P-BitM coordinates authorized browser-based assessment campaigns from a local
administrative control plane. Each campaign receives an isolated public
service, and each active target receives a dedicated browser container.
- A Vue administrative dashboard.
- Campaign, target, template, SMTP, landing-page, plugin, and module libraries.
- Scheduled Complete and immediate Standalone campaign lifecycle management.
- Isolated VNC or Selkies browser sessions.
- Event, keylog, screenshot, file, and module-result views.
- Campaign metadata dumps and per-session artifact and browser-profile exports.
- A CLI for setup, diagnostics, lifecycle operations, and local administration.
Trust boundary
The dashboard and admin backend are the trusted control plane. Campaign
services are isolated workloads exposed through Traefik. Browser containers
communicate with their campaign service and are managed by the admin backend
through a restricted Docker socket proxy.
P-BitM is designed for a single trusted host. It is not a multi-tenant hosted
service and should not be exposed as an unattended public control plane.
Next step
Read the requirements, then follow
installation. Last modified on August 28, 2026