
How to Learn Red Teaming in 2026: From Operator Basics to Full Engagements
There is a specific moment that separates a penetration tester from a red teamer. The pentester gets a shell and feels the job is done. The red teamer gets a shell and immediately thinks about the EDR agent that just logged the process, the SOC analyst who might be glancing at the alert queue, and whether the beacon’s sleep timer looks human.
Red teaming is penetration testing with three extra constraints: stealth, a specific objective, and a defender who is actively trying to catch you. That is the whole discipline in one sentence, and it is why red teaming sits on top of pentesting rather than beside it.
This post is the roadmap in dependency order. Six steps, eight to twelve months on top of existing offensive security skills, and a checkpoint at each stage. If you are completely new to hacking, this is not your starting point. Build pentesting fundamentals first, get domain admin in a lab on your own, then come back. Red teaming on weak fundamentals just means getting caught faster.
One hard rule before anything else. Every technique here is for authorised engagements and your own lab. Red team work runs on a signed rules of engagement document. Without written authorisation this is not red teaming, it is unauthorised access, and it is a criminal offence under the Information Technology Act in India and equivalent laws everywhere else.
Red team versus pentest, the distinction that matters
A penetration test answers “what can be exploited in this scope”. Breadth matters. You enumerate, you find as many issues as you can, you report them all.
A red team engagement answers “can we achieve this objective, quietly, and if the defenders catch us, how quickly”. Depth and stealth matter. You might ignore ten exploitable bugs because the quiet path only needs one.
Who hires for it: red team units at banks and large enterprises, offensive security consultancies, and managed detection and response providers who run adversary simulations against their own clients.
What you need first: real comfort with networking, Linux, Windows, and basic web and network exploitation. If BloodHound and Kerberoasting are already familiar words, you are roughly ready.
The mindset shift: getting a shell is the easy part. Keeping it without tripping an alert is the actual job.
Step 1: Build the foundation
Time needed: 6 to 8 weeks
Red teaming lives in Windows networks, and specifically in Active Directory. Your foundation has to run deeper than a typical pentester’s, because you are operating while someone reads the logs.
Networking and infrastructure
- Protocols, routing, proxies and tunnelling, because you will pivot through all of them
- What normal traffic looks like on the wire, so you can make yours blend in
- DNS in real depth. It is both a covert channel and a detection surface
Active Directory basics
- Domains, forests, trusts, organisational units and group policy
- Authentication flows, NTLM and Kerberos, conceptually for now, in depth later
- How a real enterprise is structured and administered day to day
Operating systems and scripting
- Windows internals, the privilege model, and crucially what event logging records
- Linux for your own tooling and infrastructure
- PowerShell and Python, plus enough C sharp to read and modify offensive tooling
Checkpoint: you can stand up a small Active Directory lab with a domain controller and a couple of workstations, and explain what each authentication step writes to the logs. That logging awareness is what makes the rest of this roadmap click.
Step 2: Learn offensive tradecraft
Time needed: 4 to 6 weeks
Now the attack techniques, mapped to how a real intrusion actually unfolds. Learn the technique and why it works, not just the tool that automates it, because the tool will be flagged and you will need to adapt.
The kill chain in practice
- Initial access. Phishing, malicious documents, LNK and ISO delivery, and the detection tradeoffs of each
- Execution. Loaders, process injection, and running payloads in memory to stay off disk
- Lateral movement. WMI, WinRM, SMB, pass the hash, pass the ticket, and which is quietest where
- Persistence. Scheduled tasks, services, run keys, and the quieter options defenders forget to watch
- Privilege escalation. Local misconfigurations, token abuse, service exploits
Checkpoint: in your lab you can chain initial access to execution to lateral movement, and narrate what each step would look like from the defender’s console.
Step 3: Master a C2 framework
Time needed: 4 to 6 weeks
Command and control is how you operate an implant from a distance. Pick one framework and learn it cold before you look at a second. A collection of tools you half understand is worse than one you know completely.
Pick one and go deep
- Cobalt Strike. The commercial industry standard. Worth understanding even if you learn on something else, because this is what real teams and real reports reference
- Sliver. Free, modern, widely used for both learning and real work. A strong default
- Mythic. Open and flexible, excellent for understanding how C2 actually works under the hood
What to actually learn
- Listeners across HTTP, HTTPS, DNS and SMB named pipes, and when each is appropriate
- Beacon behaviour: sleep, jitter, and malleable profiles that shape how your traffic looks
- Redirectors and domain fronting style setups that keep your real infrastructure hidden
- Operating cleanly through the framework and logging your own actions for the eventual report
Checkpoint: you can deploy a beacon in your lab, route it through a redirector, and tune its profile so the traffic does not match a textbook default signature.
Step 4: Evasion and OPSEC
Time needed: ongoing, and never finished
This is the part that genuinely separates a red teamer from a pentester. A loud operator gets the whole engagement burned in the first hour. The rule here is simple: understand detection before you try to beat it.
