Ross ROSS = Recommend OSS · open-source software intelligence for agents

trustedsec/unicorn

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18. observed · 2026-08-28

github.com/trustedsec/unicorn · homepage · Python · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

70/100

  • Activity 85
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4823
  • days_rel: n/a
  • days_push: 90
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

3938 stars · 819 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Magic Unicorn is a Python CLI tool that generates PowerShell downgrade-attack commands to inject shellcode directly into memory. It supports custom shellcode, Metasploit, and Cobalt Strike payloads for paste-and-run delivery.

Use cases

  • generate powershell shellcode injection payload
  • powershell downgrade attack tool
  • create metasploit powershell one-liner
  • inject shellcode into memory via powershell
  • generate cobalt strike powershell launcher
  • red team payload delivery tool

When to choose

  • you need a quick PowerShell-based shellcode injection command for authorized penetration tests or red team engagements
  • you want to integrate Metasploit or Cobalt Strike payloads into a paste-and-run delivery method
  • you are testing PowerShell execution-policy bypass and downgrade attack defenses

When to avoid

  • you need a full C2 framework rather than a payload generator
  • your target environment blocks PowerShell entirely or has modern AMSI/EDR controls you have not tested against
  • you are looking for a defensive or detection tool rather than an offensive one

Facets

cli-tool · maturity active

penetration-testing security cli security penetration-testing developer-tools windows python cli shellcode-injection powershell-downgrade-attack offensive-security red-team metasploit cobalt-strike payload-generation linux macos

10 sources

Member repositories

RepositoryRoleHealth v2
trustedsec/unicornmain70

For agents

markdown · JSON · MCP: product_card(name="trustedsec/unicorn")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem