Skip to content
CyberWarFare Labs Certified Purple Team Analyst v2 (CPTA)

Review — CyberWarFare Labs : Certified Purple Team Analyst [CPTA v2], My First Purple Team Certification

June 2025CyberWarFare LabsPassed
Certification
CPTA v2
Provider
CyberWarFare Labs
Difficulty
Intermediate
Rating
★★★★½4.5/5.0
Introduction

Hello everyone! It's me Chicken0248 again. In this blog I'll briefly cover the Certified Purple Team Analyst [CPTA v2] course, labs, and exam from CyberWarFare Labs, known for affordable cybersecurity training, frequent discounts, and their cloud lab environments.

Course Experience
CPTA v2 course portal
Figure 1

Course access is available immediately after purchase. You can review the full syllabus here.

One thing to note: the syllabus is missing a section called Purple Teaming Infrastructure, which covers the blue team toolset used in the course and labs:

  • Wazuh ELK
  • Velociraptor
  • TheHive
  • MISP
  • Moloch / Arkime
  • IDS Tower
Lab Experience
CPTA v2 lab environment diagram — attack and blue team investigation sides
Figure 2

The lab environment has you connect via VPN, attack an external-facing network and an Active Directory network, then pivot to the blue team side to observe and investigate the activity using the tools taught in the course.

To be honest, I didn't complete any of the labs before taking the exam. I tried to run through the AD Exploitation & Investigation lab on the Friday before my exam date, but I couldn't access IDS Tower and support was offline for the evening, so I went into the exam cold.

Lab access activation page
Figure 3
OpenVPN file and credentials for lab environment
Figure 4

Lab time doesn't start automatically after purchase: you activate it yourself, which kicks off a 30-day countdown. Once activated, you'll get an OpenVPN file and credentials to connect.

Lab modules breakdown
Figure 5

There are 4 lab modules with 29 labs in total:

  • Web Exploitation & Investigations: 6 labs
  • Network Exploitation & Investigations: 7 labs
  • Host Exploitation & Investigations: 6 labs
  • AD Exploitation & Investigations: 10 labs

The labs cover very accessible red team techniques and the corresponding investigation process for each attack: great for anyone just starting out on either the red or blue team side. I revisited the lab environment after the exam and IDS Tower was still down, but every other lab worked fine without it. Don't let that stop you. Do the labs before your exam.

Exam Experience
CPTA v2 exam certification procedure
Figure 6

The exam format is 48 hours total: 24 hours of lab access to the exam environment, followed by 24 hours to complete and submit your deliverable report. If you fail, you get one free retake with feedback provided.

Unlike CRTA and CCDA which require scheduling by email, CPTA v2 uses an online scheduling portal.

Exam scheduling calendar — pick a date and time in GMT
Figure 7

Head to the exam page on the labs portal, pick an available date, select your time in GMT, and click "SCHEDULE".

Confirmation dialog — type Confirm to proceed
Figure 8

A confirmation dialog will appear: type "Confirm" and click "SCHEDULE" again to lock it in.

Exam scheduled confirmation screen
Figure 9

Your schedule is now confirmed and you'll receive a confirmation email.

Exam countdown timer and pre-exam information on the portal
Figure 10

The countdown starts immediately after scheduling. You can cancel up to 3 hours before the start time, and some exam information is visible on this page ahead of time. One heads-up: you won't receive a reminder email on exam day, so set your own alarm.

Once the exam starts, the exam page will display everything you need: VPN file and credentials, blue team environment credentials, scenario, red team simulation, blue team objectives, overall exam objectives, deliverable requirements, and scope of engagement. A live countdown timer is always visible.

On the red team side, you can complete the red team objectives within about an hour. It's actually easier than CRTA on the attack side, but remember: this is a purple team exam. The real work is conducting multiple targeted attacks, investigating each one on the blue team side, and creating detection rules for them. After fully compromising the domain controller I stepped back, re-read the exam objectives, and built a proper plan for the attack-investigate-detect cycle before writing my report alongside execution.

Lab revert in progress — 3-minute revert with extra time for Windows initialization
Figure 11

The exam includes 2 revert quota. I used my first revert to start fresh: a clean environment meant I could execute each attack step deliberately and investigate it without leftover noise from my initial blind run. Revert takes about 3 minutes, plus extra time for Windows machines to fully initialize and agents to reconnect to the SIEM.

On the blue team side, the toolset is quite different from CCDA. Not all tools and log sources covered in the course and labs will be present in the exam environment, so take time to explore what's available before diving into your investigation.

Near the end of report writing, my Elastic instance broke: a missing configuration caused all logs to disappear and I couldn't query anything. I wrapped up what I had and submitted. If this happens to you, contact support immediately: a revert alone may not fix an Elastic configuration issue.

Report submission still goes via email with a specific subject line and filename. You'll get the subject when you book, and the required filename after your 24-hour lab window closes, at which point the 24-hour report submission countdown begins.

Report submission acknowledgement email
Figure 12

After submitting, CyberWarFare Labs will acknowledge receipt and ask you to wait 5–7 business days for results.

Pass result email received on Friday
Figure 13

I received my result on a Friday, longer than CRTA and CCDA (which both came back the next day), but still well within the window. Passed on the first attempt.

Unusually, they sent the certificate via email rather than through Accredible. The reason was explained in a note included with the result:

Digital Certificate + Badge (via Accredible): We're currently updating our badge infrastructure. You can expect to receive your Accredible certificate and shareable badge by mid-July. We'll notify you as soon as it's live.

There was also a slight date error on the emailed certificate due to the manual process, but nothing significant.

Accredible link generation on the exam portal
Figure 14

I noticed you could generate an Accredible link directly from the exam portal, so I tried it.

Accredible certificate — white box artifact and incorrect date
Figure 15

And it worked, but the certificate had a white box artifact next to the CWL CEO's name, and the date reflected the moment I generated the link rather than the actual exam date. Best to wait until mid-July as advised before generating your shareable badge.

Key Takeaways & Tips
  • Document every step you take on the red team side, including timestamps of each attack.
  • This is not just a red team exam. It's a purple team exam. If you approach it with a purely offensive mindset, you'll likely fail. Think like a blue teamer too.
  • Purple teaming is about planning. Your success comes from your plan and how you execute it.
  • If you're unsure how to plan your approach, reference the lab walkthroughs in the course.
  • Use your revert quota carefully: it takes time for machines to start and for agents to reconnect to the SIEM after a revert.
  • If your Elastic instance breaks (e.g., missing config causes logs to vanish), contact support immediately: a revert may not resolve it.
  • Use the pre-built detection rules from the lab walkthroughs as a guide for writing your own. In some cases they'll work with only minor adjustments.