
PhantomCtx
Activation Context Hijacking Evasion Tool

Activation Context Hijacking Evasion Tool

Exploit for CVE-2017-11882 (Microsoft Office Equation Editor buffer overflow) supporting shellcode injection and command execution with payloads up…

Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin…

Windows local privilege escalation exploit for CVE-2018-8120 supporting x32 and x64 architectures, tested on multiple Windows 7 and 2008 variants.

Exploit for CVE-2023-34312: local privilege escalation in Tencent QQ/TIM via arbitrary address write vulnerabilities in QQProtect.exe, enabling…

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

Kernel exploit for Xbox SystemOS using CVE-2024-30088

Windows x64 handcrafted token stealing kernel-mode shellcode

Previously-0day exploit from the Hacking Team leak, written by Eugene Ching/Qavar.

This is an exploit for CVE-2020-0674 that runs on the x64 version of IE 8, 9, 10, and 11 on Windows 7.

Weaponized exploit and proof-of-concept repository for Windows kernel and user-mode exploits, featuring ROP chains, ASLR bypass, and privilege…

CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking

Shellcode injection using the Windows Debugging API

Proof-of-concept framework for CVE-2025-24252 and CVE-2025-24132, providing mDNS crash trigger and heap overflow reverse shell with multiple payload…

Python exploit for CVE-2025-11001/11002 targeting 7-Zip on Windows, leveraging symlink creation to achieve code execution when 7-Zip runs with admin…

Python script that wraps nasm/objdump to quickly generate shellcode bytes from assembly instructions or compiled ELF binaries, supporting multiple…

Local privilege escalation exploit for CVE-2020-1066 targeting Windows 7 and Server 2008 R2. Leverages arbitrary file replacement via Windows…

Hijacks code execution via overwriting Control Flow Guard pointers in combase.dll