Two admins at the same company can do remote process triage very differently. One keeps a window open with a tree of the forty PCs on the accounts floor, clicks into whichever one the helpdesk mentions, sorts by CPU and ends the runaway process with a right-click. The other types pslist \\PC-0421, reads the columns, and follows up with pskill. If something is really odd, they run Process Explorer or ProcDump on the machine for a closer look. The first way is LizardSystems Remote Process Explorer. The second is Microsoft’s Sysinternals Suite. Both work. They suit different people and different network rules.
Use only on systems you administer and with your organisation’s authorization. Ending a process discards the user’s unsaved work in it.
At a glance
| Remote Process Explorer | Sysinternals Suite | |
|---|---|---|
| Publisher | LizardSystems | Microsoft (Mark Russinovich) |
| Form | One Windows GUI app, many remote computers | ~70 separate utilities, CLI and GUI |
| Cost (at time of writing) | Free for personal, non-commercial use; Business US$149.95 per machine; Corporate US$2,999.95 | Free |
| Current release | v25.05 (May 2025) | Suite updated September 2026 |
| Supported OS (vendor list) | Windows 10/11, Server 2012 R2–2025 | PsTools: Windows 8.1+/Server 2012+; latest Process Explorer: Windows 11/Server 2019+ |
| Remote process list | Yes, live, several computers side by side | PsList \\computer (performance counters) |
| End a remote process | Yes | PsKill \\computer (-t for the tree) |
| Start a process remotely | Yes | PsExec |
| Change priority remotely | Yes | Not in PsList/PsKill; run a tool on the target |
| Handles, DLLs, dumps, boot-time autostarts | No | Process Explorer, Handle, ListDLLs, ProcDump, Autoruns (run on the target) |
| Shut down / restart target | Yes | PsShutdown |
| Transport | WMI over DCOM (TCP 135, 137–139, >1024) | Admin share over SMB 445 (PsExec, PsKill), performance counters (PsList) |
| Rights | Admin on each target; per-computer alternate credentials | Admin on each target; -u/-p switches |
| Export | Process info to file | Text output you can redirect or pipe |
Check both vendors’ pages for current versions and licence terms before you roll anything out.
The real differences
Breadth versus depth
Remote Process Explorer does one job across many machines. It shows the process list and tree with PID, CPU, memory, priority, handle count and thread count, lets you end, start or reprioritise processes, and can restart the box. Adding a computer is a one-time step, after which you just click back to it. For a helpdesk that deals with frozen apps several times a day, that saves real time.
Sysinternals goes deeper on a single machine. Remotely, PsList and PsKill cover “what’s running” and “end it”, but the tools that explain why something hung only run locally. That means Process Explorer’s handle and DLL views, ProcDump’s hang dumps and Process Monitor’s file and registry trace. You run them through PsExec, an interactive remote session, or by walking to the desk. Microsoft’s current Process Explorer build also lists Windows 11 and Server 2019 as its minimum, which may rule it out for older kit that Remote Process Explorer still supports.
Which firewall holes you already have
This is often the deciding factor. Remote Process Explorer uses WMI over DCOM. Its FAQ lists TCP 135, UDP 137–138, TCP 139 and high TCP ports for RPC. Many hardened workstation baselines block inbound DCOM from anywhere except an admin subnet, and some block it completely. PsKill and PsExec work over the admin share on TCP 445, which is also frequently restricted, and security tools often flag PsExec’s service-based remote execution. Before you choose, test both against a locked-down PC from your admin workstation. Choose the tool whose path your security team is willing to keep open.
Rights and audit trail
Both need local admin on the target, and neither needs an agent installed in advance. Both authenticate with your account, or with alternate credentials you supply: per computer in Remote Process Explorer, -u in the Ps tools. So the target’s Security log shows your network logon either way. PsExec also briefly installs a service on the target, which leaves System log entries. That’s useful for auditing, and it’s also something your EDR may alert on.
Cost and licensing
Sysinternals costs nothing and is licensed by Microsoft. Remote Process Explorer is free only for personal, non-commercial use. Using it at work needs a Business licence per machine it’s installed on, meaning your admin workstations, not the targets. The Corporate licence covers the whole organisation. For a two-tech helpdesk that’s two Business licences, a modest amount next to the time a GUI saves if the task comes up daily.
Pick Remote Process Explorer if…
- Remote “it’s frozen” tickets are a daily chore, and the people handling them prefer a GUI to a prompt.
- You want one window with several machines’ processes and an easy way to end, start or reprioritise.
- DCOM/WMI from your admin subnet to workstations is already allowed.
- You also need to restart the machine from the same place.
Pick Sysinternals if…
- You’re comfortable at the command line and want to script it: PsList output into a log, PsKill in a runbook.
- You need root-cause depth (handles, DLLs, hang dumps, autostarts), not just “end it”.
- Budget is zero, or your policy favours Microsoft-signed tools.
- SMB 445 from your admin hosts is allowed but DCOM isn’t.
Many admins keep both. Sysinternals goes on every admin’s USB stick or tools share. Remote Process Explorer goes on the helpdesk consoles that handle most “it’s frozen” calls.
Where to go next
Full reviews: Remote Process Explorer and Sysinternals Suite. The command-line walk-through, including taskkill and CIM, is in find and end a hung process on a domain workstation. Related tools, including Windows Admin Center’s Processes tool, are listed in Server & Workstation Triage. See where to get for how to obtain each tool from its publisher and verify the signature.