# trustedsec/unicorn

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18.

Repository: https://github.com/trustedsec/unicorn
Canonical: https://ross.abutalabs.com/products/trustedsec-unicorn
Homepage: https://www.trustedsec.com
Language: Python
License: NOASSERTION
License Family: other
Last push: 2026-06-04T20:58:58+00:00

## Health v2 (maintenance only)
Score: 70/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 85, release rhythm 35, longevity 100
- inputs: {"age_days": 4823, "days_push": 90, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3938, forks 819 (observed 2026-08-28T04:08:30.164456+00:00)

## What it is
Magic Unicorn is a Python CLI tool that generates PowerShell downgrade-attack commands to inject shellcode directly into memory. It supports custom shellcode, Metasploit, and Cobalt Strike payloads for paste-and-run delivery.

## Use cases
- generate powershell shellcode injection payload
- powershell downgrade attack tool
- create metasploit powershell one-liner
- inject shellcode into memory via powershell
- generate cobalt strike powershell launcher
- red team payload delivery tool

## When to choose
- you need a quick PowerShell-based shellcode injection command for authorized penetration tests or red team engagements
- you want to integrate Metasploit or Cobalt Strike payloads into a paste-and-run delivery method
- you are testing PowerShell execution-policy bypass and downgrade attack defenses

## When to avoid
- you need a full C2 framework rather than a payload generator
- your target environment blocks PowerShell entirely or has modern AMSI/EDR controls you have not tested against
- you are looking for a defensive or detection tool rather than an offensive one

## Facets
- artifact type: cli-tool
- maturity: active
- function: penetration-testing, security, cli
- domain: security, penetration-testing, developer-tools
- platform: windows, python, cli
- tags: shellcode-injection, powershell-downgrade-attack, offensive-security, red-team, metasploit, cobalt-strike, payload-generation, linux, macos

## Member repositories
- trustedsec/unicorn (main) score 70

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:30.164456+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:24:38.536455+00:00, confidence not recorded.
  - readme: https://github.com/trustedsec/unicorn (fetched 2026-08-28T04:08:30.164456+00:00, sha b51a7e7a0558)
  - homepage: https://www.trustedsec.com (fetched 2026-08-29T09:18:37.926496+00:00, sha 98491e09937e)
  - site_page: https://trustedsec.com/about-us (fetched 2026-08-29T09:18:37.929359+00:00, sha 8ac2cdc5b731)
  - site_page: https://trustedsec.com/about-us/our-team (fetched 2026-08-29T09:18:37.931067+00:00, sha 0eda6bcc5efb)
  - site_page: https://trustedsec.com/about-us/our-partners (fetched 2026-08-29T09:18:37.932777+00:00, sha 0810e8ce8469)
  - site_page: https://trustedsec.com/about-us/news (fetched 2026-08-29T09:18:37.934762+00:00, sha 55a2b3b037f3)
  - site_page: https://trustedsec.com/about-us/events (fetched 2026-08-29T09:18:37.937326+00:00, sha 7d5a1f2427c7)
  - site_page: https://trustedsec.com/ai-security (fetched 2026-08-29T09:18:37.939667+00:00, sha fa8fc686949a)
  - site_page: https://trustedsec.com/blog/trustedsec-achieves-crest-certification (fetched 2026-08-29T09:18:37.941642+00:00, sha 2661985bcc44)
  - site_page: https://trustedsec.com/resources/webinars/risk-at-the-edge-managing-cyber-exposure-across-it-ot-assets (fetched 2026-08-29T09:18:37.943333+00:00, sha c05d99ac917f)
- Data as of 2026-08-30T08:39:29.467469+00:00.
