mirror of
https://github.com/kernelstub/Ferrum
synced 2026-06-21 13:55:09 +00:00
2.4 KiB
2.4 KiB
FERRUM
Ferrum is a Windows-first vulnerability research and security auditing framework written in Go. It is designed as a single binary, ferrum.exe, with modules registered through a small core interface.
Build
GOOS=windows GOARCH=amd64 go build -o ferrum.exe ./cmd
Or use the included script:
.\scripts\build-windows.ps1
From Linux/macOS:
./scripts/build-windows.sh
Usage
ferrum.exe --HELP
ferrum.exe --ALL --VERBOSE
ferrum.exe --ALL --OUTPUT ferrum-reports
ferrum.exe --CLSID
ferrum.exe --CLSID --OUTPUT clsid.txt
ferrum.exe --TOKENS
ferrum.exe --REGISTRY
ferrum.exe --POLICY
ferrum.exe --DLLSEARCH
ferrum.exe --SERVICES
ferrum.exe --DRIVERS
ferrum.exe --PIPES
ferrum.exe --STARTUP
ferrum.exe --SCHEDULED
ferrum.exe --ENV
ferrum.exe --MITIGATIONS
ferrum.exe --AUTORUNS
ferrum.exe --IFEO
ferrum.exe --SILENTEXIT
ferrum.exe --WINLOGON
ferrum.exe --LSA
ferrum.exe --APPINIT
ferrum.exe --APPCERT
ferrum.exe --UAC
ferrum.exe --INSTALLER
ferrum.exe --POWERSHELL
ferrum.exe --APPLOCKER
ferrum.exe --WDAC
ferrum.exe --DEFENDER
ferrum.exe --FIREWALL
ferrum.exe --RDP
ferrum.exe --WMI
ferrum.exe --HOSTS
ferrum.exe --SHARES
ferrum.exe --SHELL
ferrum.exe --BROWSER
ferrum.exe --PROTOCOLS
ferrum.exe --COMLOCAL
ferrum.exe --KNOWNDLLS
ferrum.exe --SVCPATHS
ferrum.exe --DRIVERPATHS
ferrum.exe --CERTIFICATES
ferrum.exe --NETWORKPROVIDERS
ferrum.exe --PRINT
ferrum.exe --WINSOCK
ferrum.exe --ACCESSIBILITY
ferrum.exe --CLSID --VERBOSE
ferrum.exe --CLSID --QUIET
Architecture
cmd/contains the CLI entry point.core/contains module registration, context, and banner code.modules/contains research modules. New modules implementcore.Moduleand callcore.Register.windows/contains build-tagged Windows API wrappers and non-Windows stubs.output/contains console logging.
Output
Write a single module report:
ferrum.exe --CLSID --OUTPUT clsid.txt
Run every module and write one file per module:
ferrum.exe --ALL
ferrum.exe --ALL --OUTPUT ferrum-reports
Without --OUTPUT, --ALL creates a timestamped folder such as ferrum-output-20260613-153000.
CLSID ProcMon Filter Model
--CLSID models this ProcMon workflow for COM hijack/LPE triage:
User is NT AUTHORITY\SYSTEMPath contains HKCU\Software\ClassesPath contains InprocServer32Path contains LocalServer32Result is NAME NOT FOUND