Head to head

CRTO vs CRTP

Two redteam exams that come up together — how they actually differ, and who each one is for.

Take CRTP if you want cheap, foundational on-premises Active Directory skills built on PowerShell and native tooling. Take CRTO (Zero-Point Security) if you want adversary simulation with Cobalt Strike — C2, OPSEC, and evasion inside a defended network. They teach different things, so many people do both; if forced to pick, choose by whether you need AD fundamentals or C2 tradecraft.

CRTO
advanced, £399 (GBP), incl. licensed Cobalt Strike lab
CRTP
intermediate, $249–$499 (USD), by 30/60/90-day lab access
Harder
CRTO
CRTOCRTP
VendorZero-Point SecurityAltered Security
Leveladvancedintermediate
Duration48h runtime across a 4-day window24-hour exam + report
Formatassumed-breach CTF; capture 6 of 8 flags (75%); no written reporthands-on AD; OS command execution on all 5 targets, then a report
Cost£399 (GBP), incl. licensed Cobalt Strike lab$249–$499 (USD), by 30/60/90-day lab access

What each one is

CRTP (Certified Red Team Professional) from Altered Security is an entry-level on-premises Active Directory course and exam. It focuses on the fundamentals — enumeration, privilege escalation, lateral movement, Kerberos and trust abuse — largely through PowerShell and living-off-the-land tooling, in an assumed-breach scenario.

CRTO (Certified Red Team Operator) from Zero-Point Security, authored by Daniel Duggan (RastaMouse), teaches adversary simulation through a command-and-control framework. It ships with a licensed Cobalt Strike and drills the operator side of red teaming: beacons, malleable profiles, OPSEC, and evasion inside a monitored, defended AD network.

The real difference

CRTP teaches how AD attacks work; CRTO teaches how to run them like an operator. One is about understanding the domain and the manual techniques; the other is about tooling, tradecraft, and staying quiet against defenses. As one reviewer put it, CRTP focuses on a manual PowerShell approach while CRTO encourages the C2 frameworks and common tooling found in almost every real engagement. Neither replaces the other: CRTP gives you the AD understanding, CRTO gives you the Cobalt Strike and OPSEC muscle to apply it under monitoring.

Cost and time

CRTP costs $249–$499 depending on lab duration, with a 24-hour hands-on exam plus a written report, three-year validity, and a $99 retake.

CRTO is priced at £399 (GBP) and includes generous lab time. Its exam is a 48-hour effort within a four-day window, structured as a capture-the-flag: you need six of eight flags, and there is no written report. That format rewards operating cleanly through the environment rather than documenting methodology.

Which one to choose

Choose CRTP if you are newer to Active Directory and want affordable, foundational understanding of how domain attacks work. Choose CRTO if you specifically want C2 operation, Cobalt Strike fluency, and OPSEC against a defended network — it is widely rated as strong value once you already have grounding like OSCP or CRTP. They complement each other, so a common path is CRTP for the AD fundamentals followed by CRTO for the operator tradecraft. If you can only take one, decide by the gap you need to close: concepts, or C2.

What people who sat these say

which focus on a more manual approach and Powershell wizardry, RTO encourages the usage of C2 frameworks and other common tooling
V3dedCRTO holder
Cobalt Strike was so cool to use. I wish I can bring it with me for each challenge/engagements
amirr0rCRTO holder

Full detail on each: CRTO · CRTP. For where both sit in a longer plan, see the roadmap.