Choosing red team training in 2026 is harder than it looks, because the label now covers everything from a two-hour video course to a six-day instructor-led engagement simulation with a graded capstone. Some programs teach adversary emulation against a full Active Directory estate. Others teach a single discipline in depth, such as malware development, cloud identity abuse, or physical covert entry. The gap between them matters when you are spending a training budget or trying to prove capability to a client.
This guide covers red team training providers that operators, consultancies and internal security teams actually use. Each one was checked against its own course catalogue rather than against roundup pages, so the certification names, formats and exam structures below reflect what the provider currently sells. Some are large institutions with GIAC-backed certification. Some are small shops run by working operators who teach what they used on last quarter’s engagement. Both models produce good red teamers, and the right pick depends on where you are starting and what you need to prove.
If you are hiring an offensive team rather than building one, our list of top red teaming companies covers firms that run engagements for clients. This page is about the courses, labs and certifications that create the operators behind them.
|
Provider |
Flagship program |
Format |
Best for |
|
White Knight Labs |
ARTOC, ODPC, OAOTC, ASCPC |
Live over Zoom plus self-paced |
Operators who want practitioner-taught tradecraft with a performance-based exam |
|
SpecterOps |
Adversary Tactics: Red Team Operations |
In-person, virtual, on-demand |
Teams building a full adversary simulation capability |
|
Zero-Point Security |
Red Team Ops (CRTO) |
Self-paced with add-on lab hours |
The most widely recognised entry point into red team certification |
|
SANS Institute |
SEC565 with GIAC GRTP |
In-person, live virtual, self-paced |
Enterprises that need an accredited, budget-approved certification |
|
OffSec |
PEN-300 leading to OSEP |
Self-paced with subscription tiers |
Evasion and defense bypass against hardened targets |
|
Altered Security |
CRTP, CRTE, CRTM, CARTP |
Self-paced lab access |
Active Directory and Azure attack paths at low cost |
|
Hack The Box |
HTB CAPE |
Self-paced modules plus 10-day exam |
Proving hands-on Active Directory skill without an instructor |
|
Mandiant Academy |
Creative Red Teaming |
Four days in person, five virtual |
Learning tradecraft drawn from large-scale incident response |
|
TCM Security |
PNPT |
Self-paced with live debrief |
Newer testers who need an affordable, report-driven credential |
|
Antisyphon Training |
Pay What You Can catalogue |
Live and on-demand |
Teams with limited budget and broad upskilling needs |
|
Red Team Alliance |
Covert Methods of Entry |
In-person boot camps |
Physical red teaming, covert entry and access control bypass |
|
Maldev Academy |
Malware Development course |
Self-paced, lifetime access |
Building custom implants and payloads from first principles |
White Knight Labs sits in an unusual position: it is a consultancy that runs offensive engagements for clients and a training provider that turns those engagements into course material. The certifications are built and delivered by the same people doing the assessment work, which is why the curriculum tends to track current tradecraft rather than last year’s.
The catalogue runs to four certifications. Advanced Red Team Operations Certification (ARTOC) is the flagship, an advanced to expert level simulated lab built around Cobalt Strike. Offensive Development Practitioner Certification (ODPC) is the malware and tooling track, covering Windows internals and offensive development for operators who need to build rather than borrow. Offensive Azure Operations and Tactics Certification (OAOTC) runs as two days of virtual instruction against live Azure infrastructure. Attacking and Securing CI/CD Pipeline Certification (ASCPC) is the newest addition and the one with the least competition anywhere on this list: pipeline enumeration, secret theft, artifact poisoning, OIDC trust abuse and pivoting from a build system into cloud.
ARTOC, ODPC and OAOTC are delivered live and instructor led over Zoom. ASCPC is fully self-paced through the student portal at $700, with a 48-hour performance-based exam followed by 48 hours to submit a professional report. That report requirement is worth noting: several certifications on this list test exploitation only, and White Knight Labs tests whether you can write up what you did in a form a client would accept. The team also teaches at DEF CON Training, which is a reasonable proxy for how the wider community rates the material.
Best fit: operators who want small-cohort instruction from people currently running engagements, and teams that need CI/CD or Azure coverage that the larger providers have not caught up on yet.
SpecterOps built BloodHound, which alone tells you where the company’s expertise sits. Its Adversary Tactics curriculum is the closest thing the industry has to a canonical red team syllabus, and it spans both sides of the engagement.
The core courses are Adversary Tactics: Red Team Operations, Identity-Driven Offensive Tradecraft, Tradecraft Analysis and Detection, supported by the Adversary Perspectives series on Active Directory and Azure. Training is delivered in person at events such as Specter Bash, virtually, at conferences including Black Hat, and on demand through SpecterOps Tradecraft Academy. Private cohorts are available for organisations that want the whole team trained at once.
What separates SpecterOps from the volume training providers is the research pipeline. Instructors are practitioners running current engagements, and the material moves as their published research moves. The identity-focused courses in particular reflect where attack paths have actually gone: Kerberos, certificate services, federated trust and the seams between on-premises directory and cloud identity.
Best fit: mature teams that want the offensive and detection sides taught together, and anyone whose engagements live inside Active Directory and Entra ID.
If one credential has become the standard opening move in red team certification, it is Zero-Point Security’s Red Team Ops, better known by its CRTO designation. Ask in any offensive security community which course to take first and this is the answer you get most often, largely because the price to value ratio is difficult to argue with.
Red Team Ops runs to roughly 180 lessons covering the full attack lifecycle: external reconnaissance, initial compromise, command and control, host and domain persistence, privilege escalation, lateral movement, domain takeover and exfiltration, all framed around operational security and defense evasion against Windows Defender and AppLocker. Cobalt Strike is the C2 platform throughout, which matters because it is still the framework a large share of commercial red teams run in production. The course costs £365 and includes one exam attempt with no expiry on the voucher. Lab hours are bought separately in 40, 80 and 120 hour tiers across 30, 60 and 90 day windows.
Beyond the flagship, the catalogue has expanded into shorter focused courses across three difficulty tiers, including BOF Development and Tradecraft, Kerberos Fundamentals, Windows Access Tokens, Initial Access and Persistence, and The Art of Report Writing. The report writing course is an unusual inclusion and a welcome one, since report quality is where most junior operators lose credibility with clients.
Best fit: penetration testers making the move into red teaming who want a recognised credential without an enterprise training budget behind them.
SANS is the option that clears procurement without a conversation. When a training request has to survive a budget committee, an accredited GIAC certification is the path of least resistance, and SEC565: Red Team Operations and Adversary Emulation is the course that maps to red team work specifically.
SEC565 runs six days instructor led or 36 hours self-paced, carries 36 CPE credits, and leads to the GIAC Red Team Professional (GRTP) certification. The syllabus covers engagement planning, threat intelligence and MITRE ATT&CK-driven adversary emulation, resilient attack infrastructure and C2, Active Directory exploitation, lateral movement, exfiltration and reporting. There are 28 hands-on labs and an immersive capstone exercise against an enterprise Windows and Active Directory environment. Recent revisions have added AI tooling in offensive workflows, which is a fair reflection of how engagement prep has changed.
Delivery is in person, live virtual or self-paced with four months of access. The cost is the highest on this list by a wide margin, and that is the honest trade: you are paying for accreditation, structure and a credential that hiring managers outside offensive security recognise on sight.
Best fit: enterprise teams, government contractors and anyone whose employer requires accredited training with formal CPE reporting.
OffSec is best known for OSCP, but the certification that belongs in a red team conversation is OSEP, earned through PEN-300: Advanced Evasion Techniques and Breaching Defenses. Where OSCP proves you can compromise a network, OSEP proves you can do it against an organisation that has a functioning security team.
The course is built around bypassing defenses rather than finding vulnerabilities: antivirus and EDR evasion, application allowlisting bypass, custom payload development, client-side attacks and lateral movement through segmented environments. The exam is the familiar OffSec format, a long self-paced practical assessment against a live environment, and it has a reputation for being genuinely difficult.
