How to Learn Red Teaming

Red Teaming Roadmap
From operator basics to running full red team engagements
Red teaming is penetration testing with stealth, objectives and a thinking defender on the other side. This is the path: foundations, offensive tradecraft, a command and control framework, evasion, Active Directory, and the reporting that makes the whole thing worth paying for.
6 steps
Foundations to purple team
8 to 12 months
To engagement ready
Stealth
The skill that separates it
Before you start
Red team is not the same as pentest

A penetration test asks "what can be exploited here". A red team engagement asks "can we achieve this objective without the defenders catching us, and if they do catch us, how fast". The difference is stealth, goals and a live opponent.

That means this roadmap assumes you already have solid security fundamentals. If you are completely new to offensive security, do a vulnerability assessment and penetration testing path first, then come back. Red teaming on weak fundamentals just means getting caught faster.

  • Who hires for it red team units at banks and large enterprises, offensive security consultancies, and managed detection and response providers who run adversary simulations
  • What you need first comfort with networking, Linux, Windows, and basic web and network exploitation
  • The mindset shift getting a shell is the easy part. Keeping it without tripping an alert is the job
Legal lineEvery technique here is for authorised engagements and your own lab only. Red team work runs on a signed rules of engagement document. Without written authorisation, this is not red teaming, it is a crime under the Information Technology Act and equivalent laws.
Step 016 to 8 weeks
Build the foundation

Red teaming lives and dies in Windows networks, specifically Active Directory. Your foundation has to be deeper than a typical pentester's, because you are operating while someone is watching the logs.

Networking and infrastructure
  • Protocols, routing, proxies, and tunnelling, because you will pivot through them
  • How traffic looks on the wire, so you can make yours look ordinary
  • DNS deeply, it is both a data channel and a detection surface
Active Directory basics
  • Domains, forests, trusts, organisational units and group policy
  • Authentication flows, NTLM and Kerberos, at a conceptual level for now
  • How a normal enterprise is actually structured and administered
Operating systems and scripting
  • Windows internals, the privilege model, event logging and what gets recorded
  • Linux for your own infrastructure and tooling
  • PowerShell and Python, plus enough C sharp to read and tweak offensive tooling
CheckpointYou can stand up a small Active Directory lab with a domain controller and a couple of workstations, and explain what each authentication step logs.
Step 024 to 6 weeks
Learn offensive tradecraft

Now the attack techniques themselves, mapped to how a real intrusion unfolds. Learn the technique and why it works, not just the tool that automates it.

The kill chain in practice
  • Initial access phishing, malicious documents, LNK and ISO delivery, and the tradeoffs of each
  • Execution loaders, process injection, and running payloads in memory to avoid disk
  • Lateral movement WMI, WinRM, SMB, pass the hash, pass the ticket
  • Persistence scheduled tasks, services, run keys, and quieter options
  • Privilege escalation local misconfigurations, token abuse, and service exploits
CheckpointIn your lab you can chain initial access to code execution to lateral movement, and explain what each step would look like to a defender.
Step 034 to 6 weeks
Master a C2 framework

Command and control is how you operate an implant at a distance. Pick one framework and learn it cold before you even look at a second. Depth beats a collection of tools you half know.

Pick one and go deep
  • Cobalt Strike the commercial industry standard, worth knowing even if you learn on something else
  • Sliver free, modern, and widely used for learning and real work
  • Mythic flexible and open, good for understanding how C2 actually works under the hood
What to actually learn
  • Listeners across HTTP, HTTPS, DNS and SMB named pipes, and when each fits
  • Beacon behaviour, sleep, jitter and malleable profiles that shape your traffic
  • Redirectors and domain fronting style setups that hide your real infrastructure
  • Operating safely through the framework, logging your own actions for the report
CheckpointYou can deploy a beacon in your lab, route it through a redirector, and tune its profile so its traffic does not look like a textbook default.
Step 04ongoing
Evasion and OPSEC

This is the part that actually separates a red teamer from a pentester. A loud operator gets the entire engagement burned. Understand detection before you try to beat it.

