logo

Native PowerShell x86 Shellcode Injection on 64-bit Platforms

ID: 8a346be4-e92d-5a81-99cf-942927fe8216

STIX ID: report--8a346be4-e92d-5a81-99cf-942927fe8216

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2023-09-20

Date Updated: 2026-05-01

...
...

This report provides a technical walkthrough and PoC for executing x86 shellcode from PowerShell on x64 Windows by launching the 32-bit PowerShell under SysWOW64, encoding payloads (Unicode + Base64) to bypass execution restrictions, and integrating msfvenom-generated Meterpreter payloads via a provided Python helper (unicorn.py). It contains one-line and expanded PowerShell examples, discusses limits (HTTPS stager size), and demonstrates successful Meterpreter sessions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.