Red Team Level 2
MotiGraph
Track

Red Team Level 2

The jump from penetration tester to red team operator: an integrated CRTP, PNPT and CRTO preparation path across enterprise Active Directory, professional network engagements, Command & Control and OPSEC.

25 Courses
140 Lessons
202 Hours
26 Weeks
Advanced Level
  • Red Team
  • Active Directory
  • Cobalt Strike
  • C2
  • CRTP
  • PNPT
  • CRTO
  • Adversary Simulation
About This Track

What You Are Signing Up For

This is the second level of the Red Team route, and it changes the question. Level 1 asked how you break into a system; Level 2 asks how you operate inside an enterprise once you are in. You go deep on Active Directory the way CRTP demands — architecture, enumeration as attack-path mapping, Kerberos, delegation, trusts, AD CS and domain dominance — then run full external-to-internal engagements the way PNPT measures, and finally move into red team operations proper with CRTO: Command & Control, Cobalt Strike, OPSEC and detection-aware tradecraft. It is thirty percent theory and seventy percent hands-on, in enterprise AD labs, internal network labs and C2 labs, and it ends with a full enterprise adversary simulation against a multi-domain forest.

  • One continuous route across CRTP, PNPT and CRTO — enterprise AD, professional engagements and C2.
  • Seventy percent hands-on in enterprise AD, internal network and C2 labs.
  • Real red team tradecraft: Cobalt Strike, C2 infrastructure, OPSEC and detection awareness.
  • Ends with a full enterprise adversary simulation across a multi-domain forest.

What You Will Be Able to Do

  • Enumerate an enterprise Active Directory and map complete attack paths.
  • Escalate from a low-privilege domain user to Domain and Enterprise Admin.
  • Execute Kerberos attacks: Kerberoasting, AS-REP roasting and delegation abuse.
  • Abuse domain and forest trusts, AD CS and SQL Server links to cross boundaries.
  • Run a professional external-to-internal engagement and write the report and debrief.
  • Stand up C2 infrastructure and operate a Beacon with OPSEC in mind.
  • Move laterally and establish persistence the way an adversary would, inside a lab.
  • Reason about what the blue team sees, not only whether the exploit worked.

Requirements

  • Red Team Level 1, or equivalent hands-on experience.
  • Solid networking, Linux and Windows.
  • Comfort with enumeration, exploitation and both privilege-escalation surfaces.
  • Active Directory fundamentals and basic pivoting.
  • This is not a beginner track — it starts where Level 1 ends.

Who It Is For

  • Graduates of Level 1 ready to move from pentesting to red teaming.
  • Junior and working penetration testers.
  • Internal pentesters and security consultants.
  • Offensive security analysts and SOC analysts crossing to the red side.
  • Anyone specialising in Active Directory.
  • Anyone targeting CRTP, PNPT or CRTO.

This is a preparation and training track. It builds the knowledge and practical skills the CRTP, PNPT and CRTO paths are built on, but it does not award those certifications: their official exams and requirements are separate. All practical work — including Command & Control, evasion and data-collection exercises — is carried out in authorised, isolated lab environments only, never against systems you do not own or have explicit permission to test.

Skills

What You Will Learn

Enterprise Active Directory

  • AD architecture: forests, trees, trusts and security descriptors
  • Enumeration as attack-path mapping, not a checklist
  • Offensive PowerShell and .NET tradecraft
  • ACL, ACE and object-permission abuse
  • Group Policy and delegation abuse

Kerberos & Domain Escalation

  • Kerberos architecture and the authentication flow
  • Kerberoasting and AS-REP roasting
  • Unconstrained, constrained and resource-based delegation
  • Domain and Enterprise Admin attack paths
  • AdminSDHolder and protected groups

Trusts, AD CS & Persistence

  • Domain and forest trust abuse and cross-forest paths
  • AD CS and certificate-based privilege escalation
  • SQL Server links and cross-system attack paths
  • Kerberos persistence: Golden, Silver and Diamond tickets
  • ACL-based and SSP persistence concepts

