CRTP Exam Prep & Study Resources

Altered Security certification · 2 products

Certified Red Team Professional

Study materials for CRTP

Frequently asked questions

What is CRTP?

CRTP (Certified Red Team Professional) by Altered Security is a hands-on Active Directory security certification focused on real-world AD enumeration, exploitation, lateral movement, and persistence techniques. The course teaches candidates how to attack AD environments using tools like PowerView, BloodHound, Mimikatz, and Rubeus in a dedicated lab environment. CRTP is widely recommended for security professionals who want to build solid Active Directory attack skills before tackling more advanced certifications like OSEP or CRTE.

How hard is CRTP?

CRTP is intermediate in difficulty, making it an accessible but substantive credential for professionals transitioning into Active Directory-focused pentesting or red team roles. The 24-hour practical exam requires successfully chaining multiple AD attack techniques to compromise the exam environment, it is not trivial, but candidates who have completed the course labs thoroughly and practiced the attack chains will generally find the difficulty manageable. CRTP strikes a good balance between being achievable for motivated candidates and genuinely testing practical AD attack skills.

What Active Directory topics does CRTP cover?

CRTP covers a comprehensive range of Active Directory attack techniques. Topics include domain enumeration using BloodHound and PowerView, Kerberoasting and AS-REP roasting, DCSync for credential extraction from domain controllers, Golden and Silver Ticket attacks for persistence and lateral movement, ACL and ACE-based privilege escalation, PowerShell constrained language mode bypass, AppLocker bypass techniques, delegation abuse (unconstrained and constrained), and domain persistence mechanisms including AdminSDHolder abuse and skeleton key implantation.

Prerequisites for CRTP?

Basic Windows and Active Directory administration knowledge is the primary prerequisite for CRTP. Familiarity with PowerShell is helpful since many of the tools used in the course are PowerShell-based. No advanced hacking experience is strictly required, but having basic pentesting knowledge at the eJPT or PJPT level will make the course easier to follow. Candidates who understand how Active Directory authentication works conceptually, users, groups, domain controllers, Kerberos, will have a significantly easier time absorbing the attack techniques taught in CRTP.

Is CRTP worth it?

Yes. CRTP is one of the best-value Active Directory attack certifications available, particularly for security professionals preparing for OSEP, CRTE, or senior penetration testing roles. The Altered Security lab environment is well-designed and realistic, the course is highly practical, and the 24-hour exam genuinely tests whether you can execute AD attack chains under pressure. Many OSCP holders pursue CRTP as their next certification specifically because it fills the AD-focused gap that OSCP only partially addresses.

CRTP vs CRTE, what is the difference?

CRTP and CRTE are both Altered Security Active Directory certifications but differ substantially in complexity and scope. CRTP is the entry-level offering, covering single-domain Active Directory attack techniques appropriate for professionals new to AD exploitation. CRTE (Certified Red Team Expert) is the advanced follow-on, covering multi-domain and multi-forest attack scenarios, forest trust exploitation, ADCS attacks, and more sophisticated persistence techniques. CRTP is the logical prerequisite before CRTE, providing the foundational AD attack skills that CRTE builds upon.

How long to prepare for CRTP?

Two to four weeks of focused preparation is typically sufficient for candidates with basic pentesting experience. The included lab time covers all course material and the labs are designed to give you hands-on practice with every technique before the exam. Candidates who work through the lab exercises methodically, practice the full attack chain multiple times, and understand why each technique works, not just how to execute it mechanically, will be well prepared for the 24-hour exam.

Related

All Altered Security certifications · Browse cheatsheets