TL;DR - Should You Get CRTP in 2026?
CRTP (Certified Red Team Professional) is the most affordable Active Directory certification at $249-$499. Perfect for beginners wanting hands-on AD experience without the $1,649 OSCP price tag.
✅ Get CRTP if you:
- • Are new to Active Directory pentesting
- • Want affordable hands-on AD lab access
- • Need a beginner cert before OSCP/CRTO
- • Prefer unproctored, no-stress exams
- • Budget under $500 for certification
❌ Skip CRTP if you:
- • Already have OSCP or CRTO experience
- • Need HR-recognized cert for job applications
- • Want advanced evasion/OPSEC techniques
- • Prefer video-based learning over PDFs
- • Need cert with industry-wide name recognition
Bottom line: CRTP is the best value-for-money AD cert for beginners. It won't get you past HR filters like OSCP, but the practical skills are solid and the price is unbeatable. Treat it as a stepping stone, not a career-maker.
What is CRTP?
CRTP (Certified Red Team Professional) is an Active Directory penetration testing certification offered by Altered Security (formerly Pentester Academy). It's designed to teach practical AD attack techniques through hands-on labs and an unproctored 24-hour exam.
Core Topics
- • Active Directory enumeration (BloodHound, PowerView)
- • Kerberos attacks (Kerberoasting, AS-REP Roasting)
- • Privilege escalation techniques
- • DACL/ACL abuse (GenericAll, WriteDACL, etc.)
- • Delegation attacks (Unconstrained, Constrained)
- • Forest and domain trusts exploitation
Advanced Topics
- • Golden & Silver ticket attacks
- • Diamond ticket attacks
- • LAPS password theft
- • SQL Server trust abuse
- • Cross-forest attacks
- • Persistence techniques
📚 Course Structure
- Course Material: 250+ page PDF covering all attack techniques with command examples
- Lab Access: 30, 60, or 90 days of 24/7 access to a Windows Server 2022 AD environment
- Learning Objectives: 28 learning objectives to complete before the exam
- Tools Provided: Pre-configured Windows 11 student VM with all necessary tools
- Support: Discord community and instructor support via forums
⚠️ Updated for 2026
Altered Security updated the CRTP course in 2024-2025 to use Windows Server 2022 and Windows 11 environments, replacing the older Server 2019 labs. The course now covers modern AD attack techniques relevant to current enterprise environments.
Exam Format & Structure
How the Exam Works
- 1. Setup (1 hour): You receive VPN or Guacamole credentials to access a fully patched Windows Server 2022 AD environment with multiple domains and forests
- 2. Exam (24 hours): 5 target servers + 1 student foothold machine. Goal: OS level command execution on all 5 targets
- 3. Critical: No tools are provided on the attacker machine - you must bring your own toolkit and have your cheatsheet ready
- 4. Enumeration is Everything: Map trusts, GPO, accessible machines, tickets, delegations, services, user privileges. Screenshots are crucial!
- 5. Report (48 hours): After the 24-hour exam, you have 48 hours to submit a detailed report with screenshots, commands, and remediation recommendations (typically 27-117 pages)
- 6. Report Structure: Initial access → recon → privilege escalation → lateral movement → full forest compromise, with server-by-server breakdown
- 7. Results: Confirmation email within hours, pass/fail notification the following day. Certificate issued if successful
✅ Exam Advantages
- • Unproctored: No webcam monitoring, no stress from being watched
- • Full Toolset Allowed: Use any tools - no restrictions (but bring your own!)
- • Internet Access: Google commands, check notes, use ChatGPT - all allowed
- • VPN or Guacamole: Choose your preferred access method
- • 48-Hour Report Window: More time than OSCP's 24-hour report deadline
- • Assume-Breach Start: You start with Domain User access, skip initial foothold
⚠️ Exam Challenges
- • Bring Your Own Tools: No tools provided on attacker machine - come prepared!