Professional Engagements

  • OSINT and external attack-surface discovery
  • External penetration testing to initial access
  • Internal network penetration testing to domain compromise
  • Professional reporting, attack narrative and live debrief

Red Team Operations

  • Adversary simulation versus emulation and engagement planning
  • Command & Control architecture, listeners and redirectors
  • Cobalt Strike and Beacon operations
  • OPSEC, host and network indicators, and detection surface
  • Defense-evasion fundamentals: AMSI, EDR and Defender awareness
Hands On

What You Will Build

Every project below is yours to keep and to show. By the end you have a portfolio, not a certificate alone.

Enterprise Labs

  • Enterprise AD lab: low-privilege user to Domain Admin
  • Trust lab: child domain to forest root and Enterprise Admin
  • External-to-internal engagement: OSINT to domain compromise
  • C2 lab: infrastructure, redirectors and Beacon operations
  • OPSEC lab: operating against a monitored environment

Adversary Simulation

  • A full campaign chaining CRTP, PNPT and CRTO skills into one workflow
  • A multi-domain forest with a DMZ, internal network and forest trust
  • Fourteen phases from OSINT through to an executive debrief

Graduation Project

You finish with a full enterprise adversary simulation against a multi-domain forest that mirrors a real organisation: an external host and DMZ, a web server and VPN gateway, an internal network of workstations, servers and SQL, an Active Directory domain behind a domain controller, and a forest trust to a second domain. You work fourteen phases — OSINT, external recon, initial access, host enumeration, privilege escalation, credential access, lateral movement, Active Directory, domain privilege escalation, trust analysis, objective completion, evidence, a professional report and an executive debrief — operating as a red team operator throughout, not a CTF player.

The Roadmap

Your Path Through This Track

Red Team Level 2 roadmap
The Route

Course by Course

25 modules · 140 lessons. Open any module to see what is inside it.

  1. 01 CRTP Foundation Advanced Active Directory Architecture Intermediate 6 lessons 8 hours

    You attacked a domain in Level 1; here you learn how an enterprise directory is really built, because you cannot map an attack path through a structure you do not understand. Forests, trees, trusts, the global catalog, and the security descriptors —

    • Active Directory
    • Forest
    • Trusts
    • CRTP
    • Forests, trees, domains and the global catalog
    • Domain controllers, OUs and Group Policy
    • LDAP, Kerberos, NTLM and DNS in the enterprise
    • Trust relationships and their direction
    • Security principals: SIDs and RIDs
    • ACLs, ACEs and security descriptors
    Open course
  2. 02 CRTP · PNPT · CRTO Advanced AD Enumeration Intermediate 6 lessons 8 hours

    Enumeration in an enterprise is not a checklist, it is cartography. You learn to turn users, groups, sessions, ACLs, SPNs and trusts into a single readable graph — the attack path from a low-privilege user to Domain Admin — before touching anything.

    • Enumeration
    • Attack Path
    • BloodHound
    • CRTP
    • Enumerating users, groups and computers
    • Sessions, logged-on users and shares
    • SPNs, service accounts and privileged groups
    • ACLs, object permissions and GPOs
    • Trust enumeration
    • Attack-path mapping with BloodHound
    Open course
  3. 03 CRTP PowerShell and .NET Tradecraft Advanced 6 lessons 8 hours

    The operator toolset, and the logging that watches it. Offensive PowerShell and .NET for enumeration and execution, and — just as important — the security controls you will meet: AMSI, script block logging and constrained language mode, understood we

    • PowerShell
    • .NET
    • AMSI
    • CRTP
    • PowerShell for offensive enumeration
    • PowerShell objects, pipeline and remote execution
    • PowerShell security controls and logging
    • AMSI, script block logging, constrained language mode
    • .NET security concepts and assemblies
    • In-memory execution and loaders (concepts)
    Open course
  4. 04 CRTP Windows Enterprise Privilege Escalation Advanced 6 lessons 8 hours

    Local administrator on one host is not the goal now; it is a step in a larger path. Service abuse, token and privilege concepts, credential discovery and application misconfiguration — escalation seen as part of an enterprise attack path rather than

    • Windows
    • PrivEsc
    • Services
    • CRTP
    • Local admin discovery and service abuse
    • Token and privilege concepts
    • Credential discovery on the host
    • Application misconfiguration and local security policy
    • Services, scheduled tasks and whitelisting concepts
    • Escalation as part of an attack path
    Open course
  5. 05 CRTP Credential Access and Credential Abuse Advanced 6 lessons 8 hours

    In an enterprise, credentials are the movement. Where Windows stores them, how password reuse and cached credentials open doors, and how a discovered hash or ticket becomes the next hop of lateral movement or privilege escalation.

    • Credentials
    • NTLM
    • Kerberos
    • CRTP
    • Credential hunting and Windows credential stores
    • NTLM, Net-NTLM and Kerberos credentials
    • Password reuse and cached credentials
    • Service-account credentials and sessions
    • Credential replay concepts
    • From credentials to movement
    Open course
  6. 06 CRTP Kerberos Attacks Advanced 6 lessons 10 hours

    One of the deepest parts of CRTP, and one of the most productive in a real domain. Kerberos not as a protocol diagram but as an attack surface: the ticket flow, Kerberoasting and AS-REP roasting, and the three kinds of delegation that hand an attacke

    • Kerberos
    • Kerberoasting
    • Delegation
    • CRTP
    • Kerberos architecture and the authentication flow
    • TGT, TGS, SPNs and service accounts
    • Kerberoasting
    • AS-REP roasting
    • Unconstrained delegation
    • Constrained and resource-based delegation
    Open course
  7. 07 CRTP · PNPT Active Directory Privilege Escalation Advanced 6 lessons 10 hours

    The heart of CRTP: starting as a low-privilege domain user and building a path to Domain Admin out of misconfigurations. Group-membership and ACL abuse, GPO and delegation abuse, and the protected-group machinery — AdminSDHolder — that both defends a

    • Active Directory
    • ACL Abuse
    • GPO
    • CRTP
    • Group membership abuse
    • ACL and ACE abuse, object permissions
    • GPO abuse
    • Delegation abuse in practice
    • Protected groups and AdminSDHolder
    • Lab: domain user to Domain Admin
    Open course
  8. 08 CRTP · PNPT · CRTO Lateral Movement Advanced 6 lessons 8 hours

    Walking a credential across a network. The technologies that carry execution — SMB, WMI, WinRM, PsExec, DCOM, PowerShell Remoting — and the credential-reuse techniques, Pass-the-Hash and Pass-the-Ticket, that turn one compromised workstation into a r

    • Lateral Movement
    • Pass-the-Hash
    • WinRM
    • CRTP
    • CRTO
    • SMB, WMI and remote services
    • WinRM, WinRS and PowerShell Remoting
    • PsExec and DCOM
    • Pass-the-Hash
    • Pass-the-Ticket
    • Lab: PC to server to DC
    Open course
  9. 09 CRTP · CRTO Persistence in Enterprise AD Advanced 6 lessons 8 hours

    How an adversary keeps a domain once they own it — studied so you can find and analyse it, inside a lab. Kerberos-based persistence, the ticket family (Golden, Silver, Diamond), AdminSDHolder and ACL-based persistence, and the concepts behind Skeleto

    • Persistence
    • Golden Ticket
    • Silver Ticket
    • CRTP
    • Kerberos-based domain persistence
    • Golden tickets
    • Silver and Diamond tickets
    • AdminSDHolder and ACL-based persistence
    • Skeleton Key and custom SSP concepts
    • Detecting persistence in a lab
    Open course
  10. 10 CRTP Active Directory Trusts Advanced 6 lessons 8 hours

    A forest is not one domain, and the trusts between domains are attack paths in their own right. Domain and forest trusts, parent-child relationships, trust keys, SID filtering and selective authentication, and the cross-domain and cross-forest paths

