
PichichiH0ll0wer
Nim-based process hollowing loader for PE executables with configurable injection methods, direct/indirect syscalls, anti-debug, payload encryption,…

Nim-based process hollowing loader for PE executables with configurable injection methods, direct/indirect syscalls, anti-debug, payload encryption,…

Python-based exploit for CVE-2021-21086 in Adobe Acrobat Reader DC, generating malicious PDFs with shellcode execution via crafted font charstrings.

MS17-010_CVE-2017-0143

Google Chrome Use After Free

Simple dotnet Native AOT app that uses AsmResolver to convert shellcode to PE

Laravel RCE exploit. CVE-2018-15133

WonderCMS Authenticated RCE - CVE-2023-41425

Python-based exploit for CVE-2022-22965 (Spring4Shell) with vulnerability detection and webshell injection (Behinder/Godzilla) into Spring web…

Various tools, PoCs and experiments related to my blog at https://www.forrest-orr.net/

Apache Tomcat Manager API WAR Shell Upload

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

CVE-2024-24576 Proof of Concept

spring4shell | CVE-2022-22965

A Proof of Concept for CVE-2023-50564 vulnerability in Pluck CMS version 4.7.18

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

Rust crate for ghost-frame call-stack spoofing, runtime indirect syscalls, and APC injection on Windows x64. Provides SSN resolution, JIT stub…

Evince/xreader/Atril RCE exploit to CVE-2026-46529

The FreeBSD ICMP buffer overflow, freebsd buffer overflow poc