Atomic Red T1548.002

Invoke-AtomicTest T1548.002

Executes the UAC bypass atomic tests (T1548.002) with Atomic Red Team, validating detection of privilege escalation via UAC.

Run it in the purple team lab when you want to validate UAC bypass detection: the T1548.002 atomics replicate known bypasses (fodhelper, eventvwr, UACME ones) and the team verifies what was detected — Sysmon Event 13 (the bypass key), SIEM rules, EDR. It's the detection validation of the escalation: the real attacker technique. In purple teaming, atomics validate UAC rules and the result feeds the matrix.

Do not run it in production: bypasses modify the registry and elevate processes — the lab is the place. And note: T1548.002 is a family (registry bypasses, autoElevate binaries): each atomic validates a bypass — coverage is validated per variant. Detection of the change in the bypass key (Sysmon Event 13) is the classic rule being validated. Modern bypasses (UACME ones) evolve: the atomic validates documented variants, new ones require updated atomics. Test host with UAC at default level (the bypass requirement).