    • Trusts
    • Forest
    • Enterprise Admin
    • CRTP
    • Domain and forest trusts
    • Parent/child domains and trust keys
    • SID filtering and selective authentication
    • Cross-domain attack paths
    • Cross-forest concepts and krbtgt
    • Enterprise Admin escalation
    Open course
  11. 11 CRTP AD CS and Certificate-Based Attacks Advanced 5 lessons 8 hours

    Active Directory Certificate Services is a privilege-escalation surface hiding in plain sight in most enterprises. Certificate authorities and templates, enrolment and authentication certificates, the misconfigurations that lead to escalation, and ho

    • AD CS
    • Certificates
    • PrivEsc
    • CRTP
    • AD CS, certificate authorities and templates
    • Enrolment and authentication certificates
    • Certificate-based privilege escalation misconfigurations
    • Common AD CS attack paths
    • Detection and mitigation
    Open course
  12. 12 CRTP SQL Server and Database Trusts Advanced 5 lessons 6 hours

    Databases are a cross-system attack path most testers overlook. SQL Server architecture and authentication, enumeration, and the linked-server and database-trust chains that carry an attacker from one system to command execution on another.

    • SQL Server
    • Linked Servers
    • CRTP
    • SQL Server architecture and authentication
    • SQL enumeration
    • Linked servers and database trusts
    • Cross-system attack paths
    • SQL to OS execution concepts
    Open course
  13. 13 PNPT External Penetration Testing Advanced 6 lessons 10 hours

    The PNPT half begins at the edge of the network, where a real engagement starts. OSINT and attack-surface discovery, external and service enumeration, and the initial access that turns an internet-facing weakness into a foothold on the inside.

    • External
    • OSINT
    • PNPT
    • OSINT and attack-surface discovery
    • DNS, subdomains and email intelligence
    • Technology discovery and external network mapping
    • External service enumeration
    • Vulnerability identification and initial access
    • From external foothold to internal access
    Open course
  14. 14 PNPT Internal Network Penetration Testing Advanced 6 lessons 10 hours

    Once inside, the real engagement begins. Internal enumeration of Windows and Linux networks, domain enumeration and credential discovery, and the lateral movement and privilege escalation that lead to a domain controller — the full external-to-intern

    • Internal
    • AD
    • Domain Compromise
    • PNPT
    • Internal enumeration: Windows and Linux networks
    • SMB, LDAP, DNS and Kerberos internally
    • Domain enumeration and credential discovery
    • Lateral movement and privilege escalation
    • Domain controller attack paths
    • Lab: external to internal to domain
    Open course
  15. 15 PNPT Professional Pentest Reporting and Debrief Advanced 5 lessons 6 hours

    PNPT weights the report as heavily as the hacking, and adds something most exams do not: a live debrief. You learn to write the executive summary, the attack narrative and the technical findings, and to present and defend them the way the exam and a

    • Reporting
    • Debrief
    • PNPT
    • Executive summary and scope
    • Methodology, findings and evidence
    • Risk, impact and remediation
    • Attack path, timeline and appendix
    • Delivering a live debrief
    Open course
  16. 16 CRTO Foundation Red Team Operations Fundamentals Advanced 5 lessons 6 hours

    Where CRTO begins, and where the mindset shifts. The difference between a penetration test and a red team engagement, adversary simulation versus emulation, the attack lifecycle, and the engagement planning, objectives and rules of engagement that a

    • Red Team
    • Adversary Simulation
    • OPSEC
    • CRTO
    • What is red teaming? Pentest versus red team
    • Adversary simulation and emulation
    • The attack lifecycle
    • Engagement planning, objectives and rules of engagement
    • OPSEC, legal, compliance and detection considerations
    Open course
  17. 17 CRTO Command and Control Architecture Advanced 6 lessons 10 hours

    The infrastructure that makes a red team operation possible and survivable. Team servers, C2 channels, listeners and beacons, communication profiles over HTTP/HTTPS and DNS, and the redirectors and traffic management that keep the operator hidden beh

