CRTP: RED TEAMING IN ACTIVE DIRECTORY WITH LOTL
CRTP is not about exploits or external tools it’s about creativity, strategy, and discipline. Living off the Land taken to the extreme to…
CRTP: RED TEAMING IN ACTIVE DIRECTORY WITH LOTL

CRTP is not about exploits or external tools it’s about creativity, strategy, and discipline. Living off the Land taken to the extreme to compromise Active Directory.
After passing the PNPT and the CPTS, I felt like I was on a good streak. I didn’t want to lose momentum, so I looked for another certification that would not only validate my skills but also bring me closer to what I do in Red Team operations. I had been eyeing the Certified Red Team Professional (CRTP) from Altered Security for a while, and I finally decided to go for it.
Context and Motivation
What attracted me most to the CRTP was its practical focus an exam where you simulate compromising a corporate network starting as a low-privileged user, with the final goal of taking over the Domain Controller, all while using PowerShell as your primary weapon. No Kali Linux or typical pentesting distros — just pure, real-world scenarios.
I wanted to strengthen my skills in Active Directory, improve persistence and lateral movement, sharpen my defense evasion, and especially take my PowerShell skills to the next level. That detail hooked me the exam forces you to think like a real attacker, relying on system tools and avoiding patchable exploits.
Preparation
Altered Security offers three different plans depending on your experience level:
- 3 months (Beginner) — $499
- 2 months (Intermediate) — $379
- 1 month (Expert) — $249
I went with the 1-month plan. Honestly, if you already have AD experience and have gone through similar certifications, one month is enough to prepare and tackle the exam.
The official material was very complete labs with 40 flags, a detailed step-by-step lab manual, course videos, slide decks, and written guides. Everything you need to train without searching for external resources.
As I solved the labs, I took notes in Notion to build my own cheatsheet with commands, attack vectors, and key techniques. Having everything centralized made it easier once the exam came.
The most valuable topics for me were Kerberos attacks, trust abuse between domains, and defense bypass. Those areas really helped me take my AD knowledge to another level.
The Exam
The CRTP exam gives you 24 hours of lab time plus 24 hours for reporting. I started on a Saturday at around 10:00 AM; after about 15 minutes, the lab was ready and the clock started ticking.
The objective compromise four machines and, finally, two Domain Controllers. You begin in an assumed breach scenario, meaning you start with low-privileged access on a Windows machine. From there, you need to escalate privileges and move across the network.
By around 5:00 PM, I had achieved the objective. It wasn’t smooth sailing the initial vector was easier than I expected, but the first jump to another machine gave me trouble. I knew what I had to do, but the technique wasn’t working until I realized a small mistake that was causing the failure. Once I corrected it, everything flowed better.
What I enjoyed the most was that the machines were fully patched, forcing you to rely on Living off the Land (LotL) techniques. If you want to practice bypassing defenses and truly think like an attacker, this exam delivers from start to finish.
The Report
After a break, that same evening I dedicated myself to the report. It took me about 2 hours to complete.
It wasn’t long (around 32 pages), but it was detailed exact commands, screenshots, and clear explanations of every step. Having gone through more demanding reports before, like the CPTS, really helped me complete it quickly and efficiently.
What CRTP Left Me
CRTP reinforced techniques that I now apply daily in Red Team engagements. It made me appreciate even more the scenarios where a low-privileged user can become the entry point to compromise an entire organization.
The biggest lesson was deepening my Living off the Land (LotL) skills. I learned to use them during the preparation and applied them in the exam, and now I keep using those same lessons in real-world engagements.
Advice for Future Candidates
- Recommendation: CRTP is an excellent entry point into Red Teaming and Active Directory. Altered Security’s plans adapt well to beginner, intermediate, and advanced levels.
- Mistakes to avoid: Don’t underestimate it. Some people say it’s “fun” or that they passed quickly, but if you get stuck or miss key techniques, it can get tough.
- Comparison: Compared to my latest certifications (PNPT and CPTS), I’d place the CRTP at #2 in difficulty and realism, right after the CPTS.
If you want to follow my next posts about certifications, HTB, and Red Team experiences, connect with me on LinkedIn.
메타데이터
- post_id
- 6ed14162e2a8
- slug
- crtp-red-teaming-in-active-directory-with-lotl-6ed14162e2a8
- url
- https://medium.com/@ericksilvestre03/crtp-red-teaming-in-active-directory-with-lotl-6ed14162e2a8
- canonical_url
- https://medium.com/@ericksilvestre03/crtp-red-teaming-in-active-directory-with-lotl-6ed14162e2a8
- author_url
- https://medium.com/@ericksilvestre03
- status
- ok
- fetched_at
- 2026-07-31 11:00:11