trustedsec/unicorn
Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18. observed · 2026-08-28
Health v2 · maintenance only
70/100
- Activity 85
- Release rhythm 35
- Longevity 100
Flags: no_releases no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 4823
- days_rel: n/a
- days_push: 90
- n_releases_24m: 0
Adoption not part of the score
3938 stars · 819 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Magic Unicorn is a Python CLI tool that generates PowerShell downgrade-attack commands to inject shellcode directly into memory. It supports custom shellcode, Metasploit, and Cobalt Strike payloads for paste-and-run delivery.
Use cases
- generate powershell shellcode injection payload
- powershell downgrade attack tool
- create metasploit powershell one-liner
- inject shellcode into memory via powershell
- generate cobalt strike powershell launcher
- red team payload delivery tool
When to choose
- you need a quick PowerShell-based shellcode injection command for authorized penetration tests or red team engagements
- you want to integrate Metasploit or Cobalt Strike payloads into a paste-and-run delivery method
- you are testing PowerShell execution-policy bypass and downgrade attack defenses
When to avoid
- you need a full C2 framework rather than a payload generator
- your target environment blocks PowerShell entirely or has modern AMSI/EDR controls you have not tested against
- you are looking for a defensive or detection tool rather than an offensive one
Facets
cli-tool · maturity active
penetration-testing security cli security penetration-testing developer-tools windows python cli shellcode-injection powershell-downgrade-attack offensive-security red-team metasploit cobalt-strike payload-generation linux macos
10 sources
- readme: https://github.com/trustedsec/unicorn · fetched 2026-08-28 · b51a7e7a0558
- homepage: https://www.trustedsec.com · fetched 2026-08-29 · 98491e09937e
- site_page: https://trustedsec.com/about-us · fetched 2026-08-29 · 8ac2cdc5b731
- site_page: https://trustedsec.com/about-us/our-team · fetched 2026-08-29 · 0eda6bcc5efb
- site_page: https://trustedsec.com/about-us/our-partners · fetched 2026-08-29 · 0810e8ce8469
- site_page: https://trustedsec.com/about-us/news · fetched 2026-08-29 · 55a2b3b037f3
- site_page: https://trustedsec.com/about-us/events · fetched 2026-08-29 · 7d5a1f2427c7
- site_page: https://trustedsec.com/ai-security · fetched 2026-08-29 · fa8fc686949a
- site_page: https://trustedsec.com/blog/trustedsec-achieves-crest-certification · fetched 2026-08-29 · 2661985bcc44
- site_page: https://trustedsec.com/resources/webinars/risk-at-the-edge-managing-cyber-exposure-across-it-ot-assets · fetched 2026-08-29 · c05d99ac917f
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| trustedsec/unicorn | main | 70 |
For agents
markdown · JSON · MCP: product_card(name="trustedsec/unicorn")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem