Skip to content

botesjuan/CRTO-Study-Notes

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

146 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

CRTO Study Notes 2026

OPSEC ROBOT

🔴 UNSAFE
🟠 CAUTION
🟢 SAFE

  • Red Team Ops remain undetected and avoiding security triggers.
  • Perform stealthy techniques that blends into normal activity, maintain a low profile.
  • Leverage trusted processes and native tools living off the land.
  • Reuse credentials tokens and tickets to impersonate legitimate users without knowing their passwords.
  • Mimicking normal behavior to evade antivirus.
  • Bypass endpoint defenses without alerting defenders.

CRTO Exam Practice using Course Labs Simulation

  1. Setup & Prepare Cobalt Strike
    Cobalt Strike Primer Setup Lab 🕒 30 Minutes | Attacker Desktop | User: Attacker

  2. Malleable C2 Profile and payloads, ThreatCheck binaries.
    Defence Evasion Lab 🕒 45 Minutes | Attacker, DC, Workstation, Web Server | User: pchilds

  3. Enumerate with provided credentials on workstation the AppLocker, UAC and Antivirus policies.
    AppLocker Challenge 🕒 45 Minutes | Attacker, DC, Workstation | User: pchilds

  4. On initial workstation use elevated access and get SYSTEM beacon.
    Initial Access Lab 🕒 45 Minutes | Attacker, DC, Workstation | User: pchilds

  5. Impersonate user on workstation using SYSTEM beacon.
    User Impersonation Lab 🕒 30 Minutes | Attacker, DC, Workstation, Web Server | Users: pchilds, rsteel

  6. Jump as user and spawn beacon on next target.
    Lateral Movement Lab 🕒 30 Minutes | Attacker, DC, Workstation, Web Server | Users: pchilds, rsteel

  7. Perform S4U technique on server to impersonate admin.
    Constrained Delegation Kerberos Lab 🕒 30 Minutes | Attacker, Workstation, DC, Web Server, File Server | User: pchilds

  8. On server impersonate user by abusing SQL DB owner permissions with payload.
    SQL Server Lab 🕒 45 Minutes (Attacker, Workstation, DC, SQL 1, SQL 2 | Users: pchilds, rsteel

  9. On server abuse SeImpersonatePrivilege and connect to localhost.
    SQL Server Lab 🕒 45 Minutes (Attacker, Workstation, DC, SQL 1, SQL 2 | Users: pchilds, rsteel

  10. With Domain Child Trust use Golden ticket impersonation and spawn beacon.
    Parent Child Trust Lab 🕒 30 minutes | Attacker, Dublin Workstation, Contoso DC, Dublin DC | User: DUBLIN\sguest

  11. On Domain Controller establish a DNS beacon for resilience.
    Elevated Persistence Lab 🕒 30 Minutes | Attacker, DC, Workstation | User: pchilds

  12. On Domain Controller use Golden inter-realm trust key for impersonation to spawn beacon.
    Inbound Trust Lab 🕒 30 minutes | Attacker, Contoso Workstation, Partner Jump Server, Contoso DC, Partner DC | User: PARTNER\vwebber

  13. Do Active Directory Discovery.
    Discovery Lab 🕒 30 Minutes | Attacker, DC, Workstation | Users: pchilds, rsteel

  14. S4U Constrained Delegation initial ticket technique Allowed To Delegate To
    Constrained Delegation Kerberos Lab 🕒 30 Minutes | Attacker, Workstation, DC, Web Server, File Server | User: pchilds

  15. Setup socks proxy to pivot to other network subnets.
    SOCKS Lab 🕒 30 Minutes | Attacker, Workstation, DC | Users: pchilds, rsteel

  16. RBCD Write Property Allowed To Act On Behalf Of Other Identity
    Kerberos Resource-Based Constrained Delegation Lab 🕒 30 Minutes | Attacker, Workstation, DC, File Server | User: pchilds

  17. Kerberos Constrained Delegation Service Name Substitution S4U alt service flag
    Kerberos Service Name Substitution Lab 🕒 30 Minutes | Attacker, Workstation, DC, File Server, Web Server | Users: pchilds,rsteel

  18. S4U2self self coercion based TGT capture Kerberos S4U2self 🕒 30 Minutes | Attacker, Workstation, DC, Web Server | Users: pchilds,rsteel

  19. Identify and exploit a Kerberos (mis)configuration, and move laterally to domain controller
    Kerberos Challenge 🕒 60 Minutes 🖥️ Attacker, LON-WKSTN-1, LON-DC-1 | Users: pchilds, Administrator, Machine Account 3e7

Key CRTO Labs⚠️


Red Team Ops Course Content


Exam Context


Attacker Desktop Tools & Resources

AdaptixC2

🇿🇦 22May2026 🇿🇦

About

crto-study-notes

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors