2026-06-14 00:10:43 +02:00
2026-06-13 15:48:59 +02:00
2026-06-13 15:48:59 +02:00
2026-06-13 15:48:59 +02:00
2026-06-13 15:48:59 +02:00
2026-06-13 15:48:59 +02:00
2026-06-13 15:44:36 +02:00
2026-06-13 15:48:59 +02:00
2026-06-13 15:44:36 +02:00
2026-06-13 15:57:56 +02:00

FERRUM

image

Ferrum is a Windows-first vulnerability research and security auditing framework written in Go. It is designed as a single binary, ferrum.exe, with modules registered through a small core interface.

Build

GOOS=windows GOARCH=amd64 go build -o ferrum.exe ./cmd

Or use the included script:

.\scripts\build-windows.ps1

From Linux/macOS:

./scripts/build-windows.sh

Usage

ferrum.exe --HELP

Architecture

  • cmd/ contains the CLI entry point.
  • core/ contains module registration, context, and banner code.
  • modules/ contains research modules. New modules implement core.Module and call core.Register.
  • windows/ contains build-tagged Windows API wrappers and non-Windows stubs.
  • output/ contains console logging.

Output

Write a single module report:

ferrum.exe --CLSID --OUTPUT clsid.txt

Run every module and write one file per module:

ferrum.exe --ALL
ferrum.exe --ALL --OUTPUT ferrum-reports

Without --OUTPUT, --ALL creates a timestamped folder such as ferrum-output-20260613-153000.

CLSID ProcMon Filter Model

--CLSID models this ProcMon workflow for COM hijack/LPE triage:

  • User is NT AUTHORITY\SYSTEM
  • Path contains HKCU\Software\Classes
  • Path contains InprocServer32
  • Path contains LocalServer32
  • Result is NAME NOT FOUND
S
Description
Automated archival mirror of github.com/kernelstub/Ferrum
Readme GPL-3.0 1.1 MiB
Languages
Go 99.6%
PowerShell 0.2%
Shell 0.2%