Dashboard
Connected Clients
| # | User@PC | IP | OS | AV | Country | Tag | Runtime | Loader ID | Bkup C2 | Actions |
|---|
Clients
π Push new C2 / domain (all or selected clients)
Admin only. Sends a live update: clients apply the new host list (with ports), then disconnect and reconnect. Same format as the builder: primary + up to 2 backups.
| # | Nickname | User@PC | IP | OS | Account | Country | AV | Tag | Loader ID | Bkup C2 | Heal | RT | Connected | Actions |
|---|
Client Builder
Panel build: Native C++
β Windows PE, no .NET on the target machine.
|
.NET managed
β project DebugBot.Client (net48 / WinForms); requires .NET Framework 4.8 installed on the PC.
Zero-Click Exploits with the loader for client.
π§ Basic Settings
π Connection Settings
Primary C2 address plus up to two backups. The client rotates on reconnect if a host is down. Use host and port (default 4782). IPv6: [::1] in host, port separately.
π¦ Build Mode
π¦ Installation Settings
π‘οΈ Anti Methods
π Encryption & Obfuscation
π Injection & Loader
π‘οΈ Evasion Techniques
π Monitoring
π Assembly Information
π€ Output
π Mutex Database
All mutexes from client builds are saved here. Click a mutex to load it into the builder.
| Mutex | Tag | Profile | Hosts | Build Date | Builds | Actions |
|---|
π΄ Offline Clients
Previously connected clients that are now offline.
| Nickname | User@PC | IP | OS | Antivirus | Country | Tag | Account | First Seen | Last Seen | Actions |
|---|
π Statistics
π₯οΈ OS Distribution
| Operating System | Count | % |
|---|
π Country Distribution (Map)
| Country | Count | % |
|---|
π€ Account Type
| Account Type | Count | % |
|---|
π·οΈ Tag Distribution
| Tag | Count | % |
|---|
π° Crypto Clipper
Configure cryptocurrency address replacements. When a client detects a crypto address in the clipboard, it will be swapped with yours.
π€ Auto Tasks
Define tasks that execute automatically when a client connects.
Configured Tasks
| Title | Type | Mode | Parameters | Actions |
|---|
π Notifications
| Time | Client | Event | Details |
|---|
Server Settings
π Server certificate (PFX)
PFX is the most convenient, fully local format: one file with certificate and private key. No hardware token or cloud required. Used for TLS and client build signing. Restart server for certificate change to take effect.
π Panel HTTPS (loader downloads)
Recovery loader uses URLDownloadToFile on https:// ticket URLs. Enable a TLS listener (same PFX) on port 443 so clients can fetch the main EXE without a custom port. Changing these options requires a full process restart (not only βRestart serverβ).
Separate multiple bases with ; or new lines. Loader / heal builds embed the same ticket on every base so downloads work when any domain reaches this server.
Download tickets are signed with DebugStuff/download-ticket-secret.bin. Rotating the secret invalidates every existing ticket URL immediately.
πΎ Client data / downloads
Applies to Clients/*/Downloads on this machine. Set 0 to disable a limit.
π§ Native builder β block algorithms & optional controls
Block algorithms you no longer want (burned by AV / outdated). The builder droplist hides them; the server also rejects a build that still uses a blocked value. If every option in a group is blocked, you must un-block at least one before saving.
Hide optional βEncryption & obfuscationβ controls (checkboxes and obfuscation level) on the Builder tab (operators only see a simpler list).
Audit logs
Tail export of security-audit.log and download-audit.log (DebugStuff). Panel file pulls are logged as panel_file_pull. Default max 256 KB per file.
π Code signing (SmartScreen / EV)
MS SmartScreen trusts signed EXEs. Use an EV or standard code signing PFX; each build will be signed after compile. On Linux the server uses osslsigncode (install it for PFX signing). EV certs on hardware tokens usually require signing on Windows with signtool.
π± Telegram Notifications
π Notification Keywords
Keywords to monitor for in client activity. One per line.
π Account Security
Two-factor (2FA)
Option A: time-based code from an app (Google Authenticator, Aegis, etc.). Option B: one-time recovery codes if you lose the phone.
Loadingβ¦
π« Blocked IPs
Connections from blocked IPs will be automatically rejected and uninstalled.
| Blocked IP | Actions |
|---|
π Security
Manage panel accounts (admin vs support), lockout ban policy, and view recent security-audit lines. Login attempts are logged to security-audit.log.
Panel users
| Username | Role | Actions |
|---|
Failed-login lockout
After repeated failed panel logins, the IP is temporarily locked out. Optionally add that IP to the global blocklist (same list as C2 blocked IPs).
Security audit (tail)
β
Event Log
π₯ Downloads
Built Clients
0| File | PE runtime | Size | Date | Actions |
|---|---|---|---|---|
| Click Refresh to load | ||||
π» Client Data
| Type | Name | Size | Date | Actions |
|---|---|---|---|---|
| Click Refresh to load | ||||
βΉοΈ About DebugBot
DebugBot is a remote administration tool designed for educational purposes and ethical security research.
| Version | 1.0.0 |
| Platform | Cross-platform (Web Panel) |
| Server | .NET 9.0 / ASP.NET Core |
| Client | Native C++ (Windows) |
β οΈ This software is intended for authorized testing and educational use only. Unauthorized access to computer systems is illegal.