Understand detection first
  • How antivirus and EDR work, signatures, behaviour, and telemetry collection
  • What Windows event logs, Sysmon and EDR actually record about your actions
  • Why living off the land and blending in beats novel exploits most of the time
Then evade thoughtfully
  • In memory execution, reflective loading, and sleep masking to reduce artifacts
  • Minimising indicators, named pipes, process trees, command lines
  • Infrastructure OPSEC, clean redirectors, separation, and attribution awareness
The real lessonOPSEC is a discipline, not a tool. The best operators are boring on purpose. They look like a tired sysadmin, not a hacker in a movie.
Step 054 to 6 weeks
Active Directory attacks

Most real engagements are won or lost in Active Directory. This is where the majority of your study time should go, because this is where the objectives usually live.

The core attack paths
  • Enumeration BloodHound and SharpHound to map attack paths to high value targets
  • Kerberos abuse Kerberoasting, AS-REP roasting, unconstrained and constrained delegation
  • ADCS attacks certificate template misconfigurations that lead to domain privilege
  • Domain dominance DCSync, golden and silver tickets, and what each really proves
CheckpointIn a lab domain you can go from a low privilege user to domain admin through at least two different paths, and explain the detection opportunity at each step.
Step 06every engagement
Report and purple team

A red team that only breaks in is only half a service. The value is handed over in the report and the debrief, where the defenders learn what to fix.

The report
  • Attack narrative the story from initial access to objective, in order a human can follow
  • TTP mapping every action tied to a MITRE ATT and CK technique
  • Detection analysis what the blue team saw, missed, and could have caught
  • Remediation concrete, prioritised fixes, not a wall of findings
Purple teaming
  • Replaying your techniques with the defenders watching, so they can build detections live
  • Measuring detection and response time, then improving it together
  • Turning a single engagement into lasting defensive capability
CheckpointYou can write an engagement report where a defender, from your document alone, can reproduce your path and build a detection for each step.
Planning
A realistic timeline

Red teaming takes longer than most tracks because it sits on top of pentesting. This assumes you already have offensive security basics and can give it eight to ten hours a week.

Period
Focus
Month 1 to 2
Foundations, Active Directory lab, Windows internals and logging
Month 3
Offensive tradecraft, the kill chain end to end in the lab
Month 4
One C2 framework in depth, listeners, profiles, redirectors
Month 5
Evasion and OPSEC against a real EDR in the lab
Month 6 to 7
Active Directory attack paths, multiple routes to domain admin
Month 8+
Full simulated engagements, reports, purple team exercises
Careers
Where red teaming leads
Red Team Operator
Running adversary simulations end to end, usually after pentest experience
Penetration Tester
The usual stepping stone into red team work, and a solid career on its own
Purple Team Engineer
Bridging offence and defence, building detections from real attacks
Detection Engineer
Understanding attacker tradecraft to write detections that actually fire
Adversary Emulation
Replaying specific threat actor TTPs to test defences against real threats
Offensive Security Lead
Scoping, running and signing off engagements for a team
Certifications
Which certifications map to this
  • Foundation OSCP remains the baseline that proves you can exploit and pivot
  • Red team specific certifications focused on evasion, C2 and Active Directory attack paths are the natural next step after OSCP
  • Active Directory depth look for courses and exams built specifically around AD attack and defence
  • As always, take these after you can do the work in a lab, not as a way to learn it from scratch
Not sure if you are ready for red teaming yet?

If you cannot yet get domain admin in a lab on your own, start with the offensive security fundamentals first. Tell us where you are and we will point you to the right track.

Common questions
Can I start red teaming as a beginner?
Not directly. Red teaming sits on top of penetration testing. Build offensive security fundamentals and get comfortable compromising an Active Directory lab first, then this roadmap makes sense.
Red team or pentest, which pays more?
Red team roles generally pay more because they demand more, but they are also fewer and more senior. Most people reach red teaming through pentesting, which is a strong career in its own right.
Do I need Cobalt Strike to learn?
No. Cobalt Strike is commercial and licensed to organisations. Learn the concepts on free frameworks like Sliver or Mythic, which teach the same tradecraft.
How important is Active Directory?
Central. Most enterprise engagements are decided in Active Directory, so it deserves the largest share of your study time.
Is report writing really part of it?
Yes, and it is what clients pay for. An engagement that compromises everything but produces a weak report delivers little lasting value.
Is red teaming legal?
Only under a signed rules of engagement with explicit authorisation, or in your own lab. Outside that it is unauthorised access and a criminal offence.
This roadmap is educational. Red team techniques are for authorised engagements and your own lab only.