- • Enumeration-Intensive: Must enumerate trusts, GPO, tickets, delegations, services, privileges
- • Screenshot Everything: With multiple terminals, easy to lose track of attack paths
- • Detailed Report Required: Vague "I ran Mimikatz and got DA" won't pass - need detailed writeup
- • Windows Defender Active: Must bypass MDE, MDI, and Windows Defender
- • Fully Patched: Server 2022, fully patched - no easy CVE wins
💡 2026 Exam Tips from Recent Pass Holders
Before the Exam
- • Create a comprehensive cheatsheet with copy-paste ready commands
- • Re-do the lab environment from scratch without notes to build muscle memory
- • Time yourself: aim to compromise all lab machines in 8-10 hours
- • Master BloodHound custom Cypher queries for finding attack paths
- • Understand WHY commands work, not just copy-paste them
During the Exam
- • Take screenshots of EVERYTHING - you'll thank yourself during report writing
- • Enumerate thoroughly before attacking - map all trusts, delegations, ACLs
- • Use organized notes to track what you've tried on each machine
- • Focus on misconfigurations, not vulnerabilities - this is feature abuse, not CVE hunting
- • Remember: assume-breach mindset, gradual move toward full forest compromise
Report Writing Guide
⏰ Report Timeline
📝 Report Structure (Must Include)
1. Executive Summary
High-level overview of findings and impact. Non-technical summary for management.
2. Overall Attack Path
Initial access → recon → privilege escalation → lateral movement → full forest compromise
3. Server-by-Server Breakdown
Detailed explanation for each compromise with screenshots and commands
4. Tool & Technique Documentation
Every tool used, every command run, with screenshots as proof
5. Remediation Recommendations
Practical mitigations for each vulnerability/misconfiguration found
✅ Report Best Practices
- • Screenshots are King: Every command, every result, every GUI interaction
- • Command Blocks: Format all commands in code blocks for readability
- • Explain WHY: Don't just show what you did - explain why it worked
- • 30-120 Pages Typical: Recent reports range from 27-117 pages
- • Use Templates: Many students use pre-made Markdown/LaTeX templates
❌ What Gets You Failed
- • Vague Descriptions: "I ran Mimikatz and got DA" is insufficient
- • Missing Screenshots: Claims without proof = instant fail
- • No Remediation: Report must include defensive recommendations
- • Incomplete Attack Paths: Must document every step from start to finish
- • Copy-Paste from Course: Examiners can tell - use your own words
Pricing & Options
- ✓ 30 days lab access
- ✓ Course PDF (250+ pages)
- ✓ 1 exam attempt
- ✓ Discord community
- ✓ Server 2022 AD environment
- ✓ 60 days lab access
- ✓ Course PDF (250+ pages)
- ✓ 1 exam attempt
- ✓ Discord community
- ✓ Server 2022 AD environment
- ✓ 90 days lab access
- ✓ Course PDF (250+ pages)
- ✓ 1 exam attempt
- ✓ Discord community
- ✓ Server 2022 AD environment
🆚 Price Comparison
| Certification | Price | Lab Duration |
|---|---|---|
| CRTP | $249-$499 | 30-90 days |
| CRTO | $499-$649 | 30-60 days |
| OSCP | $1,649 | 90 days |
| PNPT | $399 | Lifetime |
Study Path & Timeline
📅 Recommended Timeline (60 Days)
- • Read the entire CRTP course PDF (250 pages)
- • Set up your student VM and familiarize with tools
- • Complete TryHackMe AD modules
- • Watch IppSec's AD-focused HTB walkthroughs (Forest, Sauna)
- • Master BloodHound (run collectors, analyze paths)
- • Practice PowerView commands until muscle memory
- • Complete all 28 learning objectives
- • Focus on Kerberoasting and AS-REP Roasting
- • Understand GenericAll, WriteDACL, WriteOwner
- • Practice unconstrained and constrained delegation
- • Exploit cross-domain and cross-forest trusts
- • Practice ticket manipulation (Golden, Silver, Diamond)
- • Re-do the CRTP lab from scratch without notes
- • Time yourself: aim for 8-10 hours
- • Review your cheatsheet, ensure commands are copy-paste ready
- • Schedule your exam for a weekend
📚 Recommended Resources
Free Resources
Paid Resources
- • HackTheBox Pro Labs (RastaLabs, Dante)
- • TCM Security Practical Windows Privesc
- • TryHackMe AD Module (Wreath, Throwback)
- • HTB Academy Active Directory Enumeration
Tools & Setup (Bring Your Own!)
⚠️ CRITICAL: No Tools Provided!
