mirror of
https://github.com/kernelstub/Ferrum
synced 2026-06-21 13:55:09 +00:00
9d5684de259529372618a4af66e16bc1af052773
FERRUM
Ferrum is a Windows-first vulnerability research and security auditing framework written in Go. It is designed as a single binary, ferrum.exe, with modules registered through a small core interface.
Build
GOOS=windows GOARCH=amd64 go build -o ferrum.exe ./cmd
Or use the included script:
.\scripts\build-windows.ps1
From Linux/macOS:
./scripts/build-windows.sh
Usage
ferrum.exe --HELP
Architecture
cmd/contains the CLI entry point.core/contains module registration, context, and banner code.modules/contains research modules. New modules implementcore.Moduleand callcore.Register.windows/contains build-tagged Windows API wrappers and non-Windows stubs.output/contains console logging.
Output
Write a single module report:
ferrum.exe --CLSID --OUTPUT clsid.txt
Run every module and write one file per module:
ferrum.exe --ALL
ferrum.exe --ALL --OUTPUT ferrum-reports
Without --OUTPUT, --ALL creates a timestamped folder such as ferrum-output-20260613-153000.
CLSID ProcMon Filter Model
--CLSID models this ProcMon workflow for COM hijack/LPE triage:
User is NT AUTHORITY\SYSTEMPath contains HKCU\Software\ClassesPath contains InprocServer32Path contains LocalServer32Result is NAME NOT FOUND
Languages
Go
99.6%
PowerShell
0.2%
Shell
0.2%