TopNet247Independent notes for Windows admins

Triage drawer · Server & Workstation Triage

Server and workstation triage tools for machines you administer

On the ticket: “What is this machine doing right now, and why?”

Triage is the first fifteen minutes after a ticket lands: a file server that has stopped answering SMB, a workstation with the fan at full speed, an application server where a service will not start after patching. The goal is not a root-cause report yet; it is to find out what the machine is doing, stop the bleeding if you can, and gather enough evidence that the fix sticks. The tools in this drawer are the ones Windows admins reach for in that window — some local and deep, some remote and quick.

Every tool here is judged on the same three questions we ask across the site. What chore does it remove — opening an RDP session to kill one process, or hunting for an autostart entry by hand? What rights does it need on the target, and does it need anything opened in the firewall? And what does it leave behind: a temporary service, a PowerShell transcript, nothing at all? That last question matters more than it looks. A triage action that nobody can reconstruct later is a problem for the next admin and for any incident review. The ordering and weightings are on our methodology page.

6 server and workstation triage tools side by side

Ordered from the tools that answer “what is this process doing?” to the ones that answer “is the network the problem?”. RSAT sits last because its triage use is indirect — DNS, DHCP and AD consoles for checking the dependencies of a sick machine. Click a tool name for the desk review; “Visit” links lead to the maker’s own website.

ToolLicencePlatformsKey featureBest forRights it needs
Sysinternals SuiteMicrosoftFreewareWindows client and Windows Server; ARM64 and Nano Server builds; also in the Microsoft StoreAround seventy utilities — Process Explorer, Process Monitor, Autoruns, PsTools, TCPView, SysmonAdmins who need to see exactly what a process, service or logon is doingMost tools want an elevated prompt; PsExec needs admin rights on the remote host
LizardSystems Remote Process ExplorerLizardSystemsPersonal free / paidWindows 10/11, Windows Server 2012 R2–2025Process tree for remote machines with nothing installed on them; end, start and re-prioritise processesHelp-desk and server admins ending hung processes without opening a remote sessionLocal administrator on the target computer; WMI/RPC allowed through its firewall
Windows Admin CenterMicrosoftWith Windows licenceBrowser-based; gateway on Windows Server 2016–2025 or local client on Windows 11Browser console for services, events, processes, updates, roles and storage over PowerShell remotingSmall teams replacing a pile of MMC snap-ins and RDP-to-the-server habitsGateway access plus admin rights on each managed server via WinRM / PowerShell remoting
Angry IP ScannerAnton KeksGPLv2Windows, macOS, LinuxFast ping and port sweep of an address range with CSV/XML exportChecking which hosts in a server VLAN answer before and after a changeRuns as a normal user; no rights on the targets
WiresharkWireshark FoundationGPLv2Windows, macOS, LinuxProtocol decoding for Kerberos, LDAP, SMB, DNS and RDP handshakes on your own segmentProving what really crosses the wire when logs and users disagreeCapture privileges on the machine you capture from (Npcap on Windows)
Remote Server Administration Tools (RSAT)MicrosoftWith Windows licenceWindows 10 (Oct 2018 update or later) and Windows 11 Pro/Enterprise; Windows ServerActive Directory Users and Computers, Group Policy Management, DNS, DHCP consoles and the ActiveDirectory PowerShell moduleEvery Windows admin workstation — the baseline other AD tools are measured againstGrants nothing itself — you get exactly what your AD account is delegated

Written independently: TopNet247 is none of these vendors, and table position cannot be bought. We verified licence and platform details on each maker’s website as of the date shown above.

How to choose

Desk note

Why a packet analyser and a range scanner are in this drawer

Many “server problems” turn out to be network problems wearing a disguise: a DNS record pointing at a decommissioned address, a firewall rule dropping Kerberos, a duplicate IP after a VM was cloned. Angry IP Scanner answers the quick question — which of my servers answer on which ports after the change window — and Wireshark, run on your own admin host or the affected server, shows whether the logon is stalling on DNS, Kerberos or SMB. Both are open source and free. Keep both on machines and segments you administer, and treat capture files as sensitive: they can contain names, hosts and share paths. As always, get each tool from its official site — our where-to-get page lists them.

Vendor pages: Sysinternals Suite learn.microsoft.com · LizardSystems Remote Process Explorer lizardsystems.com · Windows Admin Center learn.microsoft.com · Angry IP Scanner angryip.org · Wireshark wireshark.org · Remote Server Administration Tools (RSAT) learn.microsoft.com

Questions admins ask about server and workstation triage tools

How do I end a process on a remote workstation without RDP?

From an admin prompt, taskkill /S HOSTNAME /PID 1234 /F ends a process over RPC, and tasklist /S HOSTNAME lists them first. In PowerShell, Invoke-Command -ComputerName HOSTNAME { Stop-Process -Id 1234 -Force } uses WinRM instead. Remote Process Explorer and Windows Admin Center wrap the same idea in a GUI. Our how-to covers the full routine.

Is Sysinternals Suite safe to use on production servers?

It is published by Microsoft and widely used on production systems. Most tools only read state. The ones that change things — PsExec, PsKill, PsService, Autoruns when you untick an entry — deserve the same care as any admin action. Get it from Microsoft’s own site and check the digital signature.

Does Windows Admin Center need an agent on each server?

No. It connects to managed machines over WinRM and PowerShell remoting from a gateway you install. The managed servers need WinRM enabled and reachable from the gateway, and your account needs admin rights on them.

When should I use Wireshark instead of logs?

When logs disagree or say nothing. A slow logon, an intermittent share disconnect or a certificate error during a TLS handshake is often faster to understand from a short capture than from event logs on three different machines. Capture only on segments and hosts you administer.

What rights do remote triage tools need?

Typically local administrator on the target, plus firewall rules that allow WMI/RPC or WinRM from your admin hosts. Use a separate admin account for this work, not your everyday account, and prefer tools that do not need to install anything on the target.

Keep going

Other drawers

Money note: every vendor link here is a direct, commission-free link to that maker’s official site. Details in our affiliate disclosure.