    • C2
    • Listeners
    • Redirectors
    • CRTO
    • C2 architecture and team server concepts
    • C2 channels, listeners and beacons
    • Payload concepts and communication profiles
    • HTTP/HTTPS and DNS C2 concepts
    • C2 infrastructure and redirectors
    • Traffic management and staying hidden
    Open course
  18. 18 CRTO Cobalt Strike and Beacon Operations Advanced 6 lessons 8 hours

    The industry-standard C2, driven the way an operator drives it. Cobalt Strike architecture, listeners and beacons, beacon commands and sessions, process and payload management, and the host reconnaissance, credential operations and lateral movement t

    • Cobalt Strike
    • Beacon
    • C2
    • CRTO
    • Cobalt Strike architecture, listeners and beacons
    • Beacon commands, sessions and process management
    • Payload management
    • Host reconnaissance and credential operations
    • Lateral movement and pivoting through C2
    • Data collection through a beacon
    Open course
  19. 19 CRTO Red Team Initial Access and Host Operations Advanced 5 lessons 8 hours

    Managing a compromised host as part of a campaign, not a capture. Initial access concepts and external recon, then the host reconnaissance and post-exploitation — user context, process and network discovery, credential discovery, escalation — that a

    • Initial Access
    • Post-Exploitation
    • Recon
    • CRTO
    • Initial access concepts and external recon
    • Host reconnaissance and user context
    • Process and network discovery
    • Credential discovery in a campaign
    • Host privilege escalation and lateral movement
    Open course
  20. 20 CRTO OPSEC and Detection-Aware Red Teaming Advanced 5 lessons 8 hours

    The discipline that separates a red team operator from a tester: caring what the blue team sees. Host and network indicators, process, command-line and file artefacts, the detection surface, and the logging and EDR telemetry your every action feeds.

    • OPSEC
    • Indicators
    • Detection
    • CRTO
    • OPSEC and the concept of indicators
    • Host and network indicators
    • Process, command-line and file artefacts
    • The detection surface and logging
    • EDR visibility and Defender telemetry
    Open course
  21. 21 CRTP · CRTO Defense Evasion Fundamentals Advanced 5 lessons 8 hours

    How modern defences detect an operation, taught so you can test them in an authorised lab. AV and EDR concepts, AMSI and PowerShell logging, application whitelisting, and the Defender family — Defender, MDE, MDI — with the detection and evasion conce

    • AV
    • EDR
    • AMSI
    • CRTP
    • CRTO
    • AV and EDR concepts
    • AMSI and PowerShell logging
    • Application whitelisting and Windows Defender
    • MDE and MDI concepts
    • Detection mechanisms and evasion concepts in a lab
    Open course
  22. 22 CRTO Pivoting and Internal C2 Advanced 5 lessons 6 hours

    Reaching the segments that matter through the ones you already hold. Internal pivoting, SOCKS and proxying, C2 pivoting and multi-hop environments — running your command and control through a DMZ into an internal network and its Active Directory.

    • Pivoting
    • SOCKS
    • C2
    • CRTO
    • Internal pivoting and SOCKS
    • Port forwarding and proxying
    • C2 pivoting through compromised hosts
    • Network segmentation and multi-hop environments
    • Lab: DMZ to internal network to AD
    Open course
  23. 23 CRTO Data Hunting and Collection Advanced 5 lessons 6 hours

    The objective phase of a red team engagement, where the point is to prove impact, not to take anything real. Data discovery, file and credential hunting, sensitive-data identification across shares and databases, and the staging and collection concep

    • Data Hunting
    • Collection
    • CRTO
    • Data discovery and file hunting
    • Credential and sensitive-data hunting
    • Network shares and database discovery
    • Data staging and collection concepts
    • Objective completion within the rules of engagement
    Open course
  24. 24 CRTP · PNPT · CRTO Adversary Simulation Advanced 6 lessons 8 hours

