RMM

NetMaster

NetMaster is an open-source Windows remote-management project with a self-hosted PHP panel and a Windows service client. Its source implements command execution, screen sharing, file transfer/download, and RDP actions. No public malicious deployment was established in this source-focused review.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-09-28
Last modified
2026-09-28
Privileges
Administrator rights are required by the included installer to create and start the automatic Windows service.
Free / availability
Yes
Verification required
Static review of pinned upstream source; no local binary, panel, or sample execution was performed. The included Windows batch installer, client source, and PHP panel source establish the paths, service, and remote-management features below. No public malicious-use report was established in this review.
Supported platforms
Windows

Capabilities

Self-hosted PHP panel and Windows service clientCommand executionScreen sharingFile transfer and remote downloadRDP actions

Executables & installation paths

Filename
NetMaster_Client.exe
OriginalFileName
Not recorded
Description
Not recorded

Installation paths

C:\ProgramData\NetMaster\NetMaster_Client.exe
C:\ProgramData\NetMaster\config.ini

FORENSIC EVIDENCE

Disk artifacts

File
C:\ProgramData\NetMaster\NetMaster_Client.exe
Description
Client binary copied by the included installer and registered as the netmaster service executable.
OS
Windows
File
C:\ProgramData\NetMaster\config.ini
Description
Client configuration containing the operator-selected panel URL and polling interval.
OS
Windows
File
C:\ProgramData\NetMaster\log.txt
Description
Client log file path set by NetMaster_Client Log.cpp.
OS
Windows

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System
ServiceName
netmaster
ImagePath
C:\ProgramData\NetMaster\NetMaster_Client.exe
Description
Installation of the automatic netmaster service by the included installer.

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SYSTEM\CurrentControlSet\Services\netmaster
Description
Service Control Manager key created by the included installer.

FORENSIC EVIDENCE

Network artifacts

Description
Client panel URL is set in config.ini by the operator; no vendor domain or fixed port is inherent to NetMaster.
Domains
Not recorded
Ports
Not recorded

FORENSIC EVIDENCE

Other artifacts

Type
ServiceName
Value
netmaster
Type
PanelRegistrationEndpointSuffix
Value
userinit.php
Type
PanelPollingEndpointSuffix
Value
userupdate.php
Type
ConfigurationField
Value
url

References