Triage drawer · Server & Workstation Triage
Server and workstation triage tools for machines you administer
On the ticket: “What is this machine doing right now, and why?”
Triage is the first fifteen minutes after a ticket lands: a file server that has stopped answering SMB, a workstation with the fan at full speed, an application server where a service will not start after patching. The goal is not a root-cause report yet; it is to find out what the machine is doing, stop the bleeding if you can, and gather enough evidence that the fix sticks. The tools in this drawer are the ones Windows admins reach for in that window — some local and deep, some remote and quick.
Every tool here is judged on the same three questions we ask across the site. What chore does it remove — opening an RDP session to kill one process, or hunting for an autostart entry by hand? What rights does it need on the target, and does it need anything opened in the firewall? And what does it leave behind: a temporary service, a PowerShell transcript, nothing at all? That last question matters more than it looks. A triage action that nobody can reconstruct later is a problem for the next admin and for any incident review. The ordering and weightings are on our methodology page.
6 server and workstation triage tools side by side
Ordered from the tools that answer “what is this process doing?” to the ones that answer “is the network the problem?”. RSAT sits last because its triage use is indirect — DNS, DHCP and AD consoles for checking the dependencies of a sick machine. Click a tool name for the desk review; “Visit” links lead to the maker’s own website.
| Tool | Licence | Platforms | Key feature | Best for | Rights it needs |
|---|---|---|---|---|---|
| Sysinternals SuiteMicrosoft | Freeware | Windows client and Windows Server; ARM64 and Nano Server builds; also in the Microsoft Store | Around seventy utilities — Process Explorer, Process Monitor, Autoruns, PsTools, TCPView, Sysmon | Admins who need to see exactly what a process, service or logon is doing | Most tools want an elevated prompt; PsExec needs admin rights on the remote host |
| LizardSystems Remote Process ExplorerLizardSystems | Personal free / paid | Windows 10/11, Windows Server 2012 R2–2025 | Process tree for remote machines with nothing installed on them; end, start and re-prioritise processes | Help-desk and server admins ending hung processes without opening a remote session | Local administrator on the target computer; WMI/RPC allowed through its firewall |
| Windows Admin CenterMicrosoft | With Windows licence | Browser-based; gateway on Windows Server 2016–2025 or local client on Windows 11 | Browser console for services, events, processes, updates, roles and storage over PowerShell remoting | Small teams replacing a pile of MMC snap-ins and RDP-to-the-server habits | Gateway access plus admin rights on each managed server via WinRM / PowerShell remoting |
| Angry IP ScannerAnton Keks | GPLv2 | Windows, macOS, Linux | Fast ping and port sweep of an address range with CSV/XML export | Checking which hosts in a server VLAN answer before and after a change | Runs as a normal user; no rights on the targets |
| WiresharkWireshark Foundation | GPLv2 | Windows, macOS, Linux | Protocol decoding for Kerberos, LDAP, SMB, DNS and RDP handshakes on your own segment | Proving what really crosses the wire when logs and users disagree | Capture privileges on the machine you capture from (Npcap on Windows) |
| Remote Server Administration Tools (RSAT)Microsoft | With Windows licence | Windows 10 (Oct 2018 update or later) and Windows 11 Pro/Enterprise; Windows Server | Active Directory Users and Computers, Group Policy Management, DNS, DHCP consoles and the ActiveDirectory PowerShell module | Every Windows admin workstation — the baseline other AD tools are measured against | Grants nothing itself — you get exactly what your AD account is delegated |
Written independently: TopNet247 is none of these vendors, and table position cannot be bought. We verified licence and platform details on each maker’s website as of the date shown above.
How to choose
- Decide whether you can touch the user’s session
Opening RDP to a workstation to end one process interrupts the person using it. Remote process tools and Windows Admin Center work over WMI or PowerShell remoting instead, so the user keeps their session. Pick tools that let you act without taking over the screen.
- Check the transport before the tool
Remote process and service tools rely on WMI/DCOM, RPC or WinRM. If Windows Firewall blocks Remote Administration or WinRM on the target, no tool will help. Standardise the firewall rules by GPO for your admin subnet so triage works the day you need it.
- Use local deep tools when remote views run out
A remote process list shows names, PIDs and memory. When you need to know which DLL is loaded, which handle is holding a file, or which registry key a service reads on start, Process Explorer and Process Monitor run on the machine itself and see far more.
- Know what each action leaves behind
PsExec creates a service on the target, and security teams often alert on it. Windows Admin Center runs PowerShell that script-block logging can capture. Ending a process leaves an event only if process tracking is audited. Choose actions your security team will recognise, and note them in the ticket.
- Capture evidence before you restart
Restarting a service or rebooting clears the state you were trying to understand. Save the process list, a ProcDump of the hung process, or a short packet capture first. Two minutes of evidence often saves a second outage.
Why a packet analyser and a range scanner are in this drawer
Many “server problems” turn out to be network problems wearing a disguise: a DNS record pointing at a decommissioned address, a firewall rule dropping Kerberos, a duplicate IP after a VM was cloned. Angry IP Scanner answers the quick question — which of my servers answer on which ports after the change window — and Wireshark, run on your own admin host or the affected server, shows whether the logon is stalling on DNS, Kerberos or SMB. Both are open source and free. Keep both on machines and segments you administer, and treat capture files as sensitive: they can contain names, hosts and share paths. As always, get each tool from its official site — our where-to-get page lists them.
Vendor pages: Sysinternals Suite learn.microsoft.com · LizardSystems Remote Process Explorer lizardsystems.com · Windows Admin Center learn.microsoft.com · Angry IP Scanner angryip.org · Wireshark wireshark.org · Remote Server Administration Tools (RSAT) learn.microsoft.com
Questions admins ask about server and workstation triage tools
How do I end a process on a remote workstation without RDP?
From an admin prompt, taskkill /S HOSTNAME /PID 1234 /F ends a process over RPC, and tasklist /S HOSTNAME lists them first. In PowerShell, Invoke-Command -ComputerName HOSTNAME { Stop-Process -Id 1234 -Force } uses WinRM instead. Remote Process Explorer and Windows Admin Center wrap the same idea in a GUI. Our how-to covers the full routine.
Is Sysinternals Suite safe to use on production servers?
It is published by Microsoft and widely used on production systems. Most tools only read state. The ones that change things — PsExec, PsKill, PsService, Autoruns when you untick an entry — deserve the same care as any admin action. Get it from Microsoft’s own site and check the digital signature.
Does Windows Admin Center need an agent on each server?
No. It connects to managed machines over WinRM and PowerShell remoting from a gateway you install. The managed servers need WinRM enabled and reachable from the gateway, and your account needs admin rights on them.
When should I use Wireshark instead of logs?
When logs disagree or say nothing. A slow logon, an intermittent share disconnect or a certificate error during a TLS handshake is often faster to understand from a short capture than from event logs on three different machines. Capture only on segments and hosts you administer.
What rights do remote triage tools need?
Typically local administrator on the target, plus firewall rules that allow WMI/RPC or WinRM from your admin hosts. Use a separate admin account for this work, not your everyday account, and prefer tools that do not need to install anything on the target.
Keep going
Money note: every vendor link here is a direct, commission-free link to that maker’s official site. Details in our affiliate disclosure.