    Where the three certifications become one workflow. A guided campaign that chains OSINT, external recon, initial access, host recon, privilege escalation, credential access, lateral movement, Active Directory and domain dominance into a single contin

    • Adversary Simulation
    • CRTP
    • PNPT
    • CRTO
    • OSINT and external recon in a campaign
    • Initial access and host recon
    • Privilege escalation and credential access
    • Lateral movement and Active Directory
    • Domain dominance, objective and evidence
    • The campaign report
    Open course
  25. 25 Capstone Final Enterprise Red Team Engagement Advanced 5 lessons 10 hours

    The whole level in one engagement. A multi-domain forest — external host, DMZ, web server and VPN gateway, an internal network of workstations, servers and SQL, an Active Directory domain and a forest trust to a second domain — taken through fourteen

    • Capstone
    • Enterprise
    • Forest
    • Adversary Simulation
    • Phases 1-3: OSINT, external recon, initial access
    • Phases 4-6: host enumeration, privesc, credential access
    • Phases 7-9: lateral movement, AD, domain privesc
    • Phases 10-11: trust analysis and objective completion
    • Phases 12-14: evidence, professional report, executive debrief
    Open course
After the Track

Roles This Track Prepares You For

  • Red Team Operator
  • Internal Penetration Tester
  • Network Penetration Tester
  • Offensive Security Consultant
  • Active Directory Security Specialist
  • Adversary Simulation Analyst
  • Junior / Mid Red Team
  • Enterprise Security Assessor
Same Diploma

Other Tracks in This Diploma

Red Team Level 1 Red Team Level 1 Track Beginner

Red Team Level 1

The complete offensive-security foundation: an integrated CEH, eJPT and OSCP+ preparation path, from cybersecurity fundamentals to OSCP-level practical pentesting.

  • Ethical Hacking
  • Penetration Testing
  • CEH
  • eJPT
  • OSCP+
  • Active Directory
  • Linux
  • Windows
  • One continuous route across CEH, eJPT and OSCP+ — not three disconnected courses.
  • Sixty to seventy percent hands-on labs, in authorised training environments only.
  • Real depth where OSCP+ demands it: Active Directory, privilege escalation, pivoting and reporting.
  • Ends with a full corporate pentest and a professional written report.
Red Team Level 3 Red Team Level 3 Track Advanced

Red Team Level 3

The expert tier: an integrated OSEP, OSWE and OSED preparation path across advanced evasion, white-box web exploitation and Windows user-mode exploit development — the three specialisations that together map to OSCE3.

  • Advanced Evasion
  • Exploit Development
  • Web Exploitation
  • Reverse Engineering
  • OSEP
  • OSWE
  • OSED
  • OSCE3
  • Three real specialisations, not three variations: advanced evasion, web exploit development and binary exploit development.
  • Seventy-five percent hands-on across Windows internals, source-code review and exploit-development labs.
  • White-box web work: read the source, find the bug, write the exploit, reach RCE.
  • Windows user-mode exploit development: reverse engineering, DEP and ASLR bypass, custom shellcode.
  • Ends with three separate expert assessments, one for each of OSEP, OSWE and OSED.
Blue Team Level 1 Blue Team Level 1 Track Beginner

Blue Team Level 1

The defensive foundation: an integrated Security+, BTL1 and SC-200 preparation path, from cybersecurity fundamentals to working a SOC on the Microsoft security stack.

  • Security+
  • BTL1
  • SC-200
  • SOC
  • SIEM
  • Microsoft Sentinel
  • Defender
  • Incident Response
  • One continuous route across Security+, BTL1 and SC-200 — fundamentals to a working SOC analyst.
  • Built around the tools a SOC actually uses: a SIEM, Microsoft Sentinel and Defender, and KQL.
  • Fourteen practical labs, from packet analysis to a full incident investigation.
  • Ends with a complete SOC investigation, triaged, hunted and reported.
Certified

Certificates You Can Earn

Finish your course and receive an accredited MotiGraph certificate you can add to your CV and share with employers.

MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample