TopNet247Independent notes for Windows admins

Side by side

Remote Process Explorer vs Sysinternals for remote process triage

A GUI console for processes on many domain PCs against Microsoft's free Sysinternals command-line and local tools: transport, rights, cost and depth.

TopNet247 wrote this comparison independently. We are not LizardSystems or Microsoft, and no vendor reviewed or paid for this page.

Two admins at the same company can do remote process triage very differently. One keeps a window open with a tree of the forty PCs on the accounts floor, clicks into whichever one the helpdesk mentions, sorts by CPU and ends the runaway process with a right-click. The other types pslist \\PC-0421, reads the columns, and follows up with pskill. If something is really odd, they run Process Explorer or ProcDump on the machine for a closer look. The first way is LizardSystems Remote Process Explorer. The second is Microsoft’s Sysinternals Suite. Both work. They suit different people and different network rules.

Use only on systems you administer and with your organisation’s authorization. Ending a process discards the user’s unsaved work in it.

At a glance

Remote Process Explorer Sysinternals Suite
Publisher LizardSystems Microsoft (Mark Russinovich)
Form One Windows GUI app, many remote computers ~70 separate utilities, CLI and GUI
Cost (at time of writing) Free for personal, non-commercial use; Business US$149.95 per machine; Corporate US$2,999.95 Free
Current release v25.05 (May 2025) Suite updated September 2026
Supported OS (vendor list) Windows 10/11, Server 2012 R2–2025 PsTools: Windows 8.1+/Server 2012+; latest Process Explorer: Windows 11/Server 2019+
Remote process list Yes, live, several computers side by side PsList \\computer (performance counters)
End a remote process Yes PsKill \\computer (-t for the tree)
Start a process remotely Yes PsExec
Change priority remotely Yes Not in PsList/PsKill; run a tool on the target
Handles, DLLs, dumps, boot-time autostarts No Process Explorer, Handle, ListDLLs, ProcDump, Autoruns (run on the target)
Shut down / restart target Yes PsShutdown
Transport WMI over DCOM (TCP 135, 137–139, >1024) Admin share over SMB 445 (PsExec, PsKill), performance counters (PsList)
Rights Admin on each target; per-computer alternate credentials Admin on each target; -u/-p switches
Export Process info to file Text output you can redirect or pipe

Check both vendors’ pages for current versions and licence terms before you roll anything out.

The real differences

Breadth versus depth

Remote Process Explorer does one job across many machines. It shows the process list and tree with PID, CPU, memory, priority, handle count and thread count, lets you end, start or reprioritise processes, and can restart the box. Adding a computer is a one-time step, after which you just click back to it. For a helpdesk that deals with frozen apps several times a day, that saves real time.

Sysinternals goes deeper on a single machine. Remotely, PsList and PsKill cover “what’s running” and “end it”, but the tools that explain why something hung only run locally. That means Process Explorer’s handle and DLL views, ProcDump’s hang dumps and Process Monitor’s file and registry trace. You run them through PsExec, an interactive remote session, or by walking to the desk. Microsoft’s current Process Explorer build also lists Windows 11 and Server 2019 as its minimum, which may rule it out for older kit that Remote Process Explorer still supports.

Which firewall holes you already have

This is often the deciding factor. Remote Process Explorer uses WMI over DCOM. Its FAQ lists TCP 135, UDP 137–138, TCP 139 and high TCP ports for RPC. Many hardened workstation baselines block inbound DCOM from anywhere except an admin subnet, and some block it completely. PsKill and PsExec work over the admin share on TCP 445, which is also frequently restricted, and security tools often flag PsExec’s service-based remote execution. Before you choose, test both against a locked-down PC from your admin workstation. Choose the tool whose path your security team is willing to keep open.

Rights and audit trail

Both need local admin on the target, and neither needs an agent installed in advance. Both authenticate with your account, or with alternate credentials you supply: per computer in Remote Process Explorer, -u in the Ps tools. So the target’s Security log shows your network logon either way. PsExec also briefly installs a service on the target, which leaves System log entries. That’s useful for auditing, and it’s also something your EDR may alert on.

Cost and licensing

Sysinternals costs nothing and is licensed by Microsoft. Remote Process Explorer is free only for personal, non-commercial use. Using it at work needs a Business licence per machine it’s installed on, meaning your admin workstations, not the targets. The Corporate licence covers the whole organisation. For a two-tech helpdesk that’s two Business licences, a modest amount next to the time a GUI saves if the task comes up daily.

Pick Remote Process Explorer if…

Pick Sysinternals if…

Many admins keep both. Sysinternals goes on every admin’s USB stick or tools share. Remote Process Explorer goes on the helpdesk consoles that handle most “it’s frozen” calls.

Where to go next

Full reviews: Remote Process Explorer and Sysinternals Suite. The command-line walk-through, including taskkill and CIM, is in find and end a hung process on a domain workstation. Related tools, including Windows Admin Center’s Processes tool, are listed in Server & Workstation Triage. See where to get for how to obtain each tool from its publisher and verify the signature.

Full reviews

See the wider field in server & workstation triage.