Card index
All 10 tools, filed by drawer
Each card lists the chore the tool removes, the rights it expects and what it leaves in the audit trail. Several tools work across drawers — Windows Admin Center and Sysinternals turn up in all three comparisons — so each tool is filed once, under its main job.
RDS & Session Management
The question on the ticket: “Who is on which session host, and who connected when?” Open the full comparison
RDSLizardSystems Terminal Services ManagerPersonal free / paid
- Chore
- Finding who is on which session host and clearing disconnected or stuck sessions
- Rights
- Administrative rights on the RDS hosts, with RPC reachable through their firewalls
- Trail
- Log-offs and disconnects are recorded by Windows in each host’s own session logs
- Chore
- Assembling RDP connection history from Security and TerminalServices event logs
- Rights
- Permission to read the event logs on each target (admin or Event Log Readers)
- Trail
- Read-only: it reports on logs Windows already keeps; retention depends on your log size settings
Active Directory Management & Auditing
The question on the ticket: “Who owns this account, who changed it, and is it still needed?” Open the full comparison
ADRemote Server Administration Tools (RSAT)With Windows licence
- Chore
- Running AD, Group Policy, DNS and DHCP consoles without an RDP session to a domain controller
- Rights
- Grants nothing itself — you get exactly what your AD account is delegated
- Trail
- Changes are logged on domain controllers if Directory Service Changes auditing (5136–5141) is on
- Chore
- Bulk user provisioning, stale-account cleanup and delegated password resets
- Rights
- A service account with the AD rights for the tasks you automate; technicians get scoped roles
- Trail
- Keeps its own audit log of technician actions, alongside the domain controllers’ event logs
- Chore
- Answering “who changed this group / GPO / file permission, and when” without trawling DC logs
- Rights
- A data-collection account with read access to logs and configuration; audit policy set on DCs
- Trail
- It is the trail: collects and archives change and logon records for reports and alerts
Server & Workstation Triage
The question on the ticket: “What is this machine doing right now, and why?” Open the full comparison
TriageLizardSystems Remote Process ExplorerPersonal free / paid
- Chore
- Ending a hung or runaway process on a remote workstation without interrupting the user’s session
- Rights
- Local administrator on the target computer; WMI/RPC allowed through its firewall
- Trail
- Only visible in Windows logs if you have enabled process-tracking auditing (events 4688/4689)
- Chore
- Working out what a process, autostart entry or file lock is doing on a server
- Rights
- Most tools want an elevated prompt; PsExec needs admin rights on the remote host
- Trail
- PsExec installs a temporary PSEXESVC service (System log 7045); most other tools leave little behind
- Chore
- Everyday server housekeeping — services, event logs, updates, certificates — from one browser tab
- Rights
- Gateway access plus admin rights on each managed server via WinRM / PowerShell remoting
- Trail
- Actions run as PowerShell on the managed node; enable script-block logging if you want them recorded
- Chore
- Confirming which addresses in a server subnet answer after a reboot window or change
- Rights
- Runs as a normal user; no rights on the targets
- Trail
- Nothing on the targets beyond connection attempts in firewall or IDS logs
- Chore
- Showing whether a slow logon is DNS, Kerberos or SMB — with evidence
- Rights
- Capture privileges on the machine you capture from (Npcap on Windows)
- Trail
- Nothing on other hosts; capture files hold sensitive data and need careful storage