
PINKPANTHER
Windows x64 handcrafted token stealing kernel-mode shellcode

Windows x64 handcrafted token stealing kernel-mode shellcode

PE injection technique that overwrites a suspended process's executable with a payload, enabling code execution under a benign process identity.

Proof-of-concept exploit for CVE-2023-21608, a Use-After-Free vulnerability in Adobe Acrobat Reader enabling remote code execution via crafted PDF…

A WebKit exploit using CVE-2018-4441 to obtain RCE on PS4 6.20.

Previously-0day exploit from the Hacking Team leak, written by Eugene Ching/Qavar.

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

A Nim implementation of reflective PE-Loading from memory

Exploit Development - Weaponized Exploit and Proof of Concepts (PoC)

This is an exploit for CVE-2020-0674 that runs on the x64 version of IE 8, 9, 10, and 11 on Windows 7.

CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking

Proof-of-concept exploit for CVE-2023-41993, a WebKit JIT type confusion in Safari. Provides addrof/fakeobj primitives via heap manipulation and…

Chrome V8 n-day exploits that I've written.

simple shellcode generator

Full exploit of CVE-2016-6754(BadKernel) and slide of SyScan360 2016

Foxit PDF Reader Remote Code Execution Exploit

Exploit for CVE-2018-4233, a WebKit JIT optimization bug used during Pwn2Own 2018

poc for CVE-2025-24252 & CVE-2025-24132

Shellcode injection using the Windows Debugging API