Passing the CRTO Exam

• Certification Exam, Active Directory, Red Teaming

Introduction #

This post covers my preparation and experience with the CRTO (Certified Red Team Operator) exam. The CRTO is a practical red team certification from Zero-Point Security focused on attacking on-prem Active Directory environments using the Cobalt Strike C2 framework. The exam is 48 hours over 4 days, not proctored, with no report required and unlimited free retakes.

CPTS points

Preparation #

The Course #

The course covers everything from setting up your C2 and evading defenses to moving through the network and ultimately compromising the domain. You do not need to complete the course before attempting the exam, but I would recommend going through all of it. The material covers topics like lateral movement, Kerberos abuse, domain trust, and evasion of Defender and AppLocker. The labs are done in a browser where you get to use Cobalt Strike. You could repeat a course lab twice in one day not long ago, but now a lab cannot be launched more than once a day.

Kerberos #

Kerberos is the longest and most detailed topic in the course, and the one I would spend the most time understanding. Focus on the reasoning behind each attack and how tickets are constructed, not just the commands. In a domain forest scenario, for example, you might request a ticket that looks correct but fails because of a subtle mistake in how you constructed it.

The attack path was right, but because you did not fully understand the structure behind the request, you start questioning whether you are even on the right track. Understanding what each part of the command is doing prevents that confusion.

Enumeration #

Before acting on anything, map out the environment properly. Running ldapsearch queries and using BloodHound to understand the domain structure, trust relationships, and object permissions gives you a clear picture of where to move next.

OPSEC #

Achieving the exam objective is not enough on its own. If your OPSEC is too noisy you will still fail, because a red teamer is not supposed to get caught. Almost every action has to be weighed with OPSEC in mind. You have to think thrice before you do anything. Uploading a tool that Defender flags, or a legitimate process behaving in a way it clearly should not, are both noisy actions that lead to detection.

Labs for Practice #

It is difficult to recommend a specific lab as the exam is unique, but to build a strong Active Directory foundation and gain familiarity with offensive tooling, I recommend the Active Directory section from the CPTS course by Hack The Box. I personally thought it was a great intro to attacking Active Directory. Focus on the topics that overlap with the CRTO course, though this may not be necessary if you are already comfortable with Active Directory.

For practicing lateral movement and tool usage, a red team pro lab like Zephyr is worth trying as it involves a lot of what the CRTO course teaches, like Kerberos abuse and pivoting.

Final Thoughts #

I liked the exam and think it is a great introduction to the world of red teaming and command-and-control frameworks. It has no web exploitation and stays entirely on-prem, and it led to plenty of dead ends and backtracking, so it felt like a maze at times.

It is a hard exam, but the course gives you everything you need. The catch is that there are no dedicated CRTO practice labs outside the course itself, so it is easy to go in without feeling confident even when you are ready.