AWS Red Team Certification (ACRTP)

ACRTP_

AWS Red Team Certification (ACRTP) at a glance


  • Format: Hands-on, assessed in a live AWS environment
  • Focus: service account abuse, IAM escalation, resource abuse, lateral movement
  • Level: Professional
  • Prerequisites: a general security foundation (no prior AWS expertise required)
  • Delivered via: the Amazon Cloud Attack and Defense bootcamp

 

The Amazon Cloud Red Team Professional (ACRTP) certification is earned through the Amazon Cloud Attack and Defense Bootcamp, an instructor-led Pwned Labs program that goes deep on modern attack chains and the detections that catch them, then certifies you hands-on.

Attackers rarely break into AWS by dropping an exploit on a server. They log in with keys that were never meant to be theirs. In AWS, identity and access management is the real perimeter, and an AWS red team certification worth holding should prove you can abuse that layer the way a real intrusion does. The Amazon Cloud Red Team Professional (ACRTP) is built to test exactly that, hands-on, in live AWS accounts.

What the ACRTP certification proves

ACRTP is a hands-on AWS red team certification. There is no multiple choice section. You are dropped into a live AWS account seeded with realistic misconfigurations and telemetry, and you have to work an end-to-end attack chain: enumerate the environment, find the initial foothold, escalate privileges, pivot across services, and demonstrate impact. The assessment measures tradecraft, not trivia. When you pass, the certificate says you attacked real AWS infrastructure and won, which is the claim hiring managers and engagement leads actually care about.

Who this certification is for

ACRTP fits penetration testers moving into cloud, red teamers who need AWS depth, and cloud security engineers who want to understand offense so they can build better defenses. You do not need to be an AWS expert on day one. The Amazon Cloud Attack and Defense bootcamp that leads into the certification starts from cloud fundamentals and moves quickly into IAM abuse, credential theft, and lateral movement, so a strong general security background is enough to keep pace.

What you learn on the path to ACRTP

The curriculum mirrors how AWS environments are actually breached rather than a checklist of service names. Core areas include:

  • IAM enumeration and privilege escalation, including role assumption chains and policy misconfigurations that grant more access than intended.
  • Credential access: harvesting keys from instance metadata, environment variables, source control, and misconfigured storage.
  • Lateral movement across compute, serverless, and container services, and pivoting between accounts in an AWS Organization.
  • Abusing managed services such as S3, Lambda, EC2, and Secrets Manager to persist and reach sensitive data.
  • Detection and telemetry awareness, so you understand what CloudTrail and GuardDuty record while you operate.

Because the labs run in production-like cloud accounts, you practice against the same signals a defender would see. That blue team awareness is what separates a cloud red teamer from someone who only knows a tool.

ACRTP compared to other AWS security certifications

The AWS Certified Security Specialty is a knowledge exam. It validates that you understand AWS security controls and can answer scenario questions, and it is valuable for defensive and architecture roles. It does not ask you to break anything. Other offensive exams prove general penetration testing skill but spend little time on cloud identity, which is where most cloud compromise now happens. ACRTP sits in the gap: an offensive, fully hands-on assessment focused specifically on AWS attack paths. If your goal is to prove you can execute a cloud red team engagement in AWS, a practical certification is more convincing than a knowledge exam.

How the ACRTP exam works

The certification is assessed in a live AWS account, not a simulation. You are given objectives and a time window, and you have to accomplish them using real tradecraft against real services with real logging in place. There is no memorization component and no proctored quiz. You either reach the objectives or you do not, which makes the credential difficult to fake and easy for an employer to trust.

Related labs to build the skills first

You do not have to start with the certification. Pwned Labs hosts free starter labs for AWS where you practice real techniques against live environments in your browser. Working through those labs is the most direct way to gauge your readiness before committing to the bootcamp and exam. Browse the full catalog at pwnedlabs.io/explore.

Get certified

ACRTP is delivered through the Amazon Cloud Attack and Defense bootcamp, an instructor-led program that goes deep on modern AWS attack chains and the detections that catch them, then certifies you hands-on. See the bootcamp and enrollment details at pwnedlabs.io/bootcamps/acrtp-bootcamp.

Frequently asked questions

Is ACRTP a hands-on certification?

Yes. Every ACRTP assessment takes place in a live AWS account with realistic misconfigurations and telemetry. There is no multiple choice component.

Do I need AWS experience before starting?

You need a solid general security foundation, not prior AWS expertise. The bootcamp begins with cloud fundamentals and progresses into advanced IAM abuse and lateral movement.

How is ACRTP different from the AWS Certified Security Specialty?

The AWS Certified Security Specialty is a defensive knowledge exam. ACRTP is an offensive, fully practical certification that requires you to compromise a live AWS environment.

Does ACRTP cover detection as well as attack?

Yes. The labs run against production-like logging, so you learn what CloudTrail and GuardDuty capture while you operate, which builds the purple team awareness employers want.

What roles does ACRTP support?

Cloud penetration tester, cloud red teamer, and cloud security engineer roles where proving offensive AWS capability matters.

What practitioners say.

Caleb Havens

Red Team Operator & Social Engineer, NetSPI


"I’ve attended two training sessions delivered by Pwned Labs: one focused on Microsoft cloud environments and the other on AWS. Both sessions delivered highly relevant content in a clear, approachable manner and were paired with an excellent hands-on lab environment that reinforced key concepts and skills for attacking and defending cloud infrastructures. The training was immediately applicable to real-world work, including Red Team Operations, Social Engineering engagements, Purple Team exercises, and Cloud Penetration Tests. The techniques and insights gained continue to be referenced regularly and have proven invaluable in live operations, helping our customers identify vulnerabilities and strengthen their cloud defenses."

Sebas Guerrero

Senior Security Consultant, Bishop Fox


"The AWS, Azure, and GCP bootcamps helped me get up to speed quickly on how real cloud environments are built and where they tend to break from a security standpoint. They were perfectly structured, with real-world examples that gave me rapid insight into how things can go wrong and how to prevent those issues from happening in practice. I’m now able to run cloud pentests more confidently and quickly spot meaningful vulnerabilities in customers’ cloud infrastructure.

Dani Schoeffmann

Security Consultant, Pen Test Partners


"I found the Pwned Labs bootcamps well structured and strongly focused on practical application, with clear background on how and why cloud services behave the way they do and how common attack paths become possible. The team demonstrates both sides by walking through attacks and the corresponding defenses, backed by hands-on labs that build confidence using built-in and third-party tools to identify and block threats. The red-team labs are hands-on and challenge-driven, with clear walkthroughs that explain each step and the underlying logic. I’ve seen several of these techniques in real engagements, and the bootcamp helped me develop a repeatable methodology for cloud breach assessments and deliver more tailored mitigation recommendations."

Matt Pardo

Senior Application Security Engineer, Fortune 500 company


"I’ve worked in security for more than 15 years, and every step up came from taking courses and putting the lessons into practice. I’ve attended many trainings over the years, and Pwned Labs’ bootcamps and labs are among the best I’ve experienced. When you factor in how affordable they are, they easily sit at the top of my list. As a highly technical person, I get the most value from structured, hands-on education where theory is immediately reinforced through labs. Having lifetime access to recordings, materials, and training environments means you can repeat the practice as often as needed, which is invaluable. If you’re interested in getting into cloud security, sign up for Pwned Labs.

Steven Mai

Senior Penetration Tester, Centene


Although my background was mainly web and network penetration testing, the ACRTP and MCRTP bootcamps gave me a solid foundation in AWS and Azure offensive security. I’m now able to take part in cloud penetration testing engagements and have more informed security discussions with my team.