Unlike many other certifications, CRTP does NOT provide tools on the attacker machine. You must bring your own toolkit and have everything configured before the exam starts. This is mentioned in multiple 2025-2026 reviews as a surprise for unprepared candidates.
Pro tip: During your lab time, create a toolkit USB/folder with all your tools pre-configured and tested. Upload it to the student VM on exam day during the 1-hour setup window.
Enumeration Tools
- ✓ BloodHound + SharpHound
- ✓ PowerView (PowerSploit)
- ✓ ADModule (AD PowerShell)
- ✓ ldapdomaindump
- ✓ PingCastle (optional)
Exploitation Tools
- ✓ Rubeus (Kerberos)
- ✓ Mimikatz
- ✓ Impacket suite
- ✓ PowerUpSQL
- ✓ Certify (ADCS)
Post-Exploitation
- ✓ CrackMapExec/NetExec
- ✓ Evil-WinRM
- ✓ Invoke-Obfuscation
- ✓ PowerShell Empire
- ✓ Custom scripts
🛠️ Recommended Exam Setup
- 1. Windows 11 VM provided by Altered Security with Domain User access
- 2. Your toolkit folder uploaded during 1-hour setup time
- 3. Multiple terminals/PowerShell windows for organized workflow
- 4. Screenshot tool configured and ready (Greenshot, Flameshot, etc.)
- 5. Note-taking app open (OneNote, CherryTree, Obsidian)
- 6. Cheatsheet with copy-paste commands easily accessible
Renewal & Validity
✅ Free Renewal!
CRTP certification is valid for 3 years from the date of issue. Unlike many certifications that charge for renewal, Altered Security offers FREE renewal before expiry.
🔄 Renewal Exam vs Initial Exam
| Duration | Initial: 24+1 hrs | Renewal: 8 hrs |
| Targets | 5 machines | 3 machines |
| Report | Required ✍️ | Not Required ✅ |
| Cost | $249-$499 | FREE |
📅 When to Renew
You can take the renewal exam anytime before your certification expires. Most people renew 6 months before expiry to avoid losing their certification status.
Note: The renewal exam simply requires you to submit the Domain Admin's NTLM hash as proof of domain ownership - much simpler than the initial exam!
2025-2026 Updates
🆕 What's New in 2026
CRTP Updates
- • Server 2022 Labs: Fully patched Windows Server 2022 + SQL Server 2017
- • Multiple Domains & Forests: Practice cross-trust attacks in realistic environments
- • Defender Evasion: Bypass Windows Defender, MDE, and MDI
- • Altered Security Prep App: New AI-powered mobile app for study
- • GitHub Study Notes: Community-driven CRTP notes repository
CRTE 2026 Revamp (Next Step)
- • Server 2025 Labs: Fully revamped with latest Windows Server
- • Credential Guard: Enabled on all machines for realistic challenges
- • No CRTP Overlap: Completely new content, lean and focused
- • Advanced Red Team: Modern OPSEC, MDE/MDI evasions, trust attacks
- • AD CS Attacks: Certificate Services exploitation techniques
💰 Pricing Updates (2026)
• On-Demand: $249 (30 days) | $379 (60 days) | $499 (90 days)
• Bootcamp (Instructor-Led): $299 for 30 days lab access + live sessions
• Bootcamp Schedule: Next bootcamp starts September 5th, 2026 (4 weeks, recordings included)
• Sales: Watch for Black Friday/Cyber Monday ~20-30% discounts (historically drops to $199)
🎯 Best value: Wait for sales, get 60-day access for ~$300
📚 New Study Resources (2025-2026)
- • GitHub CRTP Study Notes - Community-maintained notes
- • CRTP Study Guides: Commercial guides available on Fourthwall & LinkedIn
- • Mobile App: Altered Security Prep with AI features (Google Play)
- • Recent Reviews: Fresh April & February 2026 reviews on Medium
- • Bootcamp Recordings: Access to live session recordings with instructor Q&A
CRTP vs OSCP vs CRTO
| Feature | CRTP | CRTO | OSCP |
|---|---|---|---|
| Price | $249-$499 | $499-$649 | $1,649 |
| Exam Duration | 24 hours | 48 hours | 23h 45m |
| Report Required | Yes (48h) ⚠️ | No ✅ | Yes (24h) ⚠️ |
| Proctored | No ✅ | Yes ❌ | Yes ❌ |
| Difficulty | Beginner | Intermediate | Intermediate-Hard |
| Pass Rate | ~70-80% | ~60-70% | ~40-50% |
| HR Recognition | Low | Medium | High |
💡 Expert Recommendation
The best path for most people in 2026: CRTP → OSCP → CRTO
- 1. Start with CRTP ($249) - Learn AD fundamentals without breaking the bank
- 2. Get OSCP ($1,649) - Use your CRTP AD knowledge for the OSCP AD set. HR recognition matters
- 3. Add CRTO ($499) - Level up to red team operations with Cobalt Strike
Total: ~$2,400. Timeline: 6-9 months. Result: Triple-certified with beginner → intermediate → advanced progression.
