Install a preview
Choose your platform on the download page and compare the package’s SHA-256 checksum before opening it. These evaluation packages include the desktop, YARA-enabled service, and CLI. They have no publisher certificate; macOS builds are not notarized. The signature database contains examples, so keep your current antivirus while evaluating.
Windows: run the x64 setup as your normal user. The installer handles the WebView2 prerequisite. macOS: choose Apple silicon or Intel, open the DMG, and copy FerXium.app to Applications. Gatekeeper may block this unsigned publisher preview.
Linux: on Ubuntu 24.04 or newer, install the downloaded Debian package:
sudo apt install ./FerXium-0.1.0-linux-x86_64.debOpen FerXium from your application menu as your regular user. The desktop starts its bundled service automatically. Closing the desktop leaves monitoring active. Stop ferxium-service before updating or uninstalling; startup at login is optional and requires the per-user templates supplied in the repository.
Build from source
Install current stable Rust and Node.js 22.12 or newer. Obtain the source, open its root folder, then install the frontend packages and build the service.
Download the complete source ZIP and its SHA-256 checksum, then extract the archive.
npm ci
cargo build --release -p ferxium-service -p ferxium-cli
npm run build
npm run tauri -- buildThe default Rust engine includes hashes and heuristics. Enable native YARA with --features yara-engine for the service and CLI. See the repository build guide for native dependencies.
Windows
Install Visual Studio Build Tools with the Desktop development with C++ workload, the Windows SDK, and the WebView2 runtime. Run the service as your regular Windows user. Installer signing is a release step, not a requirement for local builds.
macOS
Install Xcode Command Line Tools with xcode-select --install. macOS may ask for access to protected folders you select. Full Disk Access is optional and broadens file access; grant it only when you need that coverage.
Linux
On Debian/Ubuntu, install the desktop dependencies before building Tauri:
sudo apt-get install build-essential pkg-config libwebkit2gtk-4.1-dev \
libgtk-3-dev libayatana-appindicator3-dev librsvg2-dev libssl-devNative YARA builds also need C build tools; see the repository guide. File watching is subject to inotify limits and filesystem support.
Run the protection service
For development, start the service in one terminal, then launch the desktop app in another. The desktop bridge discovers a private, authenticated loopback endpoint. There is no remote service or cloud account.
cargo run -p ferxium-service
# In a second terminal:
npm run tauri -- devThe desktop app never starts an elevated daemon. Per-user startup templates are included in the repository for systemd, launchd, and Windows Task Scheduler.
Your first scan
Open Scans and choose Quick, Full, or Custom. Review file counts, skips, read errors, and potential detections. A clean result applies only to the files actually checked with the current signatures.
For a headless check:
cargo run -p ferxium-cli -- scan /absolute/path/to/folder
cargo run -p ferxium-cli -- statusThe scan command exits with 0 for no detections, 1 for detections, and 2 for read errors. Quarantine and restore are explicit desktop actions. Restoration never overwrites an existing destination.
Coverage & permissions
The service runs with your user’s file permissions. It watches selected roots and samples running executable paths. It observes file changes after they happen and provides local network traffic counters.
Memory scanning, archive unpacking, privileged execution blocking, comprehensive connection attribution, and a production signature corpus are future work. Interrupted quarantine staging and watcher queue overflows are reported for review. The preview has not undergone an independent security audit.
Contribute something useful
Start with the repository’s contribution guide and roadmap. Reproduce issues using harmless fixtures. Do not upload live malware to public issues. Security-sensitive findings belong in the private advisory workflow configured by the project maintainer.
cargo fmt --all --check
cargo clippy --all-targets -- -D warnings
cargo test
npm run check
npm run buildRead our philosophy