Atomic Red T1078

Invoke-AtomicTest T1078

Executes the valid accounts atomic tests (T1078) with Atomic Red Team, validating detection of legitimate credential usage.

Run it in the purple team lab when you want to validate detection of valid account usage: T1078 atomics replicate access with legitimate credentials (logon with the account, credential usage) and the team verifies what was detected — Event 4624, SIEM logon rules, EDR. It's the validation of access detection: the attacker technique that uses what's legitimate. In purple teaming, T1078 atomics validate logon rules and the result feeds the matrix.

Don't run it in production: access with credentials generates real logons — the lab is the place. And note: T1078 is the technique of valid account usage (the hardest to detect because it's legitimate): validation focuses on anomalies (origin, timing, behavior) — atomics test access, anomaly rules are validated with context. The atomic with lab credentials; the 'detected' result depends on the anomalous logon rule, not the logon itself (which is legitimate).