How to Learn Red Teaming
A penetration test asks "what can be exploited here". A red team engagement asks "can we achieve this objective without the defenders catching us, and if they do catch us, how fast". The difference is stealth, goals and a live opponent.
That means this roadmap assumes you already have solid security fundamentals. If you are completely new to offensive security, do a vulnerability assessment and penetration testing path first, then come back. Red teaming on weak fundamentals just means getting caught faster.
- Who hires for it red team units at banks and large enterprises, offensive security consultancies, and managed detection and response providers who run adversary simulations
- What you need first comfort with networking, Linux, Windows, and basic web and network exploitation
- The mindset shift getting a shell is the easy part. Keeping it without tripping an alert is the job
Red teaming lives and dies in Windows networks, specifically Active Directory. Your foundation has to be deeper than a typical pentester's, because you are operating while someone is watching the logs.
- Protocols, routing, proxies, and tunnelling, because you will pivot through them
- How traffic looks on the wire, so you can make yours look ordinary
- DNS deeply, it is both a data channel and a detection surface
- Domains, forests, trusts, organisational units and group policy
- Authentication flows, NTLM and Kerberos, at a conceptual level for now
- How a normal enterprise is actually structured and administered
- Windows internals, the privilege model, event logging and what gets recorded
- Linux for your own infrastructure and tooling
- PowerShell and Python, plus enough C sharp to read and tweak offensive tooling
Now the attack techniques themselves, mapped to how a real intrusion unfolds. Learn the technique and why it works, not just the tool that automates it.
- Initial access phishing, malicious documents, LNK and ISO delivery, and the tradeoffs of each
- Execution loaders, process injection, and running payloads in memory to avoid disk
- Lateral movement WMI, WinRM, SMB, pass the hash, pass the ticket
- Persistence scheduled tasks, services, run keys, and quieter options
- Privilege escalation local misconfigurations, token abuse, and service exploits
Command and control is how you operate an implant at a distance. Pick one framework and learn it cold before you even look at a second. Depth beats a collection of tools you half know.
- Cobalt Strike the commercial industry standard, worth knowing even if you learn on something else
- Sliver free, modern, and widely used for learning and real work
- Mythic flexible and open, good for understanding how C2 actually works under the hood
- Listeners across HTTP, HTTPS, DNS and SMB named pipes, and when each fits
- Beacon behaviour, sleep, jitter and malleable profiles that shape your traffic
- Redirectors and domain fronting style setups that hide your real infrastructure
- Operating safely through the framework, logging your own actions for the report
This is the part that actually separates a red teamer from a pentester. A loud operator gets the entire engagement burned. Understand detection before you try to beat it.
- How antivirus and EDR work, signatures, behaviour, and telemetry collection
- What Windows event logs, Sysmon and EDR actually record about your actions
- Why living off the land and blending in beats novel exploits most of the time
- In memory execution, reflective loading, and sleep masking to reduce artifacts
- Minimising indicators, named pipes, process trees, command lines
- Infrastructure OPSEC, clean redirectors, separation, and attribution awareness
Most real engagements are won or lost in Active Directory. This is where the majority of your study time should go, because this is where the objectives usually live.
- Enumeration BloodHound and SharpHound to map attack paths to high value targets
- Kerberos abuse Kerberoasting, AS-REP roasting, unconstrained and constrained delegation
- ADCS attacks certificate template misconfigurations that lead to domain privilege
- Domain dominance DCSync, golden and silver tickets, and what each really proves
A red team that only breaks in is only half a service. The value is handed over in the report and the debrief, where the defenders learn what to fix.
- Attack narrative the story from initial access to objective, in order a human can follow
- TTP mapping every action tied to a MITRE ATT and CK technique
- Detection analysis what the blue team saw, missed, and could have caught
- Remediation concrete, prioritised fixes, not a wall of findings
- Replaying your techniques with the defenders watching, so they can build detections live
- Measuring detection and response time, then improving it together
- Turning a single engagement into lasting defensive capability
Red teaming takes longer than most tracks because it sits on top of pentesting. This assumes you already have offensive security basics and can give it eight to ten hours a week.
- Foundation OSCP remains the baseline that proves you can exploit and pivot
- Red team specific certifications focused on evasion, C2 and Active Directory attack paths are the natural next step after OSCP
- Active Directory depth look for courses and exams built specifically around AD attack and defence
- As always, take these after you can do the work in a lab, not as a way to learn it from scratch
If you cannot yet get domain admin in a lab on your own, start with the offensive security fundamentals first. Tell us where you are and we will point you to the right track.