Understand detection first
- How antivirus and EDR actually work: signatures, behavioural detection, and telemetry collection
- What Windows event logs, Sysmon and EDR record about your every action
- Why living off the land and blending in beats a clever new exploit most of the time
Then evade thoughtfully
- In memory execution, reflective loading, and sleep masking to cut down artifacts
- Minimising indicators: named pipes, process trees, command line arguments
- Infrastructure OPSEC: clean redirectors, separation of concerns, attribution awareness
The real lesson is that OPSEC is a discipline, not a tool you install. The best operators are boring on purpose. On the defender’s screen they look like a tired sysadmin doing maintenance, not a hacker from a film.
Step 5: Active Directory attacks
Time needed: 4 to 6 weeks, then forever
Most real engagements are won or lost in Active Directory. This is where the largest share of your study time belongs, because this is where the objectives usually live.
The core attack paths
- Enumeration. BloodHound and SharpHound to map attack paths from where you are to where you want to be
- Kerberos abuse. Kerberoasting, AS-REP roasting, and unconstrained and constrained delegation attacks
- ADCS attacks. Certificate template misconfigurations that hand you domain privilege, still underappreciated by defenders
- Domain dominance. DCSync, golden and silver tickets, and understanding exactly what each one proves and costs in noise
Checkpoint: in a lab domain you can get from a low privilege user to domain admin through at least two different paths, and explain the detection opportunity at every step. The second path matters, because on a real engagement the first one is often watched.
Step 6: Report and purple team
Time needed: every engagement
A red team that only breaks in is half a service. The value is delivered in the report and the debrief, where the defenders actually learn what to fix. This is the part that justifies the invoice.
The report
- Attack narrative. The story from initial access to objective, in an order a human can follow
- TTP mapping. Every action tied to a MITRE ATT and CK technique, so it connects to the defender’s world
- Detection analysis. What the blue team saw, what they missed, and what they could have caught
- Remediation. Concrete, prioritised fixes, not an undifferentiated wall of findings
Purple teaming
- Replaying your techniques with the defenders watching, so they can build detections live
- Measuring detection and response time, then improving it together across iterations
- Turning a single engagement into lasting defensive capability, which is the real point
Checkpoint: you can write an engagement report from which a defender, using your document alone, can reproduce your path and build a detection for each step.
A realistic timeline
Red teaming takes longer than most tracks because it stacks on top of pentesting. This assumes you already have offensive security basics and can give it eight to ten hours a week.
| Period | Focus |
| Month 1 to 2 | Foundations, Active Directory lab, Windows internals and logging |
| Month 3 | Offensive tradecraft, the full kill chain in the lab |
| Month 4 | One C2 framework in depth: listeners, profiles, redirectors |
| Month 5 | Evasion and OPSEC against a real EDR in the lab |
| Month 6 to 7 | Active Directory attack paths, multiple routes to domain admin |
| Month 8 and beyond | Full simulated engagements, reports, purple team exercises |
Where red teaming leads
- Red Team Operator. Running adversary simulations end to end, usually reached after pentest experience
- Penetration Tester. The usual stepping stone, and a strong career on its own
- Purple Team Engineer. Bridging offence and defence, building detections from real attacks
- Detection Engineer. Using attacker tradecraft knowledge to write detections that actually fire
- Adversary Emulation Specialist. Replaying specific threat actor TTPs to test defences against real threats
- Offensive Security Lead. Scoping, running and signing off engagements for a team
Frequently asked questions
Can I start red teaming as a complete beginner?
Not directly. It sits on top of penetration testing. Build offensive security fundamentals and get comfortable compromising an Active Directory lab first, then this roadmap makes sense.
Red team or pentest, which pays more?
Red team roles generally pay more because they demand more, but they are fewer and more senior. Most people reach red teaming through pentesting, which is a solid career on its own.
Do I need Cobalt Strike to learn?
No. It is commercial and licensed to organisations. Learn the concepts on free frameworks like Sliver or Mythic. The tradecraft transfers.
How important is Active Directory?
Central. Most enterprise engagements are decided in Active Directory, so it earns the biggest slice of your study time.
Is report writing really part of it?
Yes, and it is what clients pay for. An engagement that compromises everything but produces a weak report delivers very little lasting value.
Is red teaming legal?
Only under a signed rules of engagement with explicit authorisation, or in your own lab. Outside that it is unauthorised access and a crime.
The honest closing
Red teaming looks like the most glamorous corner of security from the outside, all C2 beacons and domain admin. From the inside it is mostly patience, note taking, and the discipline to do the boring quiet thing instead of the exciting loud one.
If you are not there yet on fundamentals, that is fine, and knowing it is a strength. Go build an Active Directory lab, get domain admin on your own two different ways, and write down every detection you would have triggered. Do that, and step one of this roadmap will feel like revision instead of a wall.
Documenting your lab work and engagement style on Hacklido is a good way to build the writing muscle this field runs on. Red teaming is judged on reports as much as on access, and the only way to get good at reports is to write them before anyone is paying for them.