Pricing follows OffSec’s subscription model. The course and exam bundle is $1,749 with 90 days of access and one exam attempt. Learn One is $2,749 per year with a full year of access and two attempts. Learn Unlimited is $6,099 per year across the entire library with unlimited exam attempts, which is often the better value if more than one certification is on your roadmap. Enterprise pricing is negotiated separately.
Best fit: existing OSCP holders and experienced testers whose engagements keep dying at the EDR boundary.
Altered Security, the team behind the widely used CRTP certification, runs the most granular progression of Active Directory and Azure attack labs available. Rather than one large course, the catalogue is a ladder, and you climb it at the pace your engagements demand.
On the on-premises side the sequence runs ACPT for infrastructure and network testing fundamentals, CRTP (Certified Red Team Professional) for attacking and defending Active Directory, CESP-ADCS for certificate services attacks, CRTE (Certified Red Team Expert) for the advanced lab, CETP for Windows evasion tradecraft, and CRTM (Certified Red Team Master) against a simulated global central bank environment. The cloud track covers CARTP and CARTE for beginner and advanced Azure red team tactics.
Every course is self-paced with hands-on lab access and an exam-based certification at the end. The pricing sits well below the instructor-led providers, which is what has made CRTP such a common line on offensive security resumes. The trade-off is that you are learning without an instructor in the room, so the labs reward people who are comfortable working through a problem alone.
Best fit: self-directed learners who want depth in directory and cloud identity attacks at the lowest cost per certification.
Hack The Box started as a hacking playground and has become a serious certification body. For red team purposes the relevant credential is HTB Certified Active Directory Pentesting Expert (CAPE), which is one of the more demanding practical exams currently on the market.
CAPE covers 15 modules across deep enumeration, foothold, lateral movement, domain privilege escalation, post-exploitation, C2 fundamentals and professional reporting, with an emphasis on manual exploitation over tooling. The exam gives you 10 days, an engagement letter and an internal foothold with no credentials, and requires 90 points plus a professional report. It is open book. Most candidates report three to four months of preparation at a sustainable pace. The voucher and content bundle is $1,260, with HTB Certified Penetration Testing Specialist (CPTS) at $490 as the natural prerequisite.
The wider platform matters too. Pro Labs and Dedicated Labs give teams multi-host attack environments to train against continuously rather than once, which suits organisations that want ongoing skills maintenance rather than a single certification event. The newer HTB Certified Offensive AI Expert (COAE) track at $490 is worth watching as AI systems become an engagement scope item.
Best fit: teams that want a continuously available lab environment plus a rigorous credential that proves practical Active Directory capability.
Mandiant Academy, now part of Google Cloud, teaches offensive tradecraft informed by one of the largest incident response practices in the world. That inversion is the selling point: the instructors have seen what real intrusion sets do and what actually evaded detection, and the courses are built from that evidence base rather than from public research alone.
Creative Red Teaming is the core offering, running four days in classroom or five days virtual, delivered by Mandiant red team leads. The syllabus covers custom payload development and antivirus bypass, persistence, privilege escalation and lateral movement without triggering alerts, evasion of application allowlisting, encryption, multi-factor authentication and sandboxing, data exfiltration from secured networks, and the management side of red team operations including risk measurement and reporting. Scenario-based labs sit alongside the instruction.
The course is pitched at red team members, penetration testers and defenders who want to understand offensive TTPs from the inside. Scheduled cohorts run regionally through the year, and private delivery is available for organisations.
Best fit: enterprise security functions that want offensive training grounded in observed intrusion activity rather than lab theory.
TCM Security’s Practical Network Penetration Tester (PNPT) is not marketed as a red team certification, and it earns its place here for a specific reason: it is the only widely held credential that makes you defend your findings to a human being.
