Red Team Professional) from Altered Security is an entry-level on-premises Active Directory course and exam. It focuses on the fundamentals — enumeration, privilege escalation, lateral movement, Kerberos and trust abuse — largely through PowerShell and living-off-the-land tooling, in an assumed-breach scenario.
CRTO (Certified Red Team Operator) from Zero-Point Security, authored by Daniel Duggan (RastaMouse), teaches adversary simulation through a command-and-control framework. It ships with a licensed Cobalt Strike and drills the operator side of red teaming: beacons, malleable profiles, OPSEC, and evasion inside a monitored, defended AD network.
The real difference
CRTP teaches how AD attacks work; CRTO teaches how to run them like an operator. One is about understanding the domain and the manual techniques; the other is about tooling, tradecraft, and staying quiet against defenses. As one reviewer put it, CRTP focuses on a manual PowerShell approach while CRTO encourages the C2 frameworks and common tooling found in almost every real engagement. Neither replaces the other: CRTP gives you the AD understanding, CRTO gives you the Cobalt Strike and OPSEC muscle to apply it under monitoring.
Cost and time
CRTP costs $249–$499 depending on lab duration, with a 24-hour hands-on exam plus a written report, three-year validity, and a $99 retake.
CRTO is priced at £399 (GBP) and includes generous lab time. Its exam is a 48-hour effort within a four-day window, structured as a capture-the-flag: you need six of eight flags, and there is no written report. That format rewards operating cleanly through the environment rather than documenting methodology.
Which one to choose
Choose CRTP if you are newer to Active Directory and want affordable, foundational understanding of how domain attacks work. Choose CRTO if you specifically want C2 operation, Cobalt Strike fluency, and OPSEC against a defended network — it is widely rated as strong value once you already have grounding like OSCP or CRTP. They complement each other, so a common path is CRTP for the AD fundamentals followed by CRTO for the operator tradecraft. If you can only take one, decide by the gap you need to close: concepts, or C2.
What people who sat these say
which focus on a more manual approach and Powershell wizardry, RTO encourages the usage of C2 frameworks and other common tooling
Cobalt Strike was so cool to use. I wish I can bring it with me for each challenge/engagements
Full detail on each: CRTO · CRTP. For where both sit in a longer plan, see the roadmap.