Files
atomic-red-team/atomics/T1122/T1122.yaml
T

16 lines
299 B
YAML
Raw Normal View History

2018-05-24 17:59:15 -06:00
---
attack_technique: T1122
display_name: Bypass User Account Control
atomic_tests:
- name: PowerShell UAC Bypass
description: |
PowerShell EventViewer Bypass by Matt Nelson
supported_platforms:
- windows
executor:
name: powershell
command: |
Invoke-EventVwrBypass.ps1