The exam has no flags and no multiple choice. You get five full days for the assessment, two more to write a professional report, and then a live 15-minute debrief where you present your findings. The scope covers OSINT, Active Directory exploitation, antivirus and egress bypass, lateral and vertical movement and domain controller compromise. At $499 the voucher includes over 45 hours of training with 12 months of access, spanning Practical Ethical Hacking, Windows and Linux privilege escalation, OSINT and the External Pentest Playbook, plus one free retake.
For a junior operator, the debrief is the part that changes how you work. Red team engagements are sold on the quality of the debrief as much as the compromise, and very little training touches that skill. Treat PNPT as the foundation layer before CRTO or CAPE rather than as a red team credential in its own right.
Best fit: newer testers building toward red team work who need affordable training plus practice at communicating findings.
Antisyphon, from the Black Hills Information Security orbit, runs on a pay-what-you-can model. Courses start at $0 and students pay forward what they can afford, which has made it the most accessible serious training on this list without the quality drop that usually accompanies free.
The offensive catalogue includes Active Directory Security and Hardening, Advanced Penetration Testing of Non-Western IT Infrastructures, Assumed Compromise with detections and Microsoft Sentinel, Attacking and Defending AI, Modern Webapp Pentesting II and an OSINT Crash Course. Instructors include John Strand, Jordan Drysdale, Kent Ickler, Steve Borosh, BB King and Mishaal Khan, most of whom are recognisable from conference stages. Courses run live with hands-on instruction or on demand for self-paced study.
The Assumed Compromise course deserves a specific mention for red team purposes, since it teaches the offensive path and the detections it generates in the same sitting. That pairing is exactly what a purple team function needs and what most offensive courses leave out.
Best fit: teams with a thin training budget, and anyone who wants to broaden across offense and detection without committing thousands per seat.
Almost every provider on this list teaches network intrusion. Red Team Alliance teaches the part of a full-scope engagement that happens in a parking lot at two in the morning, and there is very little competition for what it does.
The curriculum is organised into eight course families. CMOE, Covert Methods of Entry, is the flagship: a five-day immersive boot camp covering covert entry across physical, digital and human security layers. PACS covers physical access control systems including electronic locks, card readers and credential cloning. PIDS covers intrusion detection, sensors, alarms and countermeasures. DISG teaches disguise and deception, pretexting and identity manipulation. RCON covers reconnaissance, surveillance and target profiling. OPER covers mission planning, team coordination and operational security. SPEC handles specialist subjects such as safe manipulation and vault entry, and HOST carries partner-delivered programs.
Training is hands-on and in person, which is unavoidable given the subject matter. If your firm sells full-scope assessments or your client asks whether an attacker could physically reach the server room, this is where that capability is built. Our roundup of advanced attack simulation and emulation firms shows how often physical access forms part of a serious engagement scope.
Best fit: consultancies adding physical red teaming to their service line, and internal teams testing site security rather than only the network.
Maldev Academy solves one problem extremely well. When an off-the-shelf payload gets caught and the engagement stalls, someone on the team has to write something that does not, and that skill is taught in very few places at this depth.
The malware development course launched with 91 modules and has grown past 170 as new material has been added. Coverage runs through Windows internals, loader architecture, payload encryption and obfuscation, execution methods, IoC spoofing, API hooking, direct and indirect syscalls, anti-analysis and anti-debugging, LSASS credential dumping, keylogging and ETW tampering. A separate Offensive Phishing Operations course covers the initial access side.
Pricing is lifetime access at $500, or $700 bundled with the malware database, and lifetime includes future module releases. There is no exam or certification, which is the honest limitation: this is capability training rather than a credential. It pairs naturally with a certification-led course elsewhere on this list, and comfort with C and Windows API programming is effectively a prerequisite.
Best fit: operators moving from using tooling to building it, and teams that need custom implants for engagements against mature detection stacks.
These are different purchases and conflating them wastes money. A certification is evidence you can show a client, an employer or an auditor, and its value depends on how widely the market recognises it. A capability is a skill you did not have last month. CRTO, OSEP, GRTP and CAPE buy recognition. Maldev Academy and much of the Antisyphon catalogue buy capability with no credential attached. If a contract requires certified staff, start with the accredited options. If your engagements are failing at a specific technical point, buy the course that fixes that point and ignore whether it ends in an exam.
