Frequently Asked Questions

Everything you need to know before you start.

Getting Started

What is red teaming, and how is it different from regular penetration testing?
Red teaming means testing an organization's real-world defenses the way an actual adversary would, not just scanning for technical vulnerabilities. A typical penetration test focuses on finding and exploiting weaknesses in networks or applications. Red teaming goes further: it also tests the human element through social engineering and the physical element through covert entry, because a real attacker does not care which category their way in falls into. This training covers all three: physical, social, and cyber.
Do I need prior security or IT experience to start?
No. The curriculum starts with the legal and ethical foundations of red teaming before moving into technique, so you do not need a security background to begin. The more advanced, tool-heavy courses later in the path build on the earlier ones, so working through the curriculum in order gets you there fastest.
Where should I start?
Start with Legal, Ethical and Regulatory Foundations and Pre-Engagement: Scoping, Safety and Authorization. Those two set up the legal and planning groundwork that every other course builds on. From there, Reconnaissance Fundamentals and Social Engineering are natural next steps. Each course page also notes what it assumes you already know.
Is there an age requirement?
Yes. You must be at least 18 to purchase or use these Services. If you are under 18, a parent or legal guardian needs to be involved and consent on your behalf.
Is it legal to learn what's taught in these courses?
Yes. This is full-spectrum red team training, covering physical, social, and cyber tradecraft, and every part of it is legal to learn and practice as long as you are working on your own property and equipment or have explicit written authorization from the owner. Using these same skills against people, property, or systems you do not own or are not authorized to test is illegal in most jurisdictions, including under the Computer Fraud and Abuse Act in the United States. Every course in this curriculum is built around staying inside that line, not around how to cross it.

Courses and Access

How many courses are there?
Ten courses make up the full curriculum, covering the complete red team path from legal groundwork through physical entry, social engineering, tools, and reporting. Courses are being updated constantly, check the Courses page for the current lineup.
Are the video lessons available right now?
Courses launch with the full written curriculum. Video lessons are being produced and released progressively, so if a course you purchased does not have video yet, it is on the way, not missing.
How long do I have access after I purchase a course?
Access does not expire. Once you purchase a course, it is yours for as long as Red Team and this platform are up and running.
Do you offer a certificate, and is it industry-recognized?
Certificates of completion are issued for applicable courses and are valid for 3 years from the date you earn them. They represent that you completed the material, they are not a professional license, a government accreditation, or a guarantee of employment.
Will completing these courses guarantee me a job in cybersecurity?
No. No course, certificate, or training program can guarantee employment, salary, or career outcomes. What you get is real, field-tested skill and knowledge, what you do with it is up to you.

Payment and Refunds

What's your refund policy?
All sales are final. Because you get immediate access to the full digital course upon purchase, we do not offer refunds, credits, or exchanges for any reason. Review the free preview lessons before you buy so you know what you are getting.
What payment methods do you accept?
Payments are processed securely through third-party providers. We never see or store your full card details.
Can I purchase from outside the United States?
Yes, with the exception of countries under U.S. embargo or sanctions. You are responsible for complying with the laws of wherever you live in addition to the terms stated here.

Legal and Equipment, In Depth

Are lock picks legal to own?
In most of the United States, yes. The large majority of states have statutes that explicitly permit possession. A handful of states (Mississippi, Nevada, Ohio, and Virginia) treat certain circumstances, such as concealed possession or possession outside a business context, as evidence of criminal intent, meaning you may need to show a lawful purpose if questioned. A few states (including Arkansas, Indiana, North Dakota, Pennsylvania, and West Virginia) have no specific statute addressing possession at all. Laws change and vary by state and country, so confirm the current law where you live before assuming.
Are RFID cloning tools like a Flipper Zero or Proxmark legal to own?
Yes, in the United States these devices are federally legal to purchase and own. There is no law against ownership. What is illegal is using one to access a system, clone a credential, or open a lock you do not own and are not authorized to test. Owning the hardware is not authorization to use it on anything but your own equipment or an engagement you are contracted for.
What tools do I need for the physical courses?
Tool requirements vary by course, and each one lists what you need so you can source it yourself. If you want a starting point, my free, open-source field tool list is on GitHub.

Support

Is there a community where I can ask questions or connect with other students?
Yes. Join the Discord to ask questions, connect with other students, and see ongoing red team tradecraft as it happens.
I found a security issue on the site. How do I report it?
Email [email protected] with the details and give us reasonable time to fix it before disclosing it publicly. Responsible disclosure is appreciated.
Who do I contact with other questions?