Final Verdict
👍 Pros
-
💰
Unbeatable Price: At $249-$499, CRTP is the cheapest AD lab access
-
😌
Zero Stress Exam: Unproctored, no report, no webcam
-
🎯
Laser-Focused on AD: Learn one thing deeply
-
⚡
Quick to Complete: Most students pass in 30-60 days
-
📚
Solid Practical Skills: You'll actually know how to enumerate AD and abuse DACL
👎 Cons
-
🚫
Zero HR Recognition: Won't get you past ATS filters like OSCP/CEH
-
📖
PDF-Only Course: No video lectures. Not ideal for visual learners
-
🎭
No OPSEC/Evasion: Won't learn AV bypass or EDR evasion
-
🔧
No C2 Framework: No Cobalt Strike, no Sliver, no Mythic
-
📊
Narrow Scope: It's AD and only AD. Very siloed skillset
🎯 The Bottom Line
CRTP is a fantastic beginner cert for the price, but don't expect it to land you a job.
Think of CRTP as an investment in skills, not credentials. You'll learn real AD attack techniques for 85% less than OSCP. The practical knowledge is solid - you'll genuinely understand BloodHound, Kerberos attacks, and DACL abuse after completing it.
But here's the reality check: CRTP won't get you interviews. HR recruiters searching LinkedIn for "OSCP OR CEH OR CISSP" won't find your CRTP certification. It's invisible to Applicant Tracking Systems.
So who should get CRTP?
- • Students/beginners who want to learn AD attacks without spending $1,649 on OSCP
- • Career switchers who need to prove to themselves they can hack before committing to expensive certs
- • OSCP students who struggle with AD and need focused practice
- • Pentesters who want to fill AD knowledge gaps without formal training budgets
If you're on the fence, ask yourself: "Am I doing this to learn or to get hired?" If it's to learn, CRTP is the best value in cybersecurity training. If it's to get hired, save your money and go straight for OSCP.
Frequently Asked Questions
Is CRTP worth it in 2026?
Yes, if you're a beginner wanting to learn Active Directory attacks on a budget. At $249-$499, it's the cheapest way to get hands-on AD lab access with modern Server 2022 environments. However, it has minimal industry recognition compared to OSCP.
How hard is the CRTP exam?
CRTP is rated as beginner-friendly with a ~70-80% first-attempt pass rate. The exam requires you to compromise 4 out of 5 machines in 24 hours. If you complete all 28 learning objectives in the lab and understand BloodHound/PowerView, you should pass comfortably.
CRTP vs OSCP: Which should I get first?
Get CRTP first if: You're new to AD, on a tight budget, or want to build confidence before OSCP.
Go straight to OSCP if: You already understand AD basics, have $1,649 to spend, or need the cert for job applications. OSCP has 1000x better HR recognition.
Best path: CRTP ($249) → OSCP ($1,649) → CRTO ($499).
Can I use ChatGPT or Google during the exam?
Yes, absolutely! The CRTP exam is unproctored with no restrictions. You can use ChatGPT, Google commands, reference your notes, check PayloadsAllTheThings, or use any online resources. The exam tests your ability to apply knowledge, not memorize commands.
Will CRTP help me get a pentesting job?
Probably not on its own. CRTP has very low industry recognition - most HR departments haven't heard of it. However, the skills you learn (BloodHound, Kerberos attacks, DACL abuse) are absolutely relevant and will help in interviews where technical competency is tested. Consider CRTP as a learning tool that prepares you for OSCP.