RMM
NetMaster
NetMaster is an open-source Windows remote-management project with a self-hosted PHP panel and a Windows service client. Its source implements command execution, screen sharing, file transfer/download, and RDP actions. No public malicious deployment was established in this source-focused review.
Tool overview
- Category
- RMM
- Research authors
- Michael Haag
- Created
- 2026-09-28
- Last modified
- 2026-09-28
- Privileges
- Administrator rights are required by the included installer to create and start the automatic Windows service.
- Free / availability
- Yes
- Verification required
- Static review of pinned upstream source; no local binary, panel, or sample execution was performed. The included Windows batch installer, client source, and PHP panel source establish the paths, service, and remote-management features below. No public malicious-use report was established in this review.
- Supported platforms
Windows
Capabilities
Executables & installation paths
- Filename
- NetMaster_Client.exe
- OriginalFileName
- Not recorded
- Description
- Not recorded
Installation paths
C:\ProgramData\NetMaster\NetMaster_Client.exe
C:\ProgramData\NetMaster\config.ini
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\ProgramData\NetMaster\NetMaster_Client.exe
- Description
- Client binary copied by the included installer and registered as the netmaster service executable.
- OS
- Windows
- File
- C:\ProgramData\NetMaster\config.ini
- Description
- Client configuration containing the operator-selected panel URL and polling interval.
- OS
- Windows
- File
- C:\ProgramData\NetMaster\log.txt
- Description
- Client log file path set by NetMaster_Client Log.cpp.
- OS
- Windows
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System
- ServiceName
- netmaster
- ImagePath
- C:\ProgramData\NetMaster\NetMaster_Client.exe
- Description
- Installation of the automatic netmaster service by the included installer.
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKLM\SYSTEM\CurrentControlSet\Services\netmaster
- Description
- Service Control Manager key created by the included installer.
FORENSIC EVIDENCE
Network artifacts
- Description
- Client panel URL is set in config.ini by the operator; no vendor domain or fixed port is inherent to NetMaster.
- Domains
- Not recorded
- Ports
- Not recorded
FORENSIC EVIDENCE
Other artifacts
- Type
- ServiceName
- Value
- netmaster
- Type
- PanelRegistrationEndpointSuffix
- Value
- userinit.php
- Type
- PanelPollingEndpointSuffix
- Value
- userupdate.php
- Type
- ConfigurationField
- Value
- url
References
- https://github.com/f3di006/NetMaster/blob/b5dca5f2f11d8a76cda25122e82eb44cdcb07725/README.md
- https://github.com/f3di006/NetMaster/blob/b5dca5f2f11d8a76cda25122e82eb44cdcb07725/ClientInstaller/installer.bat
- https://github.com/f3di006/NetMaster/blob/b5dca5f2f11d8a76cda25122e82eb44cdcb07725/NetMaster_Client/Core.cpp
- https://github.com/f3di006/NetMaster/blob/b5dca5f2f11d8a76cda25122e82eb44cdcb07725/NetMaster_Client/Command.cpp
- https://github.com/f3di006/NetMaster/blob/b5dca5f2f11d8a76cda25122e82eb44cdcb07725/NetMaster_Client/Log.cpp