Cloud and identity
AWS and Active Directory attack-path testing. We map the lateral-movement and privilege-escalation chains that turn a single foothold into full domain or account compromise.
FerrumSec is the dedicated security division of Funway Interactive SRL. We work both sides of the line: hands-on penetration testing that finds what real attackers would find, and a growing suite of defensive tools and platforms — engineered in Rust — built to shut those doors for good.
A division of Funway Interactive SRL · Chișinău, MoldovaA focused security team inside Funway Interactive SRL (Chișinău, Moldova), backed by 25 years of software engineering and current, hands-on offensive security credentials.
We don't outsource judgment or ship checkbox security. Every engagement we run and every tool we build comes from people who do the work themselves — people who write software for a living, not just slide decks.
FerrumSec operates from two directions at once.
Not a scanner run and an auto-generated PDF. Our engagements run on a structured framework: defined rules of engagement, repeatable runbooks, a thorough scoping and intake process, and prioritized reporting you can actually act on. You get an adversary's-eye view of your environment, then a clear path to closing the gaps.
AWS and Active Directory attack-path testing. We map the lateral-movement and privilege-escalation chains that turn a single foothold into full domain or account compromise.
Find, report, remediate, retest. We come back and verify the fixes actually hold, so remediation isn't taken on faith.
Incident-response tooling, including raw-volume NTFS recovery and secure-deletion work, for when something has already gone wrong.
Fast, memory-safe, transparent, and free of the surveillance and dark patterns that infest so much commercial security software — whether it's a platform you sign in to or a tool you run yourself. Most are built in Rust; several are open source under the MIT license.
Beyond the standalone tools, FerrumSec is building a line of hosted platforms — full products you sign in to and put to work. They share a single account through Ferrum ID and the same Rust foundations: memory-safe, multi-tenant by design, and built without telemetry or dark patterns. All three are in beta, rolling out now at their own subdomains.
The identity backbone of the suite. One account and one sign-on across every Ferrum product, with organizations, roles, and licensing managed in a single place — backed by EdDSA-signed sessions, Argon2id password hashing, and Postgres row-level tenant isolation.
An incident-response tabletop simulator. Run your team through a fictional ransomware, business-email-compromise, or supplier-breach scenario, capture every decision and gap as it unfolds, score readiness across ten categories, and leave with a board-ready after-action report — no consultant required. Strictly defensive: simulations only, never live attacks.
Continuous external posture monitoring. Point it at a domain and it runs safe, non-invasive public checks — DNS and email security, TLS, HTTP headers, exposed services — then grades cyber hygiene from A to F with prioritized, plain-language fixes and a professional report. Safe by design: no exploitation, no brute forcing, never intrusive.
Lean, native utilities for offense and defense — most built in Rust, several open source under the MIT license.
A fast, asynchronous vulnerability scanner. Detection logic is defined in YAML templates and is Nuclei-compatible — the rules you already trust run unchanged. Built in Rust for throughput and a small footprint.
An intercepting proxy for web application security testing — a lean, native alternative to heavyweight Java-based proxies. Built on a Rust GUI (egui) for a fast, low-overhead workflow that gets out of your way.
Linux-first anti-rootkit defense. Built on eBPF via Aya (a pure-Rust eBPF stack), it watches the kernel boundary where rootkits hide and persist. Open source, MIT-licensed.
Cross-platform anti-ransomware. Behavioral detection that recognizes encryption activity and shuts it down before it spreads — backed by a documented threat model and signed, verifiable distribution, so you can trust exactly what you're running.
A macOS maintenance utility built the FerrumSec way: it does exactly what it says, removes only what it should, and never holds your machine hostage behind a subscription nag.
The same convictions shape every engagement we run and every tool we ship.
Memory safety and performance aren't features we bolt on — they're the foundation. The entire class of memory-corruption bugs behind so many real-world exploits simply doesn't apply to most of what we ship.
Security you can't inspect is security you have to take on trust. Where it makes sense, our tools are open source under the MIT license — read the code, audit it, build on it.
No ads. No telemetry quietly selling your data. No scareware, no manipulative subscriptions, no nag screens. Security software that exploits its own users has no business calling itself security software.
Short, factual answers about FerrumSec, our offensive security work, and the Ferrum Suite.
FerrumSec is the dedicated security division of Funway Interactive SRL, based in Chișinău, Moldova. It works both sides of the line: hands-on offensive security testing and a Rust-engineered suite of defensive tools called the Ferrum Suite. Its tagline is "Security forged in iron."
FerrumSec offers offensive security services that are available now: penetration testing built on a real methodology (defined rules of engagement, repeatable runbooks, thorough scoping and intake, and prioritized reporting); AWS and Active Directory cloud-and-identity attack-path testing covering lateral movement and privilege escalation; two-pass engagements that find, report, remediate, and retest; and forensics and recovery, including incident-response tooling, raw-volume NTFS recovery, and secure deletion.
The Ferrum Suite is FerrumSec's family of defensive security software, currently in active development. It spans hosted platforms — Ferrum ID (a single sign-on, identity, and licensing hub for the suite), Ferrum ResponseLab (an incident-response tabletop simulator that scores readiness and produces after-action reports), and Ferrum Sentinel (a safe external cyber-posture scanner that grades a domain's hygiene from A to F) — alongside standalone tools: Ferrum Scanner (a fast asynchronous, Nuclei-compatible vulnerability scanner using YAML templates), Ferrum Proxy (an intercepting proxy for web application security testing with a Rust egui GUI), Ferrum AntiRK (a Linux-first anti-rootkit tool using eBPF via Aya), Ferrum Aegis (cross-platform anti-ransomware with behavioral detection), and Ferrum MacCleaner (a planned macOS maintenance utility). Everything is fast, memory-safe, and transparent, mostly built in Rust, with no telemetry or dark patterns.
They are the Ferrum Suite's hosted platforms, currently in beta. Ferrum ID is the identity hub — one account and single sign-on across every Ferrum product, with central organizations, roles, and licensing. Ferrum ResponseLab is an incident-response tabletop simulator: teams rehearse fictional ransomware, business-email-compromise, or supplier-breach scenarios, capture decisions and gaps, score their readiness across ten categories, and leave with a board-ready after-action report — no consultant required. Ferrum Sentinel is a safe external posture scanner: it runs non-invasive public checks on a domain (DNS and email security, TLS, HTTP headers, exposed services), grades cyber hygiene from A to F, and delivers prioritized fixes and a professional report. Each runs at its own subdomain: id.ferrumsec.com, responselab.ferrumsec.com, and sentinel.ferrumsec.com.
Several Ferrum Suite tools are open source under the MIT license. Ferrum AntiRK is open source and MIT-licensed. FerrumSec's principle is "open where it counts" — releasing tools as open source under the MIT license where it makes sense, so the code can be read, audited, and built on.
FerrumSec is located in Chișinău, Moldova. It operates as the security division of its parent company, Funway Interactive SRL.
You can book a penetration test or other engagement through FerrumSec's parent company at funwayinteractive.com/contact?service=pentest. This is FerrumSec's contact channel for engagements.
FerrumSec is built by people who write software for a living, backed by 25 years of software engineering and current, hands-on offensive security credentials. It follows three principles: Rust by default for memory safety, open source under the MIT license where it counts, and no dark patterns ever — no ads, no telemetry, no scareware, and no nag screens.
Yes. FerrumSec is the dedicated security division of Funway Interactive SRL, its parent company. Funway Interactive's website is funwayinteractive.com.
Or to follow the Ferrum Suite as it ships? We'd like to hear from you.