CRTO Exam Prep & Study Resources

Zero Point Security certification · 1 product

Red Team Ops

Study materials for CRTO

Frequently asked questions

What is the CRTO certification?

The Certified Red Team Operator (CRTO) is a hands-on red team certification offered by Zero-Point Security, created by Daniel Sherlock (RastaMouse). It is based on the Red Team Ops course and focuses heavily on using Cobalt Strike as a command-and-control framework to simulate real adversary operations. CRTO validates practical skills in executing red team engagements within Active Directory enterprise environments.

How hard is the CRTO exam?

CRTO is considered intermediate in difficulty, sitting roughly between OSCP and OSEP in terms of overall challenge. The exam is a 48-hour practical assessment in an Active Directory lab environment where candidates must compromise multiple machines and achieve specific objectives using Cobalt Strike. Candidates who have thoroughly completed the Red Team Ops course and practiced the lab exercises should be well positioned to pass. The exam is fair and closely aligned with the course content.

What topics does CRTO cover?

CRTO covers essential red team operations topics including Cobalt Strike usage and beacon management, Active Directory enumeration and exploitation, lateral movement techniques, credential harvesting and abuse, Kerberos attacks (Kerberoasting, AS-REP roasting, delegation abuse), NTLM relay attacks, payload generation and delivery, persistence mechanisms, and data exfiltration. The course provides a strong practical foundation in C2-based operations within enterprise Windows environments.

How does CRTO compare to OSCP?

CRTO and OSCP test different skill sets with some overlap. OSCP focuses on individual machine exploitation across diverse platforms with minimal reliance on C2 frameworks. CRTO is specifically focused on Active Directory compromise using Cobalt Strike as the primary tool. CRTO is more directly applicable to real-world red team engagements, while OSCP provides a broader penetration testing foundation. Many professionals pursue both certifications, as they complement each other well.

How long does it take to prepare for CRTO?

Most candidates spend one to three months preparing for CRTO after purchasing the Red Team Ops course. Those with existing OSCP-level skills and Active Directory attack experience may be exam-ready within a few weeks of focused study. Candidates newer to Active Directory attacks should allow more time to practice the lab exercises and become comfortable with Cobalt Strike's interface and capabilities. Completing every lab exercise in the course is the single best preparation step.

What are the prerequisites for CRTO?

There are no formal prerequisites, but candidates should have a solid foundation in Windows and Active Directory concepts, basic penetration testing skills, and familiarity with common offensive tools. Holding the OSCP or having equivalent hands-on experience is strongly recommended. Candidates who are completely new to penetration testing will find the CRTO course material challenging, as it assumes baseline knowledge of exploitation techniques and post-exploitation methodology.

Is CRTO worth it?

CRTO is one of the best value certifications in the red team space. The course and exam are priced significantly lower than comparable offerings from OffSec or SANS, while providing directly applicable skills in Cobalt Strike and Active Directory attacks that are used daily in professional red team engagements. The certification is well respected in the offensive security community, and Cobalt Strike proficiency is a highly sought-after skill in red team job postings. For aspiring red teamers, CRTO is an excellent investment.

What is the CRTO exam format?

The CRTO exam is a 48-hour practical assessment in a fully configured Active Directory lab environment. Candidates receive access to a Cobalt Strike team server and must compromise a series of machines, collect flags, and achieve specified objectives. There is no report writing requirement, only flag submission. The exam environment resets periodically, so candidates should document their progress. The pass threshold requires collecting a specified number of flags out of the total available.

What study resources complement CRTO preparation?

The Red Team Ops course from Zero-Point Security is the primary study resource and is tightly aligned with the exam. Supplementary resources include the Cobalt Strike documentation and blog, HackTricks and HackTricks Cloud for Active Directory attack references, the SpecterOps blog for in-depth Active Directory research, and practice labs like HTB Pro Labs (RastaLabs is particularly relevant). Building a home Active Directory lab for Cobalt Strike practice is also highly beneficial.

What is the cost and retake policy for CRTO?

The Red Team Ops course with lab access and one exam attempt is typically priced around 400 GBP, making it one of the most affordable practical red team certifications available. Additional exam attempts can be purchased separately at a reduced price. There is a short cooling-off period between attempts. The pricing structure makes CRTO accessible to self-funded learners, which is a significant advantage over certifications that cost thousands of dollars.

Related

All Zero Point Security certifications · Browse cheatsheets