{
  "Name": "NetMaster",
  "Category": "RMM",
  "Description": "NetMaster is an open-source Windows remote-management project with a self-hosted PHP panel and a Windows service client. Its source implements command execution, screen sharing, file transfer/download, and RDP actions. No public malicious deployment was established in this source-focused review.\n",
  "Author": "Michael Haag",
  "Created": "2026-09-28",
  "LastModified": "2026-09-28",
  "Details": {
    "Website": "https://github.com/f3di006/NetMaster",
    "PEMetadata": {
      "Filename": "NetMaster_Client.exe",
      "OriginalFileName": "",
      "Description": ""
    },
    "Privileges": "Administrator rights are required by the included installer to create and start the automatic Windows service.",
    "Free": true,
    "Verification": "Static review of pinned upstream source; no local binary, panel, or sample execution was performed. The included Windows batch installer, client source, and PHP panel source establish the paths, service, and remote-management features below. No public malicious-use report was established in this review.\n",
    "SupportedOS": [
      "Windows"
    ],
    "Capabilities": [
      "Self-hosted PHP panel and Windows service client",
      "Command execution",
      "Screen sharing",
      "File transfer and remote download",
      "RDP actions"
    ],
    "Vulnerabilities": [],
    "InstallationPaths": [
      "C:\\ProgramData\\NetMaster\\NetMaster_Client.exe",
      "C:\\ProgramData\\NetMaster\\config.ini"
    ]
  },
  "Artifacts": {
    "Disk": [
      {
        "File": "C:\\ProgramData\\NetMaster\\NetMaster_Client.exe",
        "Description": "Client binary copied by the included installer and registered as the netmaster service executable.",
        "OS": "Windows"
      },
      {
        "File": "C:\\ProgramData\\NetMaster\\config.ini",
        "Description": "Client configuration containing the operator-selected panel URL and polling interval.",
        "OS": "Windows"
      },
      {
        "File": "C:\\ProgramData\\NetMaster\\log.txt",
        "Description": "Client log file path set by NetMaster_Client Log.cpp.",
        "OS": "Windows"
      }
    ],
    "EventLog": [
      {
        "EventID": 7045,
        "ProviderName": "Service Control Manager",
        "LogFile": "System",
        "ServiceName": "netmaster",
        "ImagePath": "C:\\ProgramData\\NetMaster\\NetMaster_Client.exe",
        "Description": "Installation of the automatic netmaster service by the included installer."
      }
    ],
    "Registry": [
      {
        "Path": "HKLM\\SYSTEM\\CurrentControlSet\\Services\\netmaster",
        "Description": "Service Control Manager key created by the included installer."
      }
    ],
    "Network": [
      {
        "Description": "Client panel URL is set in config.ini by the operator; no vendor domain or fixed port is inherent to NetMaster.",
        "Domains": [],
        "Ports": []
      }
    ],
    "Other": [
      {
        "Type": "ServiceName",
        "Value": "netmaster"
      },
      {
        "Type": "PanelRegistrationEndpointSuffix",
        "Value": "userinit.php"
      },
      {
        "Type": "PanelPollingEndpointSuffix",
        "Value": "userupdate.php"
      },
      {
        "Type": "ConfigurationField",
        "Value": "url"
      }
    ]
  },
  "Detections": [],
  "References": [
    "https://github.com/f3di006/NetMaster/blob/b5dca5f2f11d8a76cda25122e82eb44cdcb07725/README.md",
    "https://github.com/f3di006/NetMaster/blob/b5dca5f2f11d8a76cda25122e82eb44cdcb07725/ClientInstaller/installer.bat",
    "https://github.com/f3di006/NetMaster/blob/b5dca5f2f11d8a76cda25122e82eb44cdcb07725/NetMaster_Client/Core.cpp",
    "https://github.com/f3di006/NetMaster/blob/b5dca5f2f11d8a76cda25122e82eb44cdcb07725/NetMaster_Client/Command.cpp",
    "https://github.com/f3di006/NetMaster/blob/b5dca5f2f11d8a76cda25122e82eb44cdcb07725/NetMaster_Client/Log.cpp"
  ],
  "Acknowledgement": []
}