Look closely at exam structure, because it tells you what the course actually values. A flag-capture exam tests exploitation. An exam that requires a professional report tests whether you can operate. The strongest formats on this list combine both: White Knight Labs runs a 48-hour performance exam followed by 48 hours of report writing, HTB CAPE requires 90 points plus a report across a 10-day window, and PNPT adds a live debrief on top of the report. Since real engagements are delivered as a document and a conversation, an exam that never assesses either is measuring only half the job.
A course built around on-premises Active Directory will not help much against an estate that runs on Entra ID, federated identity and CI/CD pipelines. Map your last three engagement scopes before you buy. If cloud identity keeps appearing, look at OAOTC, CARTP and CARTE, or the SpecterOps Azure material. If build systems and supply chain keep appearing, ASCPC currently has that ground largely to itself. If your work is full scope and includes physical access, none of the network courses will cover it and Red Team Alliance will.
Live instruction gives you an operator to ask when a technique fails in a way the courseware does not explain, which is where most of the learning actually happens. It also costs more and locks you to a schedule. Self-paced training is cheaper, repeatable across a team and available when the calendar allows, but it demands the discipline to finish. A practical pattern is self-paced for foundations, such as CRTP or CPTS, then live instruction for advanced tradecraft where the instructor’s judgment is the product, such as ARTOC, the SpecterOps Adversary Tactics courses, or Creative Red Teaming.
Ask whether the instructor is a working operator or a full-time trainer. Both can teach well, but offensive tradecraft has a short half-life and courses written by people currently running engagements age more slowly. Named instructors are a good signal, and so is a public research output: SpecterOps publishes the research behind its curriculum, Antisyphon lists its instructors by name on every course, and White Knight Labs teaches at DEF CON. A provider that will not tell you who is delivering the material is telling you something.
Lab time is where the advertised price and the real price diverge. CRTO sells the course at £365 and lab hours separately in 40, 80 and 120 hour blocks, with the clock starting at purchase. OffSec bundles access into 90-day or annual subscriptions. SANS self-paced includes four months. Altered Security sells lab access per course. Work out how many hours you realistically need, whether they expire, whether a retake is included and whether the environment resembles a real enterprise rather than a handful of isolated boxes. A cheap course with an inadequate lab is not cheap.
Individual and team purchases behave differently. For a team, private cohort delivery from SpecterOps, White Knight Labs or Mandiant Academy usually beats sending people to public dates, because the scenarios can be tuned to your environment and everyone leaves with the same vocabulary. Continuous platforms such as Hack The Box Dedicated Labs suit teams that need skills maintained rather than certified once. For an individual, cost per credential and market recognition should drive the decision, which is why CRTP and CRTO appear on so many resumes. If you are choosing between building the team and buying the engagement, our list of top penetration testing companies is a useful comparison point.
There is no single best red team training provider, only the right one for a given gap. Someone moving out of penetration testing should start with CRTO or PNPT and build from there. An enterprise team that needs accredited certification with formal CPE reporting should look at SANS SEC565 and GRTP. A consultancy that keeps losing engagements at the EDR boundary needs OSEP or Maldev Academy, not another broad course. Teams working modern cloud and pipeline attack surface should look hard at the Azure and CI/CD certifications from White Knight Labs and Altered Security, since that ground is still thinly covered.
Two things are worth holding onto whichever way you go. Buy for the exam format as much as the syllabus, because a certification that requires a report and a debrief is testing the job rather than the technique. And buy from people who are still operating, because red team tradecraft written more than a year ago has usually been detected by now. The providers on this list that combine both, practitioner instructors and performance-based assessment, are the ones most likely to still be worth the budget when your next engagement scope lands.
If you’re a Red Team training provider and want to feature your company on this list, email us or submit a form in the Top Choices section. After a thorough assessment, we’ll decide whether it’s a valuable addition.