CRTO Certification
HARD
Red Team Operations Zero-Point Security Cobalt Strike

CRTO

Certified Red Team Operator RTO-1

PPP Pricing

£159-399

Exam

48 hours

Lab Access

Lifetime

Attempts

Unlimited

Reviewed & Verified By

TL;DR

Updated May 2025

CRTO (Certified Red Team Operator) is Zero-Point Security's practical red team certification that teaches adversary simulation through Cobalt Strike. Unlike pentesting certs (OSCP, PNPT), CRTO focuses on stealth, persistence, OPSEC, and realistic C2 operations.

🎉 Major 2025-2026 Updates:

In May 2025, CRTO was completely rewritten by Daniel Duggan with a new platform (LearnWorlds), redesigned exam (85/100 to pass), and improved lab integration. The exam now runs within a 4-day window with 48 hours of lab runtime that you can pause for sleep/breaks.

2026 Update: Now includes unlimited exam attempts (7-day cooldown), lifetime course & lab access, and PPP-based pricing (£159.60 in India, £399 base) making it incredibly accessible worldwide.

✓ The Good

  • • Best Cobalt Strike training available ($5k+ value)
  • Unlimited exam attempts (7-day cooldown)
  • Lifetime course & lab access (no expiry)
  • PPP pricing - affordable worldwide (£159-399)
  • • Realistic red team scenarios (not CTF)
  • • 48-hour exam is generous & flexible
  • • Strong OPSEC focus

✗ The Bad

  • • Heavily Cobalt Strike-focused
  • • Requires solid Windows/AD foundation
  • • Not beginner-friendly (need OSCP-level)
  • • Less recognized than OSCP/OSEP
  • • Limited C2 framework diversity
  • • Course light on modern BOF techniques

💀 Bottom Line

CRTO is absolutely worth it if you're serious about red teaming and want to master Cobalt Strike. With the 2026 updates (unlimited exam attempts, lifetime access, PPP pricing), it's now one of the best value certifications in cybersecurity. The exam rewards planning, discipline, and stealth-focused execution. Not for beginners. Get OSCP or PNPT first, then level up to CRTO.

🎯 What is CRTO?

CRTO (Certified Red Team Operator) is a hands-on certification that simulates real adversary behavior in enterprise environments. Instead of exploiting quick wins like pentesting, you learn to establish persistent Command & Control (C2) infrastructure, evade EDR, and maintain long-term access while remaining undetected.

Red Team vs. Pentest

🔴 Red Team (CRTO)

  • • Goal-oriented (exfiltrate data, maintain access)
  • • OPSEC-first mindset
  • • Evade detection (EDR, blue team)
  • • Persistent C2 infrastructure
  • • Weeks/months timeline
  • • Simulate real APT adversaries

🔵 Pentesting (OSCP)

  • • Find as many vulns as possible
  • • Speed & coverage matter
  • • Detection less critical
  • • Quick shells & pivots
  • • Days/weeks timeline
  • • Test security posture

Cobalt Strike Focus

CRTO centers around Cobalt Strike, the industry-standard C2 framework used by red teams worldwide (and APT groups). You'll master:

  • Beacon configuration & listeners
  • Malleable C2 profiles (evasion)
  • SOCKS pivoting through beacons
  • SMB beacon chaining
  • Post-exploitation modules
  • Aggressor Script automation

💡 Cobalt Strike alone costs $5,900/year commercially. CRTO at $499 is an insane value for learning it.

Who Created CRTO?

CRTO was originally created by RastaMouse (Daniel Duggan), a well-known red teamer and author of "Adversarial Tactics: Red Team Operations." In May 2025, he completely rewrote the course with updated techniques, a new platform, and an improved exam format. Zero-Point Security maintains high-quality, community-driven training focused on real-world red team skills.

Exam Details

2025 Exam Format (Updated May 2025)

1

🎯 Objective

Compromise an enterprise Active Directory environment and earn 85 out of 100 points to pass. The exam tests realistic red team operations: initial access → privilege escalation → lateral movement → domain dominance → exfiltration.

2

⏱️ Duration & Window

You get 48 hours of lab runtime within a 4-day calendar window. This means you can pause your lab anytime to sleep, take breaks, research techniques, or plan your next move. The 4-day window starts when you launch the exam.

💡 Why This Matters:

Unlike traditional 24-hour exams, CRTO simulates a real engagement. You're not expected to rush - treat it like actual red team work. Sleep, reset mentally, and approach with a clear head.

3

🛡️ Environment

Fully patched Windows Active Directory domain with realistic defensive measures:

  • AppLocker (application whitelisting)
  • Windows Defender / EDR solutions
  • Network segmentation & firewalls
  • Restrictive user permissions (least privilege)
  • Security logging & monitoring (simulated blue team)
4

📊 Scoring System

The exam is scored out of 100 points. Different objectives award different point values based on difficulty and criticality. You need 85+ points to pass.

Your Progress 85/100 to pass
5

🎯 Exam Goal

Your objective is to create a file named rto.txt on the final machine. No flag submission or written report required. Focus on pwning, not writing.

6

♾️ Unlimited Attempts (2026 Update)

You now get unlimited exam attempts with your course purchase! If you don't pass, you can retake the exam as many times as needed. There's a 7-day cooling-off period between attempts to allow time to study and improve.

💡 Why This is Huge:

This removes the pressure of a one-shot exam. You can take the exam, learn from mistakes, study what you missed, and try again. No additional fees. This makes CRTO one of the most learner-friendly certifications available.

Pre-2025 vs. 2025 Format

Aspect Old (Pre-May 2025) New (May 2025+)
Scoring Create rto.txt file 85/100 points
Platform Separate lab login Integrated (LearnWorlds)
Report No report required Still no report ✓
Course Access Limited duration Lifetime note access
Exam Pause Yes (4-day window) Yes (same flexibility)

2025 Community Feedback

"Passing the new CRTO exam with a 100/100 score confirmed that the course rewards planning, discipline, and stealth-focused execution." - Razzle Mouse, 2025

"The May 2025 update significantly improved the platform and exam format. The course is well-maintained with lifetime access to notes." - Community Review, 2025

"CRTO 2025 is NOT a beginner-level certification. You need solid Windows/AD knowledge before attempting." - _Paradox, Medium 2025

Prerequisites

CRTO is NOT for beginners. You need a solid foundation in Windows, Active Directory, and basic pentesting before tackling red team operations.

Required Skills

  • 1

    Windows & Active Directory

    Understanding of AD concepts: domains, forests, trusts, GPOs, Kerberos, NTLM, LDAP

  • 2

    Basic Pentesting

    Enumeration, exploitation, privilege escalation, lateral movement basics

  • 3

    PowerShell & CMD

    Comfortable writing basic scripts, understanding common commands

  • 4

    Networking Fundamentals

    TCP/IP, DNS, SMB, HTTP/HTTPS, proxying, pivoting concepts

Recommended Background

  • OSCP or PNPT Certification

    Proves you have pentesting fundamentals down

  • HackTheBox / TryHackMe Experience

    Completed AD boxes, Pro Labs (RastaLabs, Offshore)

  • Real-World Pentesting

    1-2 years in security, pentesting, or SOC work

  • Home AD Lab

    Built and broken your own AD environment

🗺️ Recommended Learning Path

Start

eJPT / BTL1

Then

OSCP / PNPT

Finally

CRTO

Advanced

CRTE / OSEP

⚠️ Don't Skip the Fundamentals

Multiple 2025 reviewers emphasized that CRTO is not beginner-friendly. The exam requires external research beyond course notes and expects you to figure things out independently. If you struggle with basic Windows/AD exploitation, you will fail the exam. Get OSCP or equivalent experience first.

Pricing: PPP-Based Global Access

Zero-Point Security uses Purchasing Power Parity (PPP) pricing, making CRTO accessible worldwide. The price adjusts based on your country's cost of living.

What You Get (One-Time Payment)

Lifetime Course Access

Full Red Team Ops course with lifetime updates

Lifetime Lab Access

20+ lab machines, no expiry date

Unlimited Exam Attempts

Free retakes with 7-day cooldown

Cobalt Strike License

For course/lab use (training license)

PPP Pricing Examples (2026)

🇬🇧 United Kingdom (Base Price)

Standard rate

£399

🇮🇳 India

PPP adjusted (~60% discount)

£159.60

🇺🇸 United States

PPP adjusted

~£340-380

🌍 Other Countries

Varies by local purchasing power

Check website

💡 Visit the official course page to see your local pricing. It's automatically calculated based on your location.

🏆

Incredible Value

Cobalt Strike alone costs $5,900/year. Getting CS training + cert + lifetime access for £159-399 is insane ROI.

♾️

Unlimited Attempts

No stress about failing. Take the exam, learn, improve, and try again. No extra fees.

🌍

Global Access

PPP pricing makes red team training accessible to students worldwide, not just wealthy countries.

No Hidden Costs

Unlike OSCP's subscription model ($2,749/year Learn One), CRTO is a one-time payment with lifetime access. No renewals, no lab extensions to purchase, no retake fees. Pay once, learn forever.

Total Cost: £159-399 (one-time)

Study Path & Timeline

Most students spend 2-4 months on CRTO, depending on prior experience. Here's how to structure your study time.

🐢

Beginner Route

3-4 months

If you're new to red teaming or Cobalt Strike

  • • Complete all labs slowly
  • • Take detailed notes
  • • Build home AD lab
  • • Practice with Defender ON
🏃

Intermediate Route

6-8 weeks

If you have OSCP or solid AD knowledge

  • • Focus on Cobalt Strike
  • • Complete all labs once
  • • Practice OPSEC scenarios
  • • Master malleable C2

Advanced Route

3-4 weeks

If you're already a pentester/red teamer

  • • Speed through material
  • • Practice exam chains
  • • Refine OPSEC
  • • Book exam ASAP

📅 Realistic 8-Week Study Plan

W1-2

Foundations & Cobalt Strike Basics

Complete external recon, initial access, and Cobalt Strike fundamentals modules. Set up team server, understand beacons & listeners.

W3-4

Active Directory Exploitation

Kerberoasting, AS-REP roasting, delegation attacks, DCSync, Golden/Silver tickets. Master BloodHound paths.

W5-6

Pivoting & OPSEC

SOCKS pivoting, SMB beacons, malleable C2 profiles, EDR evasion, process injection, in-memory execution.

W7

Practice with AV Enabled

Redo ALL exercises with Windows Defender enabled. Fix broken techniques. This is CRITICAL for exam success.

W8

Full Attack Chains

Complete multi-hop attack chains on lab machines. Practice creating the rto.txt file. Schedule exam.

Critical Advice from 2025 Passers

1. Redo all labs with Defender enabled. The exam has AV/EDR. If your exploits work with Defender off but fail with it on, you're not ready.

2. The course doesn't cover everything. Expect to research external resources during the exam. Practice Googling techniques independently.

3. OPSEC matters in the exam. Failing detection checks can lock you out. Practice stealth from day one.