Atomic Red T1059.001

Invoke-AtomicTest T1059.001

Executes PowerShell atomic tests (T1059.001) with Atomic Red Team, validating detection of offensive PowerShell execution.

Run it in the purple team lab when you want to validate detection of PowerShell abuse: T1059.001 atomics replicate offensive variants (-enc execution, download cradles, policy bypass) and the team verifies what was detected — ScriptBlock Logging (Event 4104), SIEM rules, EDR. It's PowerShell detection validation: the real attacker technique. In purple teaming, T1059.001 atomics validate PowerShell logging and rules, and the result feeds the matrix.

Don't run it in production: offensive PowerShell execution generates real events — the lab is the place. And note: T1059.001 is a family (cradles, enc, bypasses): each atomic validates a variant — coverage is validated per variant. Detection depends on logging (ScriptBlock Logging enabled): without 4104, the rule has no data — the exercise also validates telemetry configuration. The obfuscated -enc atomic validates the obfuscation rule; the cradle validates the download rule.