Rogue Labs - Rogue Ops - Red Team I Review

by on under RedTeaming
5 minute read

Rogue Ops I

RT1

I just recently completed the Rogue Ops - Red Team 1 (ROPS-RT1) from Rogue Labs, along with their certification exam. Since then, I have already had people I spoke to ask me about it, due to how new and unknown it is in the industry at the time of writing.

What is it?

The ROP-1 is an entry level Red Team oriented certification, featuring an impressive lab environment and well thought out course structure. The instructor, Nick Downer is an industry veteran Red Teamer and co-author of the Red Team Field Manual v2.

The course

The entire course, including the labs run through what they call the “Rogue Arena”. Within it, virtual machines can be spun up and down, as well as GUI sessions to the various lab instance machines can be accessed. This allows for students without a powerful computer to be able to comfortably take the course, as local virtual machines are not required.

ROPS-RT1 also features Cobalt Strike(“CS”), the industry Gold Standard as the C2 Framework used for the course. As far as I know, the only other course provider that teaches the use of CS is Zero-Point Security.

The interface

If purchased for organizations and teams, I see some added value where there is a “manager” dashboard, where team leads can have an overview of their team’s progress as they move along. However as I am just a slave normal team member, I am unable to see it and hence will not be able to share more.

There is also a team interface, where you can see the progress of your teammates.

![dashboard][/images/2026/ROPS-RT1/dashboard.png)]

The Swag

I don’t know about you, but as a common pleb, I love free stuff! And I must say Rogue gives some of the best swag out there, period. I won’t say exactly what they are as they may change over time, but they are high quality stuff that you can use on a day to day basis. #trustmebro

Comparison with the Zero-Point RTO1

elephant

Of course first we must address an important question. How does it stack up against what I deem to be its immediate competitor, the ZPS-RTO1?

I will start by saying I think this is an easier course and certification than the RTO1. There is less coding involved, with significantly less technical skill required. This is an amazing course for Offensive Security beginners dipping their toes into Red Teaming. with very useful tips on Operational Security, but do not expect to take this and expect to become an elite Red Teamer like the marketing suggests. In fact, neither of the 2 will do that; but the RTO1 just goes that fair bit further into the technical stuff.

The ROPS-1 is also significantly more hand-holdy throughout the course, which could be better suited for learners who prefer being spoonfed taught in a very detailed step by step manner. I guess this could be a strategic move; as the newer generation(IYKYK) enter the workforce, this style of teaching would be more attractive to them and set them up well to be the new upcoming generation of Red Team Professionals.

The Exam

The exam was a 2 day affair, spanning 2 days, about 10 hours each day.; It was proctored where you had to turn on your webcam and screen share. This was a nice touch as I’ve seen in increasing number of noob shit cert buyer/cheaters in the previous years, so having proctoring adds a layer of credibility to RT1 holders.

p.s. If you have to cheat or have to buy Cybersecurity certifications, please consider leaving the industry and let more deserving people have the jobs. I would also recommend going out and apologizing to the plants and trees for you wasting the oxygen they produce.

The certification challenge(as they call it) was held in the same environment as the labs, with a custom scenario spun up for you. It’s quite different from the usual practical exams you see and hear from various training providers. The exams were scenario based and had a clear attack path, where you have to put what you have learnt to the test as you hit each objective. You don’t have much guesswork required, and just have to refer to your notes. e.g. “how do I ldap query to find a machine named XXX?”

During the exam I had a strange bug which got me stuck for an hour or two, but thankfully the proctor was watching and pinged me to retry a certain thing I had done previously.

Logging and cleanup is also an integral part of the exam, which Nick saying that successfully clearing all the objectives but having subpar logging may cause you to fail. In my opinion while it can be annoying, this is reflective of a real world engagement. Logging methodology may differ from person to person, and some mature Red Teams may even have automated logging to some extent. But the idea of getting the student used to the idea of logging, which is crucial for reporting and cleanup later is unique and the first I’ve seen in a course. No report is required (thank God).

All in all, I’d say 2 days is more than sufficient to complete everything, I had completed it within the first day, while most of my team who took the exam with me cleared them early on the second day.

The Stretch Labs

Now here comes the stretch labs. These can be completed before or after the certification challenge, and is totally optional. Every couple of modules during the labs, there are stretch goals presented. The techniques to achieve these goals are typically not taught in the course, and provide an extra challenge should you be up for it. These have varying difficulties and some were fairly interesting to solve.

Completing all stretch labs and submitting them will award you the “Overachiever” badge and a challenge coin.

Summary

All in all, it was a nice experience. The team has definitely put a ton of effort into the course creation. There were quite a few teething issues but they would most likely have been resolved by the time you read this.

cert

1 https://www.zeropointsecurity.co.uk/

Red Team, Rogue, Cobalt Strike, Active Directory